Hi, I m going mad. When I try to get my SSL certificate I get:
Invalid response from https://acme-v02.api.letsencrypt.org/acme/authz-v3/11086819742. Details: Type: urn:ietf:params:acme:error:dns Status: 400 Detail: DNS problem: SERVFAIL looking up A for - the domain's nameservers may be malfunctioning
Yesterday I tried to set up this DNSKEY but apparently I did something wrong so I deleted all I had done. Is maybe this Key the reason? Thank you so much
Thanks _az I think it is plesk. Disable DNSSEC? I deleted the DS I created related to this DNSKEY. Actually I migrated my domain and from there I have this problem. Even before I tried to create the DNSKEY I had this and there are no DS on my DNSSEC
Fatal error: Parent zone has a signed DS RR (Algorithm 13, KeyTag 2286, DigestType 2, Digest xNsU2ILKpwie6vliJVbMWWJwMr57wLMSMLNN+XzEqvU=), but the destination DNSKEY doesn't exist or doesn't validate the DNSKEY RR set. No chain of trust created.
DNSSEC has two fundamental parts: A DS RR in the parent zone and a matching DNSKEY in the signed zone.
So if you migrate your domain and if you create a new DNSKEY, you (or your registrar) must update the DS RR in the parent zone. Or must remove the DS RR -> zone is not longer signed.
Normally:
Disable DNSSEC on your old DNS provider, check, if the missing DS is propagated
Thank you. On my old registrar they told me that the domain is already transferred and today my subscription expires. I ve found that this signature exipires the 1st of march. Are these signatures autorenew? Or normally even if I cant find this DS RR (that is not displaying on my DNSSEC) it will disapear on this date?
Wait, registrars continue publishing DNS RRs for domains that are no longer registered through them? That doesn't seem like something registries (or customers) would like very much...