# How to avoid rate limit

**URL:** <https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641>\
**Category:** Help\
**Created:** [April 16, 2024, 1:32am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641 "2024-04-16T01:32:20Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![kamiya](https://avatars.discourse-cdn.com/v4/letter/k/3da27b/32.png) [@kamiya](https://community.letsencrypt.org/u/kamiya)\
**Post date:** [April 16, 2024, 1:32am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/1 "2024-04-16T01:32:20Z")

</div>

Hello,

I am using cPanel/WHM and have run into the following problem, please advise.

> Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [crt.sh | example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:  
mixh.jp

I ran this command:  
I tried to renew my certificate with cPanel.

It produced this output:

```nohighlight
[2024-03-25T20:36:27Z] AutoSSL failed to create a new certificate order because the server’s Let’s Encrypt account (https://acme-v02.api.letsencrypt.org/acme/acct/1637041807) has reached a rate limit. (429urn:ietf:params:acme:error:rateLimited (The request exceeds a rate limit) (Error creating new order :: too many certificates already issued for "mixh.jp". 
Retry after 2024-04-01T19:00:00Z: see https://letsencrypt.org/docs/rate-limits/)) You may contact Let’s Encrypt to request a change to this rate limit.

```

My web server is (include version):  
LiteSpeed 6.0

The operating system my web server runs on is (include version):  
CloudLinux 8

My hosting provider, if applicable, is:  
I'm hosting provider in Japan.

I can login to a root shell on my machine (yes or no, or I don't know):  
Yes.

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):  
Yes.  
WHM 11.118.0.4

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):  
I do not use Certbot.

My customer's SSL certificate could not be renewed successfully with the error outputting a large number of errors.  
I am giving away the domain "mixh.jp" for free to my users, and I have about 10,000+ subdomains, on multiple servers.  
I tried to request a rate limit relaxation via the form but that did not work.

How do I renew all of my clients' certificates without restrictions?

Please advise.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [April 16, 2024, 1:43am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/2 "2024-04-16T01:43:18Z")

</div>

Hello @kamiya, welcome to the Let's Encrypt community. 🙂

Testing and debugging are best done using the **[Staging Environment](https://letsencrypt.org/docs/staging-environment/)** as the **[Rate Limits](https://letsencrypt.org/docs/rate-limits/)** are much higher.

> [@kamiya](#):
>
> The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):  
> I do not use Certbot.

But you should be able to state the name of the client and its version

Check [Rate Limits - Let's Encrypt](https://letsencrypt.org/docs/rate-limits/#a-id-overrides-a-overrides) and consider filling out [rate limiting form](https://isrg.formstack.com/forms/rate_limit_adjustment_request)

Also consider if you can use [https://publicsuffix.org/](https://publicsuffix.org/)

Please be aware any of these will take time..

---

<div class="post-metadata">

**Author:** ![kamiya](https://avatars.discourse-cdn.com/v4/letter/k/3da27b/32.png) [@kamiya](https://community.letsencrypt.org/u/kamiya)\
**Post date:** [April 16, 2024, 1:58am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/3 "2024-04-16T01:58:42Z")

</div>

Hello @Bruce5051,

Thank you for your answers.

> Testing and debugging are best done using the **[Staging Environment](https://letsencrypt.org/docs/staging-environment/)** as the **[Rate Limits](https://letsencrypt.org/docs/rate-limits/)** are much higher.
> 
> But you should be able to state the name of the client and its version[/quote]

I am using a feature bundled with the dedicated hosting software called cPanel/WHM.  
The software is the aforementioned version, I am using "WHM 11.118.0.4".  
Unfortunately, there does not appear to be a way to use a staging environment with this software.

> Check [Rate Limits - Let's Encrypt](https://letsencrypt.org/docs/rate-limits/#a-id-overrides-a-overrides) and consider filling out [rate limiting form](https://isrg.formstack.com/forms/rate_limit_adjustment_request)

I tried to order from the rate limiting form to ask for the limit to be lifted but I get the following error:

```nohighlight
No Overrides Possible
The error you are receiving has no possible overrides. 

```

Is there something wrong with my application process?

> Also consider if you can use [https://publicsuffix.org/](https://publicsuffix.org/)

Can you please tell us the specific use of the PSL?

Regards,

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [April 16, 2024, 2:08am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/4 "2024-04-16T02:08:19Z")

</div>

> [@kamiya](#):
>
> Can you please tell us the specific use of the PLS?

Your domain name `mixh.jp` would act as though it were a TLD.  
Thus increasing the limits for your users, it would be as each had their own domain name.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [April 16, 2024, 2:14am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/5 "2024-04-16T02:14:12Z")

</div>

@kamiya there are also other Free ACME CAs.

> **[ACME CA Comparison - Posh-ACME](https://poshac.me/docs/v4/Guides/ACME-CA-Comparison/)**
>
> Documentation for the Posh-ACME PowerShell module

---

<div class="post-metadata">

**Author:** ![kamiya](https://avatars.discourse-cdn.com/v4/letter/k/3da27b/32.png) [@kamiya](https://community.letsencrypt.org/u/kamiya)\
**Post date:** [April 16, 2024, 2:20am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/6 "2024-04-16T02:20:47Z")

</div>

> [@Bruce5051](#):
>
> > [@kamiya](#):
> >
> > Can you please tell us the specific use of the PSL?
> 
> Your domain name `mixh.jp` would act as though it were a TLD.  
> Thus increasing the limits for your users, it would be as each had their own domain name.

Thank you for your clear answer.  
If I register "mixh.jp" in PSL, does it mean that rate limits are applied to each user's subdomain?  
What steps are necessary to register "mixh.jp" in the PSL?

> [@Bruce5051](#):
>
> @kamiya there are also other Free ACME CAs.

Unfortunately, it is not possible to change the ACME because Let'sEncrypt is closely integrated with the panel functions bundled with the cPanel/WHM software.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [April 16, 2024, 2:24am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/7 "2024-04-16T02:24:45Z")

</div>

> [@kamiya](#):
>
> If I register "mixh.jp" in PLS, does it mean that rate limits are applied to each user's subdomain?

That is how I understand it.

> [@kamiya](#):
>
> What steps are necessary to register "mixh.jp" in the PLS?

Check here [Submit amendments to the Public Suffix List](https://publicsuffix.org/submit/)

If more knowledgeable Let's Encrypt community members correct what I have presented,  
by all means take their advise. 🙂

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [April 16, 2024, 2:47am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/8 "2024-04-16T02:47:57Z")

</div>

Using the Public Suffix List is probably better for you as that registered name is being shared by different customers. It is [described here](https://publicsuffix.org/). It will possibly affect how cookies by your customers are handled so be sure to study it.

Other than the PSL, based on the dates in your first post you issued 50 certs for the registered name `mixh.jp`. That is the default limit for certs for a single registered name.

You should be able to request a rate limit to allow more especially as a hosting provider.

Some of the other limits cannot be extended but this one should be. I provide a sample below. Is this how you filled out the form?

Were you trying to issue a very large number of certs in a short time? Because you would still need to pace requests to avoid the "hard" limits (like 300 new orders / hour). See [Rate Limits - link here](https://letsencrypt.org/docs/rate-limits/)

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/c/3/c3fca2d8f16d7f9dcdfab6f7f6f3962a377af216.png)

---

<div class="post-metadata">

**Author:** ![kamiya](https://avatars.discourse-cdn.com/v4/letter/k/3da27b/32.png) [@kamiya](https://community.letsencrypt.org/u/kamiya)\
**Post date:** [April 16, 2024, 3:00am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/9 "2024-04-16T03:00:38Z")

</div>

Thank you for your answers @Bruce5051 and @MikeMcQ .

I will take action to register the domain on the Public Suffix List.  
Can you tell me for reference how long this will take to register?

We are currently working around the issue by using a different certificateprovider, but the deadline with the cPanel/WHM hosting software is expected to be around December of this year.

> [@MikeMcQ](#):
>
> Some of the other limits cannot be extended but this one should be. I provide a sample below. Is this how you filled out the form?

Apparently I have been checking the wrong items.  
I selected "too many certificates already issued" and the form to apply appeared.

---

<div class="post-metadata">

**Author:** ![kamiya](https://avatars.discourse-cdn.com/v4/letter/k/3da27b/32.png) [@kamiya](https://community.letsencrypt.org/u/kamiya)\
**Post date:** [May 9, 2024, 3:42am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/10 "2024-05-09T03:42:14Z")

</div>

Hello,

> [@MikeMcQ](#):
>
> Some of the other limits cannot be extended but this one should be. I provide a sample below. Is this how you filled out the form?

I applied for a Rate Limit Adjustment Request via the form.  
However, after one day, I have not received any response to my registered email address.

Is there any way to check if my application was correctly submitted?  
Is there any other way but to wait for a response from Let's Encrypt?

Regards,

---

<div class="post-metadata">

**Author:** ![JamesLE](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jamesle/32/49364_2.png) [@JamesLE](https://community.letsencrypt.org/u/JamesLE)\
**Post date:** [May 9, 2024, 3:45am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/11 "2024-05-09T03:45:30Z")

</div>

Please read the information that’s provided on the rate limit form regarding our response times.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 8, 2024, 3:46am UTC](https://community.letsencrypt.org/t/how-to-avoid-rate-limit/216641/12 "2024-06-08T03:46:29Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
