Hi,
I thought I’d finally get around to putting a ssl cert on one of my toy sites however I’m not having much luck, I’ve tried 3 different clients (Have skipped certbot so far on account of python issue) but they’re all failing the same way
I tried first on the staging server then on production as a last ditch attempt (in case staging is broken - it always is where I work :D)
Full domain is cryptohash.net
Most recently I ran getssl
Running it against the following subdomains cryptohash.net,md2.cryptohash.net,md4.cryptohash.net,md5.cryptohash.net,sha1.cryptohash.net,sha224.cryptohash.net,sha256.cryptohash.net,sha384.cryptohash.net,sha512.cryptohash.net,ripemd128.cryptohash.net,ripemd160.cryptohash.net,ripemd256.cryptohash.net,ripemd320.cryptohash.net,whirlpool.cryptohash.net,tiger128-3.cryptohash.net,tiger160-3.cryptohash.net,tiger192-3.cryptohash.net,tiger128-4.cryptohash.net,tiger160-4.cryptohash.net,tiger192-4.cryptohash.net,snefru.cryptohash.net,snefru256.cryptohash.net,gost.cryptohash.net,gost-crypto.cryptohash.net,adler32.cryptohash.net,crc32.cryptohash.net,crc32b.cryptohash.net,fnv132.cryptohash.net,fnv1a32.cryptohash.net,fnv164.cryptohash.net,fnv1a64.cryptohash.net,joaat.cryptohash.net,haval128-3.cryptohash.net,haval160-3.cryptohash.net,haval192-3.cryptohash.net,haval224-3.cryptohash.net,haval256-3.cryptohash.net,haval128-4.cryptohash.net,haval160-4.cryptohash.net,haval192-4.cryptohash.net,haval224-4.cryptohash.net,haval256-4.cryptohash.net,haval128-5.cryptohash.net,haval160-5.cryptohash.net,haval192-5.cryptohash.net,haval224-5.cryptohash.net,haval256-5.cryptohash.net
I even renamed all my domains (they used to be underscores not dashes)
Got a reference #179.6cb57568.1474529297.3c20eb
The full output text is way long but this looks like the start of a sub-request
HTTP/1.1 202 Accepted
Server: nginx
Content-Type: application/json
Content-Length: 335
Boulder-Request-Id: 3QBcFfIFf_7Mix13DwufJqVxhIHy2VOlR0a0f90qMco
Boulder-Requester: 4510433
Link: <https://acme-v01.api.letsencrypt.org/acme/authz/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc>;rel="up"
Location: https://acme-v01.api.letsencrypt.org/acme/challenge/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc/271270046
Replay-Nonce: ANf9br6wJuSoxCIcB7od5DHhRYdnqooq4gIBnZxhGEQ
Expires: Thu, 22 Sep 2016 07:28:10 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 22 Sep 2016 07:28:10 GMT
Connection: keep-alive
response {
"type": "http-01",
"status": "pending",
"uri": "https://acme-v01.api.letsencrypt.org/acme/challenge/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc/271270046",
"token": "BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8",
"keyAuthorization": "BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8.3dds3VAeGTS8X_gd4Fu8mXBrjgFWZkidMfgZdGXtVAI"
}
code 202
checking
url https://acme-v01.api.letsencrypt.org/acme/challenge/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc/271270046
response {
"type": "http-01",
"status": "pending",
"uri": "https://acme-v01.api.letsencrypt.org/acme/challenge/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc/271270046",
"token": "BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8",
"keyAuthorization": "BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8.3dds3VAeGTS8X_gd4Fu8mXBrjgFWZkidMfgZdGXtVAI"
}
code
getcr return code 0
Pending
sleep 5 secs before testing verify again
checking
url https://acme-v01.api.letsencrypt.org/acme/challenge/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc/271270046
response {
"type": "http-01",
"status": "valid",
"uri": "https://acme-v01.api.letsencrypt.org/acme/challenge/A1gbEXYEUCUw7pFVsD_dgClx8eFwvPCy9GbwJAF0jKc/271270046",
"token": "BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8",
"keyAuthorization": "BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8.3dds3VAeGTS8X_gd4Fu8mXBrjgFWZkidMfgZdGXtVAI",
"validationRecord": [
{
"url": "http://ripemd160.cryptohash.net/.well-known/acme-challenge/BfzJEP9EZGElEbjD72epd_4zTVQ1Agfyy3VpgpuRuO8",
"hostname": "ripemd160.cryptohash.net",
"port": "80",
"addressesResolved": [
"59.167.214.24",
"2001:44b8:219c:8e00::1"
],
"addressUsed": "59.167.214.24"
}
]
}
code
getcr return code 0
Verified ripemd160.cryptohash.net
remove token from /tmp/acl
Verifing ripemd256.cryptohash.net
domain ripemd256.cryptohash.net has location /tmp/acl
url https://acme-v01.api.letsencrypt.org/acme/new-authz
payload {"resource": "new-authz", "identifier": {"type": "dns", "value": "ripemd256.cryptohash.net"}}
payload64 eyJyZXNvdXJjZSI6ICJuZXctYXV0aHoiLCAiaWRlbnRpZmllciI6IHsidHlwZSI6ICJkbnMiLCAidmFsdWUiOiAicmlwZW1kMjU2LmNyeXB0b2hhc2gubmV0In19
nonce fupznLAdq-Bypnz2wofe5hdrS3Lq3owvzCrZbwDPIno
protected {"alg": "RS256", "jwk": {"e": "AQAB", "kty": "RSA", "n": "xZlNFky42KaJzagC5-XHXRrMvUY6uGrdmGHkTRh-iQnNG-YIsh7P3gNxcXYLUQbSMDpwrfrWj-Tob5QV7J6vEIhkkOqL3e6CCpDZjn5_tFlh2FQR0JKqu00PyL6s0XnFpptsbPZK97p5PYtyFCWi-IluWsJ_pPFCzM4yMM2R5V4u-Pxbk7unESyFBbjJzi36cI0ENtvrpNu2v0EvRqhn8hpxo6U_kNCf_RcLthIBxDNGp75pevwORaJo7n7opIEUl9gPTeSlG3fclRsmd2ZUjwUIHP6bzDdHB_VmQtIO05tbIUFsYDMynpDA_wIDpwb3IDeq5fq-VuVP5Gj2y326TJx_onSpXjMk3GCzKzd5J7rgbsUe1U4VkiUZgyKimrbjFsEShc3R2j-PJGfkc8dhlgnkGTUZzPe0kX5TYZQdyH-PipNbxndaAwYa-_opxhZGWWgjavGTN7JhgA6xqTx_7oMSD-_NWyVVXc0XU_TUVOq7U5eilZpqD-MOZA6e0bQainOpQFuF6dF8FVv4sO7RKZN5xm4ufsD1NdjhCghFzdeB4rM9Q79m9gcUsGel2AUDsEIWnDBIPTpQyA1Bw1bLa5_liA-CK3v5iSbQMr9tRkYXMTHeEzsVRlKqCcMxrL3TVtupqt05Ncl6dOHhrX6LrRKC22ZGy_wxJzxROZ3_nSU"}, "nonce": "fupznLAdq-Bypnz2wofe5hdrS3Lq3owvzCrZbwDPIno"}
data for account registration = {"header": {"alg": "RS256", "jwk": {"e": "AQAB", "kty": "RSA", "n": "xZlNFky42KaJzagC5-XHXRrMvUY6uGrdmGHkTRh-iQnNG-YIsh7P3gNxcXYLUQbSMDpwrfrWj-Tob5QV7J6vEIhkkOqL3e6CCpDZjn5_tFlh2FQR0JKqu00PyL6s0XnFpptsbPZK97p5PYtyFCWi-IluWsJ_pPFCzM4yMM2R5V4u-Pxbk7unESyFBbjJzi36cI0ENtvrpNu2v0EvRqhn8hpxo6U_kNCf_RcLthIBxDNGp75pevwORaJo7n7opIEUl9gPTeSlG3fclRsmd2ZUjwUIHP6bzDdHB_VmQtIO05tbIUFsYDMynpDA_wIDpwb3IDeq5fq-VuVP5Gj2y326TJx_onSpXjMk3GCzKzd5J7rgbsUe1U4VkiUZgyKimrbjFsEShc3R2j-PJGfkc8dhlgnkGTUZzPe0kX5TYZQdyH-PipNbxndaAwYa-_opxhZGWWgjavGTN7JhgA6xqTx_7oMSD-_NWyVVXc0XU_TUVOq7U5eilZpqD-MOZA6e0bQainOpQFuF6dF8FVv4sO7RKZN5xm4ufsD1NdjhCghFzdeB4rM9Q79m9gcUsGel2AUDsEIWnDBIPTpQyA1Bw1bLa5_liA-CK3v5iSbQMr9tRkYXMTHeEzsVRlKqCcMxrL3TVtupqt05Ncl6dOHhrX6LrRKC22ZGy_wxJzxROZ3_nSU"}}, "protected": "eyJhbGciOiAiUlMyNTYiLCAiandrIjogeyJlIjogIkFRQUIiLCAia3R5IjogIlJTQSIsICJuIjogInhabE5Ga3k0MkthSnphZ0M1LVhIWFJyTXZVWTZ1R3JkbUdIa1RSaC1pUW5ORy1ZSXNoN1AzZ054Y1hZTFVRYlNNRHB3cmZyV2otVG9iNVFWN0o2dkVJaGtrT3FMM2U2Q0NwRFpqbjVfdEZsaDJGUVIwSktxdTAwUHlMNnMwWG5GcHB0c2JQWks5N3A1UFl0eUZDV2ktSWx1V3NKX3BQRkN6TTR5TU0yUjVWNHUtUHhiazd1bkVTeUZCYmpKemkzNmNJMEVOdHZycE51MnYwRXZScWhuOGhweG82VV9rTkNmX1JjTHRoSUJ4RE5HcDc1cGV2d09SYUpvN243b3BJRVVsOWdQVGVTbEczZmNsUnNtZDJaVWp3VUlIUDZiekRkSEJfVm1RdElPMDV0YklVRnNZRE15bnBEQV93SURwd2IzSURlcTVmcS1WdVZQNUdqMnkzMjZUSnhfb25TcFhqTWszR0N6S3pkNUo3cmdic1VlMVU0VmtpVVpneUtpbXJiakZzRVNoYzNSMmotUEpHZmtjOGRobGdua0dUVVp6UGUwa1g1VFlaUWR5SC1QaXBOYnhuZGFBd1lhLV9vcHhoWkdXV2dqYXZHVE43SmhnQTZ4cVR4XzdvTVNELV9OV3lWVlhjMFhVX1RVVk9xN1U1ZWlsWnBxRC1NT1pBNmUwYlFhaW5PcFFGdUY2ZEY4RlZ2NHNPN1JLWk41eG00dWZzRDFOZGpoQ2doRnpkZUI0ck05UTc5bTlnY1VzR2VsMkFVRHNFSVduREJJUFRwUXlBMUJ3MWJMYTVfbGlBLUNLM3Y1aVNiUU1yOXRSa1lYTVRIZUV6c1ZSbEtxQ2NNeHJMM1RWdHVwcXQwNU5jbDZkT0hoclg2THJSS0MyMlpHeV93eEp6eFJPWjNfblNVIn0sICJub25jZSI6ICJmdXB6bkxBZHEtQnlwbnoyd29mZTVoZHJTM0xxM293dnpDclpid0RQSW5vIn0", "payload": "eyJyZXNvdXJjZSI6ICJuZXctYXV0aHoiLCAiaWRlbnRpZmllciI6IHsidHlwZSI6ICJkbnMiLCAidmFsdWUiOiAicmlwZW1kMjU2LmNyeXB0b2hhc2gubmV0In19", "signature": "cAHGCGkk6lUB2MPfmLB_aPrRc-3BWJDsqkYFeWsT9wv-b3NsCJCFa-VAeZjjDCrqv_aD85KSaJK3-8lVz9Q2nby7zPvQjYiHC4nwMZw1xADhRiiGcE0ejxjoH3dHfB7VVxtlCdVHdLdm6KyBse8T1uhBPjGbgUwXiJLre5eHV-8e_JV6MCYjjYxTlMQMMjGUHSIEid6yzPxryLEu3TFN68Hd4rF7esY2wGuWeqzvii2D5UuWizZL9JbnOOE33M4c_MyO1zp4d2O2gOTOkYt9Gm2FrT0EnsX7F_3TOLs_QUa884MG3WO6SNT280tUmTdnFPTHfw8k2sNWxgsqmF6Q3-Gll-EbczJkPZgGcsRdoy0W25gc2Q5M8Y2LvSZy0Pce7Okcbrdo9cD3PPhp_A55ET_z1WWG3fQ91k6lwt3go5BXxL2u_BsRVKAh8n6y0nxsZtyf-ZiLsyO3YtoGyL5u3u3K6CyqsnUSCLoqQln2c-8OmSyGV_YApCVlm678bmme26oP2qXGkBQtEdWKRchjrhF2QhLofH6xRncJfRAZlf8PX1kMHAmI6QCth3D1P7XoYVakW67_6Nj_PZehIXN0Euzc8vuCYyzG0eKUcilrBg3KiOxsahLimfupl4znloUhlbQgIi8eBDAyFSGRV83JnN6bJqJeBA4J-eWhop7YPO0"}
responseHeaders HTTP/1.1 100 Continue
Expires: Thu, 22 Sep 2016 07:28:17 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
HTTP/1.1 500 Internal Server Error
Server: AkamaiGHost
Mime-Version: 1.0
Content-Type: text/html
Content-Length: 175
Expires: Thu, 22 Sep 2016 07:28:17 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 22 Sep 2016 07:28:17 GMT
Connection: close
response <HTML><HEAD><TITLE>Error</TITLE></HEAD><BODY>
An error occurred while processing your request.<p>
Reference #179.6cb57568.1474529297.3c20eb
</BODY></HTML>
code 500
completed send_signed_request
getssl: new-authz error: <HTML><HEAD><TITLE>Error</TITLE></HEAD><BODY>
An error occurred while processing your request.<p>
Reference #179.6cb57568.1474529297.3c20eb
</BODY></HTML>