# Query timeout with DNSSEC enabled

**URL:** <https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762>\
**Category:** Help\
**Created:** [May 5, 2020, 11:12am UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762 "2020-05-05T11:12:49Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![niyawe](https://avatars.discourse-cdn.com/v4/letter/n/b3f665/32.png) [@niyawe](https://community.letsencrypt.org/u/niyawe)\
**Post date:** [May 5, 2020, 11:12am UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/1 "2020-05-05T11:12:50Z")

</div>

I originally posted this [here](https://community.letsencrypt.org/t/during-secondary-validation-dns-problem-query-timed-out-looking-up-a/121249/18) but it turns out, I have a different problem.

Since two days, i cannot create or renew any certificates for [niyawe.de](http://niyawe.de). (DNS problem: query timed out looking up TXT for \_acme-challenge.aaaaaa.niyawe.de) While I can create new certificates for niyawe.tk.  
I use [dehydrated](https://github.com/dehydrated-io/dehydrated) with a dns-hook-script and the same nameservers for both domains.

The only difference is, that [niyawe.de](http://niyawe.de) is [correctly](http://dnsviz.net/d/niyawe.de/dnssec/) signed using DNSSEC.

My hosting provider is Hetzner. Since this is a common question: I am also not blocking any IPs.

The last successful renew for [niyawe.de](http://niyawe.de) was on 2020-04-29. I haven’t changed anything on my side since then.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [May 5, 2020, 11:37am UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/2 "2020-05-05T11:37:27Z")

</div>

Is there any chance you can post another pcap, not filtered by host if possible?

In your previous one, there’s only two peers - your server and one AWS validation server. There should be 4 validation servers making an appearance (3 from AWS and 1 from Viawest).

I acknowledge that you’ve said that you are not blocking any addresses, but the pcap would help pin down what’s happening. Even if it looks totally normal, that’s a help.

---

<div class="post-metadata">

**Author:** ![niyawe](https://avatars.discourse-cdn.com/v4/letter/n/b3f665/32.png) [@niyawe](https://community.letsencrypt.org/u/niyawe)\
**Post date:** [May 5, 2020, 12:52pm UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/3 "2020-05-05T12:52:51Z")

</div>

[acme-challenge.pcapng](https://community.letsencrypt.org/uploads/short-url/sHiF2KdRafGPGeMfsdQBhtMOXF0.pcapng) (1.3 MB)

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [May 5, 2020, 10:13pm UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/4 "2020-05-05T22:13:58Z")

</div>

Thanks. Don’t have any strong conclusions, though.

Looks like all the validation servers can reach this nameserver.

One weird thing is the [RST,ACK] at the end of every TCP conversation, but that just might be some NAT oddity - both peers are behind NAT.

The other thing is that some of the DNS responses are _very_ large, like 6KB. For some reason, when a query with the `norecurse` flag is sent, your nameserver comes back with a full authority & additional section, which gets kind of huge when the response is also authenticated. I don’t think that’s necessary and could cause Let’s Encrypt’s query deadline to get exceeded?

Finally I noticed that every time I query your nameservers locally, the TCP segments come back out of order, which produces a noticable delay. But I can’t really reproduce it from other networks so meh 🤷‍♂️.

---

<div class="post-metadata">

**Author:** ![mnordhoff](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/mnordhoff/32/22583_2.png) [@mnordhoff](https://community.letsencrypt.org/u/mnordhoff)\
**Post date:** [May 5, 2020, 11:06pm UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/5 "2020-05-05T23:06:10Z")

</div>

Maybe Let’s Encrypt kills out of order packets for some reason?

---

<div class="post-metadata">

**Author:** ![niyawe](https://avatars.discourse-cdn.com/v4/letter/n/b3f665/32.png) [@niyawe](https://community.letsencrypt.org/u/niyawe)\
**Post date:** [May 6, 2020, 4:28pm UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/6 "2020-05-06T16:28:21Z")

</div>

I just replaced my 4096bit Zone Signing Key with a 2048bit-Key to reduce the size of the answer and now it works. So there is an undocumented size limit. And it only exists since a few days. Nice. Please fix that.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [May 7, 2020, 9:58pm UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/7 "2020-05-07T21:58:56Z")

</div>

> [@niyawe](#):
>
> Please fix that.

> [@During secondary validation: No valid IP addresses found](https://community.letsencrypt.org/t/during-secondary-validation-no-valid-ip-addresses-found/121881/8):
>
> L…

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 6, 2020, 9:59pm UTC](https://community.letsencrypt.org/t/query-timeout-with-dnssec-enabled/121762/8 "2020-06-06T21:59:06Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
