The problem I was looking at in this thread is that one CAA error (for admin.mrhs.hwrsd.org
) was duplicated many times into other subproblems. We're going to be working on that issue this sprint.
I actually hadn't realized that the nameservers for hwrsd.org
are ns56.worldnic.com.
and ns55.worldnic.com.
That suggests that the reason that one hostname is failing CAA recheck is probably indeed related to DNS failures (SERVFAIL, timeout) for domains using Network Solutions/Web.com/worldnic.com nameservers. I suspect that if you removed that domain (assuming the other domains on this certificate are not using worldnic), the certificate overall should issue fine.