Hi, my auto renewals have starting failing with the output below. I previously did not have a CAA record so I tried adding one for letsencrypt.org but it is still failing. Any advice on how to resolve very appreciated.
My domain is: apps.epicentre-msf.org
I ran this command: sudo certbot renew --dry-run
It produced this output:
Simulating renewal of an existing certificate for apps.epicentre-msf.org
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: apps.epicentre-msf.org
Type: dns
Detail: During secondary validation: DNS problem: SERVFAIL looking up CAA for apps.epicentre-msf.org - the domain's nameservers may be malfunctioning
Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.
My web server is (include version): nginx/1.18.0 (Ubuntu)
The operating system my web server runs on is (include version): Ubuntu 22.04.2 LTS (GNU/Linux 5.19.0-1026-aws x86_64)
My hosting provider, if applicable, is: AWS
I can login to a root shell on my machine (yes or no, or I don't know): yes
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): no
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot): certbot 2.10.0