I have been unable to renew the certificate for my domain because the acme-v02 API is intermittently unresponsive. I cannot reliably establish a connection to the API servers, making it impossible to renew my certificate.
I can reproduce these connection errors on my macbook, as well as my Synology which hosts my services.
Thanks for the reply. It's hard to know if this problem is specific to me or not, but I do see some activity on down detector that indicates others might also be seeing degraded performance.
Yep, that works on my synology (my macbook has a darwin traceroute with different options). Output there:
traceroute to acme-v02.api.letsencrypt.org (172.65.32.248), 30 hops max, 60 byte packets
1 192.168.86.1 (192.168.86.1) 0.224 ms 0.295 ms 0.284 ms
2 syn-192-063-066-001.res.spectrum.com (192.63.66.1) 10.730 ms 10.907 ms 12.539 ms
3 lag-62.hcr02ausutxla.netops.charter.com (24.27.12.101) 9.356 ms 11.051 ms 9.439 ms
4 lag-21.ausxtxir02r.netops.charter.com (24.28.90.74) 14.286 ms 10.813 ms 10.891 ms
5 lag-22.rcr01hstqtx02.netops.charter.com (24.175.41.48) 20.913 ms 20.889 ms 20.977 ms
6 lag-416-10.hstqtx0209w-bcr00.netops.charter.com (66.109.9.88) 22.477 ms lag-26-10.hstqtx0209w-bcr00.netops.charter.com (66.109.1.218) 21.621 ms lag-416-10.hstqtx0209w-bcr00.netops.charter.com (66.109.9.88) 21.435 ms
7 lag-800.pr0.hou50.netops.charter.com (66.109.5.236) 23.977 ms 17.668 ms 15.758 ms
8 syn-066-109-002-031.inf.spectrum.com (66.109.2.31) 43.228 ms 21.183 ms 21.275 ms
9 172.65.32.248 (172.65.32.248) 20.095 ms * 22.566 ms
Same -T -p 443 options? Because that's a TCP connection to that domain.
Is the curl to /directory still failing?
Transient problems are not unusual. Not sure how reliable down detector is when reporting only a few outages. LE issues over 7 million certs per day. They have automated health monitoring but sometimes low volume problems sneak under their reporting thresholds.
Yep, sudo traceroute -T -p 443 acme-v02.api.letsencrypt.org is consistently working from what I can tell. curl https://acme-v02.api.letsencrypt.org/directory is sometimes hanging on the other hand.
I think I know for sure that this is not a problem with let's encrypt, but with my ISP (spectrum). I ran mtr and observed high packet loss at the last hop before reaching the let's encrypt API: