Error when expanding existing certificate

When expanding an existing certificate i get an error but the updates seems to work.
What does the error mean? Do I need to change any of the parameters?

I ran this command: certbot-auto certonly --manual --preferred-challenges dns --manual-cleanup-hook /opt/etc/certbot-distribute -d -d etc… and -d

Before continuing, verify the record is deployed.
(This must be set up in addition to the previous challenges; do not remove,
replace, or undo the previous challenge tasks yet. Note that you might be
asked to create multiple distinct TXT records with the same name. This is
permitted by DNS standards.)

Press Enter to Continue
Waiting for verification…
Cleaning up challenges
Encountered exception during recovery:
Traceback (most recent call last):
File “/opt/”, line 124, in _call_registered
File “/opt/”, line 220, in _cleanup_challenges
File “/opt/”, line 177, in cleanup
env = self.env.pop(achall)
KeyError: KeyAuthorizationAnnotatedChallenge(challb=ChallengeBody(chall=DNS01(token=‘kT\x16{\x8b\xd7H+9Q\xe8*\xd06\xad\xf9\xd13\x01I\xb0d\xf2uh\6\xb7\x01M\xad\xc2’), status=Status(pending), uri=u’’, validated=None, _url=u’’, error=None), domain=u’’, account_key=JWKRSA(key=<ComparableRSAKey(<cryptography.hazmat.backends.openssl.rsa._RSAPrivateKey object at 0x7f6872f5e7d0>)>))


  • Congratulations! Your certificate and chain have been saved at:

My web server is (include version): apache httpd 2.4.39

The operating system my web server runs on is (include version): CentOS7 7.6.1810

My hosting provider, if applicable, is: self-hosted

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): 0.36.0

Hi @digidoc

there is no real problem.

You have created a new certificate

and you use it ( ): (11518)
expires in 90 days,,,,,,,,,,,,,,,,, - 
18 entries

But the cleanup script didn't work, so your TXT entries are online.

But that's not critical.

Perhaps there is an updated cleanup script you should use.

More important: You don't have redirects http -> https:

Domainname Http-Status redirect Sec. G 200 0.080 H 200 0.064 H 200 0.784 B 200 0.350 B

So http users are insecure.

Whether or not it’s causing you problems, it still sounds like a bug in Certbot.

If you have the time, would you mind reporting it on GitHub?

Edit: cc @schoen :smiley_cat:

Oh wauw, that quick! :slight_smile:
ok, thx 4 feedback, what cleanup script are your referring to?
these are the entries from my zone file, strange the top level gets repeated in the report. IN TXT "
_acme-challenge.develop IN TXT "
_acme-challenge IN TXT "
_acme-challenge.login IN TXT "
_acme-challenge.logon IN TXT "
_acme-challenge.preview IN TXT "
_acme-challenge.respondent IN TXT "
_acme-challenge.www IN TXT "
_acme-challenge.stress0 IN TXT "
_acme-challenge.stress1 IN TXT "
_acme-challenge.stress2 IN TXT "
_acme-challenge.stress3 IN TXT "
_acme-challenge.stress4 IN TXT "
_acme-challenge.stress5 IN TXT "
_acme-challenge.stress6 IN TXT "
_acme-challenge.stress7 IN TXT "
_acme-challenge.stress8 IN TXT "
_acme-challenge.stress9 IN TXT "
the redirect is temp switched off for some testing…
also “danke” for the nice domain tester, i am gonna use that more! :slight_smile:
i will log the issue on github.

