Hi @hilla
Info is so important. And this is hitting the spot on my tooth that almost hurts.. This an issue we will see more and more of in the future until we can figure out how to enlighten administrators how to deal with world-wide validations.
If you don't mind me asking, what firewall is in use?
And secondly How are you blocking countries?
This is important information for the record.
BTW: There are ways to block entities without completely blocking entire geographic areas of the planet.
I see Mike and Peter have responded, and they are VERY intelligent folks. My questions are totally based on security "recon" and your response may help me/us find a way to share the message on firewall practices (that many sys admins do not share) that in the end can bolster your security and help a lot of other people too.
As to the question of the title of this thread, you log files will be a big help.
Hi Rip Leader
We use Sophos XGS Firewall.
I ended up allowing Sweden and Singapore yesterday and all appears to be working today.
I also added a heap of Lets Encrypt urls too.
That sounds odd. Can you give some examples? [To allow ACME http validation from any CA, just allow any IP to request /.well-known/acme-challenge via http]