# Issue in renewing

**URL:** https://community.letsencrypt.org/t/issue-in-renewing/237459
**Category:** Help
**Created:** [May 16, 2025, 4:14am UTC](https://community.letsencrypt.org/t/issue-in-renewing/237459 "2025-05-16T04:14:43Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ujjawal](https://avatars.discourse-cdn.com/v4/letter/u/ee7513/32.png) [@ujjawal](https://community.letsencrypt.org/u/ujjawal)
#### Post date: [May 16, 2025, 4:14am UTC](https://community.letsencrypt.org/t/issue-in-renewing/237459/1 "2025-05-16T04:14:43Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

Last all attempt were successful since 1 year, nothing changed on configuration side on server

My domain is: abc.gov.in

I ran this command: sudo certbot renew

It produced this output: DNS issue while renewing

My web server is (include version): apache 2.4 on aws instance

The operating system my web server runs on is (include version): Amazon Linux 2

My hosting provider, if applicable, is: AWS

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): i am using phython 2.7 with certbot 1.11.0

---

<div class="post-metadata">

### Author: ![orangepizza](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/orangepizza/32/19597_2.png) [@orangepizza](https://community.letsencrypt.org/u/orangepizza)
#### Post date: [May 16, 2025, 6:42am UTC](https://community.letsencrypt.org/t/issue-in-renewing/237459/2 "2025-05-16T06:42:58Z")

</div>

[http://abc.gov.in](http://abc.gov.in) replied by awselb/2.0 not apache :geoblocking?

---

<div class="post-metadata">

### Author: ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)
#### Post date: [May 16, 2025, 9:36am UTC](https://community.letsencrypt.org/t/issue-in-renewing/237459/3 "2025-05-16T09:36:51Z")

</div>

also CAA prevents issuance by Let's Encrypt  
[https://unboundtest.com/m/CAA/abc.gov.in/LSB4L4GT](https://unboundtest.com/m/CAA/abc.gov.in/LSB4L4GT)

> **[Certificate Authority Authorization (CAA)](https://letsencrypt.org/docs/caa/)**
>
> CAA is a type of DNS record that allows site owners to specify which Certificate Authorities (CAs) are allowed to issue certificates containing their domain names. It was first standardized in 2013, and the version we use today was standardized in...

History

> **[crt.sh | ABC.gov.in](https://crt.sh/?Identity=ABC.gov.in&deduplicate=Y)**
>
> Free CT Log Certificate Search Tool from Sectigo (formerly Comodo CA)

---

<div class="post-metadata">

### Author: ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)
#### Post date: [June 15, 2025, 9:36am UTC](https://community.letsencrypt.org/t/issue-in-renewing/237459/4 "2025-06-15T09:36:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
