# Increase rate limit for domain

**URL:** https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663
**Category:** Help
**Created:** [June 18, 2018, 7:03pm UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663 "2018-06-18T19:03:50Z")
**Posts on this page:** 8
**Page:** 1

<div class="post-metadata">

### Author: ![robogang](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@robogang](https://community.letsencrypt.org/u/robogang)
#### Post date: [June 18, 2018, 7:03pm UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/1 "2018-06-18T19:03:50Z")

</div>

Hi, we are faced with an issue on our production, we have a number of subdomains configured with letsencrypt and going to move them to wildcard but getting an error about rate limits, could you please increase limit temporary or just disable it until we generate wildcard for that domain. Thanks for the help!

My domain is: [visitnow.org](http://visitnow.org)

I ran this command: certbot certonly -d [visitnow.org](http://visitnow.org),\*.visitnow.org --dns-route53 -w /etc/letsencrypt/ --agree-tos --non-interactive --server [https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory) --expand

It produced this output: An unexpected error occurred:  
There were too many requests of a given type :: Error finalizing order :: too many certificates already issued for: [visitnow.org](http://visitnow.org): see [https://letsencrypt.org/docs/rate-limits/](https://letsencrypt.org/docs/rate-limits/)

My web server is (include version): nginx version: nginx/1.10.3 (Ubuntu)

The operating system my web server runs on is (include version): Ubuntu 16.06

My hosting provider, if applicable, is: godaddy

I can login to a root shell on my machine (yes or no, or I don’t know): yes

I’m using a control panel to manage my site (no, or provide the name and version of the control panel): no

---

<div class="post-metadata">

### Author: ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)
#### Post date: [June 18, 2018, 7:13pm UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/2 "2018-06-18T19:13:16Z")

</div>

Let’s Encrypt doesn’t lift the rate limits for individual cases. The only way to continue is to:

- wait the appropriate amount of time (see the docs for how long)
- request an exemption with the rate limit exemption form (link can be found in the rate limit docs, but it takes a lot of time for such a request to be processed)
- ask the domain to be included on the Public Suffix List (but they are increasingly strict, so your use case really needs to conform to their idea of the purpose behind the Public Suffix List).

---

<div class="post-metadata">

### Author: ![robogang](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@robogang](https://community.letsencrypt.org/u/robogang)
#### Post date: [June 18, 2018, 7:21pm UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/3 "2018-06-18T19:21:22Z")

</div>

the problem that i`m waiting about 2 weeks and can`t issue new certificate

---

<div class="post-metadata">

### Author: ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)
#### Post date: [June 18, 2018, 7:33pm UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/4 "2018-06-18T19:33:31Z")

</div>

> [@robogang](#):
>
> the problem that i`m waiting about 2 weeks and can`t issue new certificate

Did you use the stage-system? There you can do a lot of tests.

---

<div class="post-metadata">

### Author: ![jple](https://avatars.discourse-cdn.com/v4/letter/j/c5a1d2/32.png) [@jple](https://community.letsencrypt.org/u/jple)
#### Post date: [June 18, 2018, 7:48pm UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/5 "2018-06-18T19:48:13Z")

</div>

hmm, this is from the rate-limit doc:

“If you’ve hit a rate limit, we don’t have a way to temporarily reset it. You’ll need to wait until the rate limit expires after a week. We use a sliding window, so if you issued 10 certificates on Monday and 10 more certificates on Friday, you’ll be able to issue again starting Monday. You can get a list of certificates issued for your registered domain by searching on crt.sh, which uses the public Certificate Transparency logs.”

Basically, you should only be waiting a week. Have you also looked into the renewal exemption?  
“To make sure you can always renew your certificates when you need to, we have a Renewal Exemption to the Certificates per Registered Domain limit. Even if you’ve hit the limit for the week, you can still issue new certificates that count as renewals. An issuance request counts as a renewal if it contains the exact same set of hostnames as a previously issued certificate. This is the same definition used for the Duplicate Certificate limit described above. Renewals are still subject to the Duplicate Certificate limit. Also note: the order of renewals and new issuances matters. To get the maximum possible number of certificates, you must perform all new issuances before renewals during a given time window.”

Lastly, if you are hitting this regularly and do need a certificates per registered domain rate limit adjustment, please fill out the form in this doc: [https://letsencrypt.org/docs/rate-limits/](https://letsencrypt.org/docs/rate-limits/)

We typically do rate limit adjustments once a week.

Thanks so much for using Let’s Encrypt!

---

<div class="post-metadata">

### Author: ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)
#### Post date: [June 19, 2018, 1:55am UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/6 "2018-06-19T01:55:12Z")

</div>

> [@robogang](#):
>
> the problem that i `m waiting about 2 weeks and can` t issue new certificate

Y'all issuing certificates -- renewing them -- frequently. To create different certificates, you'll have to time it carefully, or defer renewing other certificates for a while.

> **[crt.sh | %visitnow.org](https://crt.sh/?q=%25visitnow.org)**
>
> Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)

You can also pursue getting a rate limit exemption from Let's Encrypt, as discussed above.

According to [Let's Debug's](https://letsdebug.net/) math, you can issue a new certificate about 9 hours from now.

> **[Test result for visitnow.org: Error](https://letsdebug.net/visitnow.org/1694)**
>
> 1 unique issue(s) detected (RateLimit)

You've recently issued certificates for both `visitnow.org` and `*.visitnow.org`. While you can't get one certificate including both names right now, you can use the single name certificates you have now, or issue more of them (taking advantage of the renewal exemption to the rate limits). (Of course, that would further delay being able to create different certificates.)

[https://crt.sh/?q=visitnow.org](https://crt.sh/?q=visitnow.org)

> **[crt.sh | \*.visitnow.org](https://crt.sh/?q=*.visitnow.org)**
>
> Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)

---

<div class="post-metadata">

### Author: ![robogang](https://avatars.discourse-cdn.com/v4/letter/r/d6d6ee/32.png) [@robogang](https://community.letsencrypt.org/u/robogang)
#### Post date: [June 19, 2018, 5:50am UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/7 "2018-06-19T05:50:43Z")

</div>

> [@mnordhoff](#):
>
> Y’all issuing certificates – renewing them – frequently. To create different certificates, you’ll have to time it carefully, or defer renewing other certificates for a while.
> 
> [https://crt.sh/?q=%visitnow.org](https://crt.sh/?q=%25visitnow.org)
> 
> You can also pursue getting a rate limit exemption from Let’s Encrypt, as discussed above.
> 
> According to [Let’s Debug’s](https://letsdebug.net/) math, you can issue a new certificate about 9 hours from now.
> 
> [Let's Debug](https://letsdebug.net/visitnow.org/1694)
> 
> You’ve recently issued certificates for both `visitnow.org` and `*.visitnow.org` . While you can’t get one certificate including both names right now, you can use the single name certificates you have now, or issue more of them (taking advantage of the renewal exemption to the rate limits). (Of course, that would further delay being able to create different certificates.)

Thanks for the help!

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [July 19, 2018, 5:50am UTC](https://community.letsencrypt.org/t/increase-rate-limit-for-domain/64663/8 "2018-07-19T05:50:45Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
