UNAUTHORIZED, why??
I think my TXT record is public right? No need to hide it, anyhow it all check outs, there isn't a discrepancy that I can see in the txt record and what I'm expecting. I'm doing the renewal on a wildcard cert that is expired, manually...
I believe the TXT record is public, but wasn't sure so I replaced it here with [TXTRECORD] fyi
My domain is: bcae.us
I ran this command:
sudo certbot renew --manual --manual-auth-hook /home/chris/Documents/set_env.sh
(in that set_env.sh I have my TXT record that I export for the function to use, it looks good)
It produced this output:
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/bcae.us.conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
*Renewing an existing certificate for .bcae.us
Certbot failed to authenticate some domains (authenticator: manual). The Certificate Authority reported these problems:
- Domain: bcae.us*
- Type: unauthorized*
- Detail: Incorrect TXT record "[TXTRECORD]" found at _acme-challenge.bcae.us*
Hint: The Certificate Authority failed to verify the DNS TXT records created by the --manual-auth-hook. Ensure that this hook is functioning correctly and that it waits a sufficient duration of time for DNS propagation. Refer to "certbot --help manual" and the Certbot User Guide.
My web server is (include version):
zorin
The operating system my web server runs on is (include version):
My hosting provider, if applicable, is:
ionos
I can login to a root shell on my machine (yes or no, or I don't know):
I'm using a control panel to manage my site (no, or provide the name and version of the control panel):
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot):
2.6.0