Please query the authoritative DNS(SEC) with dns-01

Or you could go back and edit the paragraphs out of your response and post a summary of what was edited out. That would improve the readability of the thread for some person in the future who has the same setup as you and is searching the forums for help.

5 Likes

I hope you are not using 1.0.0.1 and 1.1.1.1 (Cloudflare) as resolvers, because I've been monitoring them this evening and they are really slow to update. The SOA Refresh time has passed three times, and they are not updating. Other resolvers, line 8.8.8.8 (Google) are OK. There is no way I can wait for Cloudflare, as they only know if and when they refresh.

You can also try (the new DNS guy in town) 9.9.9.9
[which just happens to look like (8.8.8.8 plus 1.1.1.1) - now that's marketing!]

3 Likes

If with "you" you mean "Let's Encrypt": they don't use that kind of resolvers at all. They use a local instance of Unbound to crawl the DNS hierarchy starting with the root ., just like dig +trace would. See https://unboundtest.com/ to generate an example; it's configured to match the Unbound configuration used by Boulder, the Let's Encrypt ACME software.

Asking if LE uses Cloudflare as resolvers proves to me you still don't understand the DNS resolving mechanism used by Let's Encrypt.

8 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.