# My main domain has SSL and my subdomain dont have SSL

**URL:** https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507
**Category:** Help
**Created:** [March 14, 2023, 9:56pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507 "2023-03-14T21:56:13Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:04pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/22 "2023-03-14T23:04:29Z")

</div>

> [@Nolife159159](#):
>
> also i run this `sudo certbot certonly --manual` and entered vvp.lerg.lt and i got this
> 
> ```nohighlight
> jmOIQ_y9IoGfem1DN-1cPp1X6SQ7PMTTzDUV1jjO3gw.BTYdvn8zv5JjwijnYjvL-ins8n0hk9rW3loEY8biQOY
> 
> ```
> 
> so do i need to create DNS with name \_acme-challenge.vvp.lerg.lt as TXT and that what i got for an value ?

At that point you need to manually edit your DNS Records and add a TXT Record for` _acme-challenge.vvp.lerg.lt` with contents of  
`jmOIQ_y9IoGfem1DN-1cPp1X6SQ7PMTTzDUV1jjO3gw.BTYdvn8zv5JjwijnYjvL-ins8n0hk9rW3loEY8biQOY`

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:05pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/23 "2023-03-14T23:05:37Z")

</div>

> [@Nolife159159](#):
>
> `sudo certbot certonly --manual --preferred-challenges dns -d lerg.lt -d "*.lerg.lt"`

well i run this and got almost the same thing

```nohighlight
Challenge failed for domain lerg.lt
dns-01 challenge for lerg.lt
Cleaning up challenges
Some challenges have failed.

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: lerg.lt
   Type: unauthorized
   Detail: No TXT record found at _acme-challenge.lerg.lt

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address.

```

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:05pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/24 "2023-03-14T23:05:55Z")

</div>

Yeah i added that

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:07pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/25 "2023-03-14T23:07:47Z")

</div>

> [@Nolife159159](#):
>
> well i run this and got almost the same thing

OK; but that manual DNS edit of adding a TXT record will only be one for all of the domain name (and its subdomains) lerg.lt.

So how do you edit your DNS Records?

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:09pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/26 "2023-03-14T23:09:07Z")

</div>

> [@Bruce5051](#):
>
> So how do you edit your DNS Records?

i can edit those from the Hosting site where i have my server hosted

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:11pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/27 "2023-03-14T23:11:34Z")

</div>

> [@Bruce5051](#):
>
> OK; but that manual DNS edit of adding a TXT record will only be one for all of the domain name (and its subdomains) lerg.lt.

well if i run `sudo certbot certonly --manual` and enter `lerg.lt` i get this

```nohighlight
Cert not yet due for renewal

You have an existing certificate that has exactly the same domains or certificate name you requested and isn't close to expiry.
(ref: /etc/letsencrypt/renewal/lerg.lt-0001.conf)

What would you like to do?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Keep the existing certificate for now
2: Renew & replace the certificate (may be subject to CA rate limits)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel):

```

what i should chose here ?

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:12pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/28 "2023-03-14T23:12:20Z")

</div>

Presently there is not DNS TXT for the domain name **\_acme-challenge.lerg.lt**

As shown here:  
[https://unboundtest.com/m/TXT/\_acme-challenge.lerg.lt/TYNT6FT4](https://unboundtest.com/m/TXT/_acme-challenge.lerg.lt/TYNT6FT4)

````plaintext
Query results for TXT _acme-challenge.lerg.lt

Response:
;; opcode: QUERY, status: NOERROR, id: 4452
;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0

;; QUESTION SECTION:
;_acme-challenge.lerg.lt.	IN TXT

;; AUTHORITY SECTION:
lerg.lt.	0	IN	SOA	ns1.serveriai.lt. hostmaster.iv.lt. 2023031500 43200 3600 1209600 3600

----- Unbound logs -----
Mar 14 23:10:41 unbound[715086:0] notice: init module 0: validator
Mar 14 23:10:41 unbound[715086:0] notice: init module 1: iterator```
````

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:15pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/29 "2023-03-14T23:15:13Z")

</div>

also i added this

 ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/5/e/5eb0646889b814f460e2a832ccc55f035a75f2ca.png)  
to DNS

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:15pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/30 "2023-03-14T23:15:52Z")

</div>

> [@Nolife159159](#):
>
> what i should chose here ?

Sorry. ☹  
Definitely wait for more knowledgeable Let's Encrypt community volunteers to assist.

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:16pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/31 "2023-03-14T23:16:30Z")

</div>

> [@Bruce5051](#):
>
> Definitely wait for more knowledgeable Let's Encrypt community volunteers to assist

Yeah ;( i will wait

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:17pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/32 "2023-03-14T23:17:48Z")

</div>

> [@Nolife159159](#):
>
> also i added this
> 
> ![image](https://global.discourse-cdn.com/letsencrypt/original/3X/5/e/5eb0646889b814f460e2a832ccc55f035a75f2ca.png)
> 
> to DNS

That would be for and only for vvp.lerg.lt

Also each time (not quite correct but close) that challenge token changes.

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:18pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/33 "2023-03-14T23:18:39Z")

</div>

> [@Bruce5051](#):
>
> That would be for and only for vvp.lerg.lt

Yeah i know but i can't generate for lerg.lt

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:20pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/34 "2023-03-14T23:20:27Z")

</div>

> [@Bruce5051](#):
>
> Also each time (not quite correct but close) that challenge token changes

so each time i need to generate new token ?

---

<div class="post-metadata">

### Author: ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)
#### Post date: [March 14, 2023, 11:20pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/35 "2023-03-14T23:20:29Z")

</div>

Let's back up a bit. Why are you using DNS validation? Because the way you're choosing to validate your domain, you'll need to manually create (and then delete) a DNS TXT record every time you want to renew the cert, which will be roughly every 60 days. That really isn't a desirable situation. Is there a reason you can't use the more common HTTP validation?

If you **do** need to use DNS validation, certbot will tell you what records you need to create. When it tells you that, you need to create them. Once you've done that, you can tell certbot to proceed, and it will issue the cert. You'll then need to delete those records. Next time you create (or renew) the cert, you'll need to do the same thing again. And again. And again.

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:21pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/36 "2023-03-14T23:21:47Z")

</div>

The good news is the Addition/Edit works, so you know how to do it;  
now just or \_acme-challenge.lerg.lt instead with the token supplied for the challenge that round.

[https://unboundtest.com/m/TXT/\_acme-challenge.vvp.lerg.lt/GYOHTPVJ](https://unboundtest.com/m/TXT/_acme-challenge.vvp.lerg.lt/GYOHTPVJ)

````plaintext
Query results for TXT _acme-challenge.vvp.lerg.lt

Response:
;; opcode: QUERY, status: NOERROR, id: 38067
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;_acme-challenge.vvp.lerg.lt.	IN TXT

;; ANSWER SECTION:
_acme-challenge.vvp.lerg.lt.	0	IN	TXT	"jmOIQ_y9IoGfem1DN-1cPp1X6SQ7PMTTzDUV1jjO3gw.BTYdvn8zv5JjwijnYjvL-ins8n0hk9rW3loEY8biQOY"

----- Unbound logs -----
Mar 14 23:19:19 unbound[715158:0] notice: init module 0: validator
Mar 14 23:19:19 unbound[715158:0] notice: init module 1: iterator
Mar 14 23:19:19 unbound[715158:0] info: start of service (unbound 1.16.3).```
````

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:22pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/37 "2023-03-14T23:22:07Z")

</div>

> [@danb35](#):
>
> Let's back up a bit. Why are you using DNS validation? Because the way you're choosing to validate your domain, you'll need to manually create (and then delete) a DNS TXT record every time you want to renew the cert, which will be roughly every 60 days. That really isn't a desirable situation. Is there a reason you can't use the more common HTTP validation?

Well im not sure what else can i use first time using certbot any sugestions?

---

<div class="post-metadata">

### Author: ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)
#### Post date: [March 14, 2023, 11:23pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/38 "2023-03-14T23:23:25Z")

</div>

Well, you could try without the `--preferred-challenges dns` part. Why are you using that?

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:23pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/39 "2023-03-14T23:23:57Z")

</div>

> [@Bruce5051](#):
>
> now just or \_acme-challenge.lerg

im not sure how can i get token for \_acme-challenge.lerg.lt cause i m getting this

```nohighlight
Please enter in your domain name(s) (comma and/or space separated) (Enter 'c'
to cancel): lerg.lt
Cert not yet due for renewal

You have an existing certificate that has exactly the same domains or certificate name you requested and isn't close to expiry.
(ref: /etc/letsencrypt/renewal/lerg.lt-0001.conf)

What would you like to do?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Keep the existing certificate for now
2: Renew & replace the certificate (may be subject to CA rate limits)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 

```

---

<div class="post-metadata">

### Author: ![Nolife159159](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/nolife159159/32/66946_2.png) [@Nolife159159](https://community.letsencrypt.org/u/Nolife159159)
#### Post date: [March 14, 2023, 11:25pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/40 "2023-03-14T23:25:03Z")

</div>

> [@Nolife159159](#):
>
> `sudo certbot certonly --manual --preferred-challenges dns -d lerg.lt -d "*.lerg.lt"`

so u mean i can try running this:

```nohighlight
sudo certbot certonly --manual -d lerg.lt -d "*.lerg.lt"

```

---

<div class="post-metadata">

### Author: ![Bruce5051](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/bruce5051/32/76576_2.png) [@Bruce5051](https://community.letsencrypt.org/u/Bruce5051)
#### Post date: [March 14, 2023, 11:25pm UTC](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507/41 "2023-03-14T23:25:25Z")

</div>

Follow @danb35 at this point.

[Previous page](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507.md?page=1)

[Next page](https://community.letsencrypt.org/t/my-main-domain-has-ssl-and-my-subdomain-dont-have-ssl/194507.md?page=3)
