# Renew Letsencrypt cert failed / removed & reinstalled everything

**URL:** <https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695>\
**Category:** Help\
**Created:** [October 23, 2020, 9:45pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695 "2020-10-23T21:45:55Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![timr1](https://avatars.discourse-cdn.com/v4/letter/t/3da27b/32.png) [@timr1](https://community.letsencrypt.org/u/timr1)\
**Post date:** [October 23, 2020, 9:45pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/1 "2020-10-23T21:45:55Z")

</div>

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. [https://crt.sh/?q=example.com](https://crt.sh/?q=example.com)), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:app-dev.sec.usace.army.mil

I ran this command:certbot --apache

It produced this output:Waiting for verification...  
Challenge failed for domain app-dev.sec.usace.army.mil  
http-01 challenge for app-dev.sec.usace.army.mil  
Cleaning up challenges  
Some challenges have failed.

IMPORTANT NOTES:

- The following errors were reported by the server:

My web server is (include version): apache 2.4

The operating system my web server runs on is (include version): redhat 7

My hosting provider, if applicable, is:aws

I can login to a root shell on my machine (yes or no, or I don't know):yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot):certbot 1.7.0

this was all working for the last few months now its hosed. uninstalled /removed all files /reinstalled  
dns is fine nslookup app-dev.sec.usace.army.mil  
Server: 172.31.0.2  
Address: 172.31.0.2#53

Non-authoritative answer:  
app-dev.sec.usace.army.mil canonical name = [ec2-3-213-47-79.compute-1.amazonaws.com](http://ec2-3-213-47-79.compute-1.amazonaws.com).  
Name: [ec2-3-213-47-79.compute-1.amazonaws.com](http://ec2-3-213-47-79.compute-1.amazonaws.com)  
Address: 172.31.57.144  
not sure how I hosed it..have other servers that work fine ..just renewed another .sec domain server this week

now I get the rate limit error..sigh

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [October 23, 2020, 9:56pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/2 "2020-10-23T21:56:28Z")

</div>

Hi @timr1

> [@timr1](#):
>
> Domain: app-dev.sec.usace.army.mil  
> Type: dns  
> Detail: DNS problem: SERVFAIL looking up CAA for sec.usace.army.mil

checking your domain via [sec.usace.army.mil - Make your website better - DNS, redirects, mixed content, certificates](https://check-your-website.server-daten.de/?q=sec.usace.army.mil) there are a lot of name server errors:

Server failures:

| Host | Type | IP-Address | is auth. | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| sec.usace.army.mil | | Server failure | yes | 3 | 0 |
| www.sec.usace.army.mil | | Server failure | yes | 3 | |

Name servers without TCP support - that's fatal, every authoritative name server must support tcp connections.

And

### 13. CAA - Entries

| Domainname | flag | Name | Value | ∑ Queries | ∑ Timeout |
| --- | --- | --- | --- | --- | --- |
| usace.army.mil | -2 | | Server failure - The name server was unable to process this query due to a problem with the name server | 3 | 0 |
| army.mil | -2 | | Server failure - The name server was unable to process this query due to a problem with the name server | 3 | 1 |
| mil | 0 | | no CAA entry found | 1 | 0 |

Server failures checking CAA entries.

If possible, create a CAA entry with your complete domain name. Then the parent checks are skipped.

Same result with unboundtest - [https://unboundtest.com/m/CAA/sec.usace.army.mil/4FG2ABGF](https://unboundtest.com/m/CAA/sec.usace.army.mil/4FG2ABGF)

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 23, 2020, 9:57pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/3 "2020-10-23T21:57:50Z")

</div>

I get a different IP:

```auto
Name: ec2-3-213-47-79.compute-1.amazonaws.com
Address: 3.213.47.79
Aliases: app-dev.sec.usace.army.mil

```

The IP you show is internal to only AWS.

I am able to reach the Internet IP via port 80.

But there may be some underlying DNS issues with that FQDN.  
see: [https://dnsviz.net/d/app-dev.sec.usace.army.mil/dnssec/](https://dnsviz.net/d/app-dev.sec.usace.army.mil/dnssec/)

[&2\* readers: Get involved; Be heard. It starts with: **if you read something you like, then like it ❤**]

---

<div class="post-metadata">

**Author:** ![timr1](https://avatars.discourse-cdn.com/v4/letter/t/3da27b/32.png) [@timr1](https://community.letsencrypt.org/u/timr1)\
**Post date:** [October 23, 2020, 10:11pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/4 "2020-10-23T22:11:11Z")

</div>

I show external dns working fine [treardon@lidar ~]$ nslookup app-dev.sec.usace.army.mil  
Server: 8.8.8.8  
Address: 8.8.8.8#53

Non-authoritative answer:  
app-dev.sec.usace.army.mil canonical name = ec2-3-213-47-79.compute-1.amazo [naws.com](http://naws.com).  
Name: [ec2-3-213-47-79.compute-1.amazonaws.com](http://ec2-3-213-47-79.compute-1.amazonaws.com)  
Address: 3.213.47.79  
& its public right now

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 23, 2020, 10:12pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/5 "2020-10-23T22:12:18Z")

</div>

> [@timr1](#):
>
> now I get the rate limit error..sigh

You need to test with the staging system (before using the production system).

The (little) good news, so far: There seems to be no CAA blocking issues 🙂

[&2\* readers: Get involved; Be heard. It starts with: **if you read something you like, then like it ❤**]

---

<div class="post-metadata">

**Author:** ![timr1](https://avatars.discourse-cdn.com/v4/letter/t/3da27b/32.png) [@timr1](https://community.letsencrypt.org/u/timr1)\
**Post date:** [October 23, 2020, 10:15pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/6 "2020-10-23T22:15:17Z")

</div>

the ip# is correct 3.213.47.79 (the other listed is the private aws ip#)  
its up here [http://3.213.47.79/](http://3.213.47.79/)  
just renewed another .sec.usace.army.mil this week

---

<div class="post-metadata">

**Author:** ![timr1](https://avatars.discourse-cdn.com/v4/letter/t/3da27b/32.png) [@timr1](https://community.letsencrypt.org/u/timr1)\
**Post date:** [October 23, 2020, 10:17pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/7 "2020-10-23T22:17:00Z")

</div>

[http://3.213.47.79/](http://3.213.47.79/) is up others are up with the domain .sec.usace.army.mil  
right now I get the rate error ..so Ill wait till tha clears

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 23, 2020, 10:30pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/8 "2020-10-23T22:30:04Z")

</div>

@griffin, please help me here.  
I want to say: Please try: `certbot --apache --dry-run`  
But that is not an allowed combination or elements (it creates havoc) - LOL

Maybe try this until we hear from "the expert":  
`certbot certonly -a apache --dry-run`

[&2\* readers: Get involved; Be heard. It starts with: **if you read something you like, then like it ❤**]

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 23, 2020, 10:40pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/9 "2020-10-23T22:40:41Z")

</div>

# Test

`sudo certbot certonly --cert-name app-dev.sec.usace.army.mil --apache --dry-run`

You most likely won't get a rate limit error when testing.

# Live

`sudo certbot run --cert-name app-dev.sec.usace.army.mil --apache --keep-until-expiring`

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 23, 2020, 10:51pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/10 "2020-10-23T22:51:49Z")

</div>

> [@timr1](#):
>
> SERVFAIL looking up CAA for sec.usace.army.mil

This has been really common lately.

[@lestaff](https://community.letsencrypt.org/groups/lestaff)

.mil subdomain (app-dev.sec.usace.army.mil) running into CAA and general nameserver errors. Any thoughts here?

---

<div class="post-metadata">

**Author:** ![JamesLE](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jamesle/32/49364_2.png) [@JamesLE](https://community.letsencrypt.org/u/JamesLE)\
**Post date:** [October 23, 2020, 11:11pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/11 "2020-10-23T23:11:52Z")

</div>

> [@griffin](#):
>
> .mil subdomain (app-dev.sec.usace.army.mil) running into CAA and general nameserver errors.

Yes, we've seen this a number of times before with certain .mil domains and their subdomains, including army.mil. I second @JuergenAuer's suggestion above:

> [@JuergenAuer](#):
>
> If possible, create a CAA entry with your complete domain name.

But even with that workaround in place, the DNSSEC chain will need to validate properly and the authoritative nameservers will need to support EDNS, or there will still be SERVFAILs:

> [@rg305](#):
>
> there may be some underlying DNS issues with that FQDN.  
> see: [app-dev.sec.usace.army.mil | DNSViz](https://dnsviz.net/d/app-dev.sec.usace.army.mil/dnssec/)

I'm afraid things are not going to work reliably without standards-compliant authoritative DNS.

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 23, 2020, 11:18pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/12 "2020-10-23T23:18:46Z")

</div>

Thanks for the prompt response, James. 🙂 Always highly appreciated.

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 23, 2020, 11:37pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/13 "2020-10-23T23:37:39Z")

</div>

> **[EDNS Compliance Tester](https://ednscomp.isc.org/ednscomp/c7fe1f5f77)**

  

> **[EDNS Compliance Tester](https://ednscomp.isc.org/ednscomp/aedb4a0426)**

I think you should try changing the CNAME to an A record and see if that helps.

[&2\* readers: Get involved; Be heard. It starts with: **if you read something you like, then like it ❤**]

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 23, 2020, 11:56pm UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/14 "2020-10-23T23:56:05Z")

</div>

Absolutely, @rg305. Makes sense to me.

---

<div class="post-metadata">

**Author:** ![timr1](https://avatars.discourse-cdn.com/v4/letter/t/3da27b/32.png) [@timr1](https://community.letsencrypt.org/u/timr1)\
**Post date:** [October 24, 2020, 12:34am UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/15 "2020-10-24T00:34:10Z")

</div>

it has to be a CNAME cause its an aws ec2 alias to it

---

<div class="post-metadata">

**Author:** ![timr1](https://avatars.discourse-cdn.com/v4/letter/t/3da27b/32.png) [@timr1](https://community.letsencrypt.org/u/timr1)\
**Post date:** [October 24, 2020, 12:36am UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/16 "2020-10-24T00:36:45Z")

</div>

for now I got the orig letsencrypt certs back in place with an exp of 11/10/20  
it was issued 8/12/20...so there never was a dns issue...for now its ok again.  
had been renewing fine for a year or so..will try again monday..thanks for all the input

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 24, 2020, 1:42am UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/17 "2020-10-24T01:42:12Z")

</div>

> [@timr1](#):
>
> it has to be a CNAME cause its an aws ec2 alias to it

I do understand that.  
My recommendation was simply to try it as an A record - just to see if that helped obtain the cert.  
Not to switch it permanently to an A record.

[&2\* readers: Get involved; Be heard. It starts with: **if you read something you like, then like it ❤**]

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 24, 2020, 1:45am UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/18 "2020-10-24T01:45:48Z")

</div>

Certainly worth trying. 🙂

---

<div class="post-metadata">

**Author:** ![rg305](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rg305/32/91314_2.png) [@rg305](https://community.letsencrypt.org/u/rg305)\
**Post date:** [October 24, 2020, 1:48am UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/19 "2020-10-24T01:48:25Z")

</div>

This needs a fix before that cert expires... Nov 10th is not that far away.  
It's just not anything I can control ☹

[&2\* readers: Get involved; Be heard. It starts with: **if you read something you like, then like it ❤**]

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [October 24, 2020, 1:52am UTC](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695/20 "2020-10-24T01:52:48Z")

</div>

> [@rg305](#):
>
> It's just not anything I can control

Story of my life, brother. 😉

[Next page](https://community.letsencrypt.org/t/renew-letsencrypt-cert-failed-removed-reinstalled-everything/136695.md?page=2)
