# Issue while renew

**URL:** <https://community.letsencrypt.org/t/issue-while-renew/237651>\
**Category:** Help\
**Created:** [May 21, 2025, 2:52am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651 "2025-05-21T02:52:14Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![ujjawal](https://avatars.discourse-cdn.com/v4/letter/u/ee7513/32.png) [@ujjawal](https://community.letsencrypt.org/u/ujjawal)\
**Post date:** [May 21, 2025, 2:52am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651/1 "2025-05-21T02:52:14Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: www.abc.gov.in

I ran this command: sudo certbot renew

It produced this output:

1 renew failure(s), 0 parse failure(s)

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): Apache

The operating system my web server runs on is (include version): AWS Linux

My hosting provider, if applicable, is:

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): Certbot version : 1.11.0

here is the Letsdebug out put :

[IssueFromLetsEncrypt]([https://letsdebug.net/www.abc.gov.in/2452845#Issue](https://letsdebug.net/www.abc.gov.in/2452845#Issue) FromLetsEncrypt-Error)

A test authorization for www.abc.gov.in to the Let's Encrypt staging service has revealed issues that may prevent any certificate for this domain being issued.

DNS problem: query timed out looking up A for www.abc.gov.in; DNS problem: query timed out looking up AAAA for www.abc.gov.in

it was successfully renew from last 1 year. no configuration changed on server.

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [May 21, 2025, 3:19am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651/2 "2025-05-21T03:19:49Z")

</div>

Hello @ujjawal,

Please show the output of each of the following commands

- `sudo certbot certificates`
- `sudo apachectl -t -D DUMP_VHOSTS`

You might want to consider upgrading Certbot;  
see [Certbot 4.0.0 released](https://community.letsencrypt.org/t/certbot-4-0-0-released/236108)

### Edit

There are also significant DNS issues see these

- [Zonemaster](https://zonemaster.net/en/result/c52fa0f1994ede07)
- [EDNS Compliance Tester](https://ednscomp.isc.org/ednscomp/45250534ff)
- [Hardenize: Comprehensive web site configuration test](https://www.hardenize.com/report/dlacbic.gov.in/1747797288#domain_dns_zone)  
 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/a/f/af683599654ba4be6ff413631641ce87522ec451.png)

---

<div class="post-metadata">

**Author:** ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)\
**Post date:** [May 21, 2025, 3:39am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651/4 "2025-05-21T03:39:25Z")

</div>

Presently I believe this is the first issue to be solved, as Let's Encrypt uses [Multi-Perspective Validation Improves Domain Validation Security - Let's Encrypt](https://letsencrypt.org/2020/02/19/multi-perspective-validation.html)

Since these are Domain Validation (DV) certificates the [Domain Name System (DNS)](https://en.wikipedia.org/wiki/Domain_Name_System) is used extensively in the validation process as well a allowing us to assist here on [Let's Encrypt community](https://community.letsencrypt.org/).  
DNS Queries need to give **consistent** results from any location on the Internet, all your authoritative DNS Servers for the _Domain_ need to also give **consistent** results as well.

> [@Bruce5051](#):
>
> ### Edit
> 
> There are also significant DNS issues see these
> 
> - [Zonemaster](https://zonemaster.net/en/result/c52fa0f1994ede07)
> - [EDNS Compliance Tester](https://ednscomp.isc.org/ednscomp/45250534ff)
> - [Hardenize Report: dlacbic.gov.in](https://www.hardenize.com/report/dlacbic.gov.in/1747797288#domain_dns_zone)
> 
> ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/a/f/af683599654ba4be6ff413631641ce87522ec451.png)

---

<div class="post-metadata">

**Author:** ![ujjawal](https://avatars.discourse-cdn.com/v4/letter/u/ee7513/32.png) [@ujjawal](https://community.letsencrypt.org/u/ujjawal)\
**Post date:** [May 21, 2025, 3:47am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651/5 "2025-05-21T03:47:37Z")

</div>

so DNS server issue is the culprit right ? is it possible that DNS sever is blocking queries from some location because when i use dig command, from my host machine it gives me proper response and answers.

is it due to any geo blocking firwall ?

---

<div class="post-metadata">

**Author:** ![MikeMcQ](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mikemcq/32/52772_2.png) [@MikeMcQ](https://community.letsencrypt.org/u/MikeMcQ)\
**Post date:** [May 21, 2025, 10:14am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651/6 "2025-05-21T10:14:58Z")

</div>

> [@ujjawal](#):
>
> it was successfully renew from last 1 year. no configuration changed on server.

I don't see you ever getting a Let's Encrypt certificate. Only ones from Amazon or Sectigo

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/a/2/a2e692eca875547a098a40a90cf4cbc616bea84f.png)

Your previous thread ([see here](https://community.letsencrypt.org/t/issue-in-renewing/237459/3)) I described the changes you need to make to your CAA records to allow Let's Encrypt to issue a cert. That doesn't affect the error you describe in this thread but it will be a problem if you want a Let's Encrypt cert. Do you?

This thread's problem to the Let's Encrypt staging system is related to your DNS servers. Some of them do not reply properly. That is difficult to test with dig commands but see DNSViz Errors for detailed errors.

> **[abc.gov.in | DNSViz](https://dnsviz.net/d/abc.gov.in/dnssec/)**

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 20, 2025, 10:15am UTC](https://community.letsencrypt.org/t/issue-while-renew/237651/7 "2025-06-20T10:15:45Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
