LE is complaining that CAA prevents issuance during renewal. CAA has not changed last renewal, nor has certbot, its configuration., or the DNS records for the certificate.
CAA records are
litts.net. 600 IN CAA 128 iodef "mailto:security@litts.net"
litts.net. 600 IN CAA 128 issuewild "letsencrypt.org"
litts.net. 600 IN CAA 128 issue "letsencrypt.org"
Verified visible from multiple external systems. Verified OK with dnsviz.net (for DNSSEC).
The last successful renewal was 26-Mar-2023.
Has Boulder changed its CNAME processing, e.g. reduced tree climbing? If so, what are the minimal zones that need CAA records to make Boulder happy?
What's particularly odd is that NONE of the 6 domains requested in the certificate are accepted. So if is a tree-climbing issue, I would expect the non-CNAME domains too be happy...
My domain is: litts.net
The requested certificate:
Subject: CN = wikiworld.litts.net
Subject Alternative Name:
DNS:wikiworld.litts.net,
DNS:wikiworld.sb.litts.net,
DNS:wikiworld.v4.litts.net,
DNS:wikiworld.v4.sb.litts.net,
DNS:wikiworld.v6.litts.net,
DNS:wikiworld.v6.sb.litts.net
I ran this command:
certbot -n renew
It produced this output:
Renewing an existing certificate for wikiworld.litts.net and 5 more domains
Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems:
Domain: wikiworld.litts.net
Type: caa
Detail: CAA record for litts.net prevents issuance
Domain: wikiworld.sb.litts.net
Type: caa
Detail: CAA record for litts.net prevents issuance
Domain: wikiworld.v4.litts.net
Type: caa
Detail: CAA record for litts.net prevents issuance
Domain: wikiworld.v4.sb.litts.net
Type: caa
Detail: CAA record for litts.net prevents issuance
Domain: wikiworld.v6.litts.net
Type: caa
Detail: CAA record for litts.net prevents issuance
Domain: wikiworld.v6.sb.litts.net
Type: caa
Detail: CAA record for litts.net prevents issuance
The logfile doesn't reveal anything else of obvious interest.
My web server is (include version):
apache
The operating system my web server runs on is (include version):
Linux
I can login to a root shell on my machine (yes or no, or I don't know):
Yes
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): certbot 1.32.0