Lets encrypt issue google cloud vm instance

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:krizovany.online

I ran this command:i following default script via ssh connection

Do you wish to issue a Let's encrypt certificate for this domain? [y/N] y
[OK] krizovany.online is accessible.
[OK] www.krizovany.online is accessible.

It produced this output:
Using the webroot path /var/www/html for all unmatched domains.
Waiting for verification...
Challenge failed for domain www.krizovany.online
Challenge failed for domain krizovany.online
http-01 challenge for www.krizovany.online
http-01 challenge for krizovany.online
Cleaning up challenges
Some challenges have failed.


  • The following errors were reported by the server:

    Domain: www.krizovany.online
    Type: dns
    Detail: DNS problem: SERVFAIL looking up A for www.krizovany.online

    • the domain's nameservers may be malfunctioning

    Domain: krizovany.online
    Type: dns
    Detail: DNS problem: SERVFAIL looking up A for krizovany.online -
    the domain's nameservers may be malfunctioning
    Oops, something went wrong...

My web server is (include version):


Operating System

Ubuntu (20.04)


WordPress (5.5)

PHP (7.4)

OpenLiteSpeed (1.6.15)

phpMyAdmin (5.0.2)

MariaDB (10.4)

Redis (5.0.7)

Memcached (1.5.22)

CertBot (0.40.0)

The operating system my web server runs on is (include version):
Ubuntu 20.04

My hosting provider, if applicable, is:
google cloud vm instance openlitespeed

domain registrar is websupport.sk

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):
CertBot (0.40.0)

cloud dns records

Your DNSSEC is broken: https://dnsviz.net/d/krizovany.online/dnssec/

While DNSSEC isn't mandatory when requesting a LE cert, when it does exist somewhere, it needs to function properly.

1 Like

I don't know how it broke, nor how to fix it, but DNS is broken - even Google DNS can't resolve it:

nslookup krizovany.online ns-cloud-c1.googledomains.com
Name:    krizovany.online

nslookup krizovany.online
*** dns.google can't find krizovany.online: Server failed

-i think i have requested dnssec key on my domain registrar by mistake...i have deleted it now, so i will see if its help
-on server DNSsEC is off

1 Like

thanks, now its working, ssl installed successfully, i had to delete cloud dns zone on my vm instance and created a new one, after that i pointed a new ns records to my domain registrar


This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.