We use our own client and it works well almost all of the time. However, I have one recent domain that I can’t seem to figure out. The cert is for sheboygan.wiki, www.sheboygan.wiki, and ftp.sheboygan.wiki. For some reason the authorization for www.sheboygan.wiki gets stuck in the pending state infinitely while the other two validate normally.
Can’t figure this out for the life of me. Any help would be wonderful. Thanks.
Does your custom client look at the individual challenge state to determine when the authorization is ready, or the overall authorization state? If it’s the former you might be running into this Boulder bug we identified yesterday. If that’s the case I recommend switching to checking the authorization state instead of the challenge state in the short-term while the bug is addressed.
Yup, this looks like an instance of Boulder issue #3346. Apologies
Your client should be able to operate on the top level authorization status short-term, which in this case is the correct "valid" state despite the challenges being recorded as pending.