# Is the ACME v2 server working?

**URL:** <https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912>\
**Category:** Help\
**Created:** [November 21, 2019, 4:44pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912 "2019-11-21T16:44:41Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![claytonrothschild](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/claytonrothschild/32/33758_2.png) [@claytonrothschild](https://community.letsencrypt.org/u/claytonrothschild)\
**Post date:** [November 21, 2019, 4:44pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/1 "2019-11-21T16:44:42Z")

</div>

I keep getting a 500 error when trying to issue using the acme v2 server.

Is it up? BTW - this appears to be the exact scenario described here: [Is the ACME v2 staging server working?](https://community.letsencrypt.org/t/is-the-acme-v2-staging-server-working/52528)

Here’s the log:

```auto
[Thu Nov 21 16:38:03 UTC 2019] RSA key
[Thu Nov 21 16:38:03 UTC 2019] HEAD
[Thu Nov 21 16:38:03 UTC 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/new-nonce'
[Thu Nov 21 16:38:03 UTC 2019] _CURL='curl -L --silent --dump-header /home/sslService/.acme.sh/http.header -g '
[Thu Nov 21 16:38:03 UTC 2019] _ret='0'
[Thu Nov 21 16:38:04 UTC 2019] POST
[Thu Nov 21 16:38:04 UTC 2019] _post_url='https://acme-v02.api.letsencrypt.org/acme/new-order'
[Thu Nov 21 16:38:04 UTC 2019] _CURL='curl -L --silent --dump-header /home/sslService/.acme.sh/http.header -g '
[Thu Nov 21 16:38:04 UTC 2019] _ret='0'
[Thu Nov 21 16:38:04 UTC 2019] code='500'
[Thu Nov 21 16:38:04 UTC 2019] Le_LinkOrder
[Thu Nov 21 16:38:04 UTC 2019] Le_OrderFinalize
[Thu Nov 21 16:38:04 UTC 2019] Create new order error. Le_OrderFinalize not found. {
  "type": "urn:ietf:params:acme:error:serverInternal",
  "detail": "Error creating new order",
  "status": 500
}

```

---

<div class="post-metadata">

**Author:** ![Phil](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/phil/32/76801_2.png) [@Phil](https://community.letsencrypt.org/u/Phil)\
**Post date:** [November 21, 2019, 4:55pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/2 "2019-11-21T16:55:23Z")

</div>

Hi @claytonrothschild,

Your log shows POSTs against the production v2 API, not staging. What version of acme.sh are you using?

---

<div class="post-metadata">

**Author:** ![claytonrothschild](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/claytonrothschild/32/33758_2.png) [@claytonrothschild](https://community.letsencrypt.org/u/claytonrothschild)\
**Post date:** [November 21, 2019, 4:56pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/3 "2019-11-21T16:56:46Z")

</div>

Hi @Phil - apologies - I did not mean staging. Updated title to reflect this.

Acme.sh v2.8.3

---

<div class="post-metadata">

**Author:** ![Phil](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/phil/32/76801_2.png) [@Phil](https://community.letsencrypt.org/u/Phil)\
**Post date:** [November 21, 2019, 5:00pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/4 "2019-11-21T17:00:32Z")

</div>

Would you mind posting a domain you’re attempting to issue for so we can dig into some log files?

---

<div class="post-metadata">

**Author:** ![claytonrothschild](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/claytonrothschild/32/33758_2.png) [@claytonrothschild](https://community.letsencrypt.org/u/claytonrothschild)\
**Post date:** [November 21, 2019, 5:01pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/5 "2019-11-21T17:01:45Z")

</div>

@Phil its a SAN cert, but one of the domains is: [app.cloudpano.com](http://app.cloudpano.com)

The basic command structure is:

```auto
acme.sh --issue --debug -w [homedir] -k 4096 -d app.cloudpano.com -d [...]

```

---

<div class="post-metadata">

**Author:** ![Phil](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/phil/32/76801_2.png) [@Phil](https://community.letsencrypt.org/u/Phil)\
**Post date:** [November 21, 2019, 5:09pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/6 "2019-11-21T17:09:56Z")

</div>

@claytonrothschild,

The order cannot contain more than 100 DNS names and your orders have 102 according to my sed and jq-fu.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [November 21, 2019, 5:18pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/7 "2019-11-21T17:18:17Z")

</div>

> [@Phil](#):
>
> The order cannot contain more than 100 DNS names and your orders have 102 according to my sed and jq-fu.

That's the correct root cause here. Thanks for digging in @Phil!

> [@claytonrothschild](#):
>
> I keep getting a 500 error when trying to issue using the acme v2 server.

This shouldn't be reported as a 500 error. We have a bug on our side. I've filed an issue ([Over-sized orders generate 500 responses · Issue #4571 · letsencrypt/boulder · GitHub](https://github.com/letsencrypt/boulder/issues/4571)) to get this fixed so that orders with more than 100 names get a descriptive malformed problem document in response instead of a generic 500 error problem.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [November 21, 2019, 5:53pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/8 "2019-11-21T17:53:23Z")

</div>

> [@cpu](#):
>
> I’ve filed an issue ([Over-sized orders generate 500 responses · Issue #4571 · letsencrypt/boulder · GitHub](https://github.com/letsencrypt/boulder/issues/4571)) to get this fixed so that orders with more than 100 names get a descriptive malformed problem document in response instead of a generic 500 error problem.

This should be fixed in Boulder master shortly ([RA: fix error returned through WFE2 for too big NewOrders. by cpu · Pull Request #4572 · letsencrypt/boulder · GitHub](https://github.com/letsencrypt/boulder/pull/4572)) and will be fixed in staging/production with next week's deploy based on our [usual schedule](https://github.com/letsencrypt/boulder-release-process#release-schedule).

Thanks again for reporting the problem @claytonrothschild

---

<div class="post-metadata">

**Author:** ![claytonrothschild](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/claytonrothschild/32/33758_2.png) [@claytonrothschild](https://community.letsencrypt.org/u/claytonrothschild)\
**Post date:** [November 21, 2019, 8:32pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/9 "2019-11-21T20:32:28Z")

</div>

Thanks guy, this makes sense. My domain list grows each week - I knew I was getting close to the limit but to be honest it felt like I only had approx ~50 in my list. Im bad at estimating! This new error reporting will be helpful.

Closing ticket.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [November 21, 2019, 8:34pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/10 "2019-11-21T20:34:28Z")

</div>

> [@claytonrothschild](#):
>
> I knew I was getting close to the limit but to be honest it felt like I only had approx ~50 in my list. Im bad at estimating!

😆 Or perhaps your ACME client is automatically including the `www` subdomain for each of your domains? That would explain hitting the error with 50 domains, it would be 2x as many order identifiers.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [November 25, 2019, 2:44pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/12 "2019-11-25T14:44:13Z")

</div>

> [@KevinAuralee](#):
>
> I don’t suppose that there is a switch to turn this “feature” off?

It should be possible but how to do it would depend on your ACME client.

---

<div class="post-metadata">

**Author:** ![cpu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/cpu/32/84514_2.png) [@cpu](https://community.letsencrypt.org/u/cpu)\
**Post date:** [December 5, 2019, 7:47pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/13 "2019-12-05T19:47:25Z")

</div>

> [@cpu](#):
>
> This should be fixed in Boulder master shortly ([https://github.com/letsencrypt/boulder/pull/4572](https://github.com/letsencrypt/boulder/pull/4572)) and will be fixed in staging/production with next week’s deploy based on our [usual schedule](https://github.com/letsencrypt/boulder-release-process#release-schedule).

Hi folks,

Just a quick follow-up to say this is now fixed in production. It took a little bit longer than usual due to the US Thanksgiving holiday last week. An order with more than 100 names should return the correct error now instead of a vague 500 internal server error.

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [January 4, 2020, 7:47pm UTC](https://community.letsencrypt.org/t/is-the-acme-v2-server-working/106912/14 "2020-01-04T19:47:38Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
