Hi everyone,
My domain is: pop3.robinson.it
I ran this command: sudo ./certbot-auto certonly --agree-tos --rsa-key-size 4096 --renew-by-default -m hostmaster@robinson.it --webroot -w /var/www/html/ -d pop3.robinson.it --renew-by-default --test-cert
It produced this output:
Domain: pop3.robinson.it
Type: connection
Detail: DNS problem: SERVFAIL looking up CAA for pop3.robinson.it
My operating system is: Ubuntu 12.04.4 LTS
My web server is: Apache/2.2.22
My hosting provider: myself
I’ve read many post on https://community.letsencrypt.org/search?q=caa without finding a reply.
I don’t have DNSSEC/CAA, from other topics this doesn’t seems to be a problem. Tell me if I’m wrong.
Being a provider, I checked my dns from an external site, the answer for CAA record is NOERROR
dig @8.8.8.8 poP3.roBinson.it caa
; <<>> DiG 9.9.5-3ubuntu0.1-Ubuntu <<>> @8.8.8.8 poP3.roBinson.it caa
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 14254
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;poP3.roBinson.it. IN A
;; ANSWER SECTION:
poP3.roBinson.it. 84782 IN A 89.96.131.132
;; Query time: 47 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Thu Apr 13 09:57:25 CEST 2017
;; MSG SIZE rcvd: 61
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 51039
;; flags: qr rd ra ad; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;caa. IN A
;; AUTHORITY SECTION:
. 86397 IN SOA a.root-servers.net. nstld.verisign-grs.com. 2017041300 1800 900 604800 86400
;; Query time: 37 msec
;; SERVER: 8.8.8.8#53(8.8.8.8)
;; WHEN: Thu Apr 13 09:57:25 CEST 2017
;; MSG SIZE rcvd: 107
this digs from my ns1.robinson.it, not recursive DNS server
same reply for ns2.robinson.it
dig @ns1.robinson.it poP3.roBinson.it caa
; <<>> DiG 9.9.5-3ubuntu0.1-Ubuntu <<>> @ns1.robinson.it poP3.roBinson.it caa
; (1 server found)
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 911
;; flags: qr aa rd; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000
;; QUESTION SECTION:
;poP3.roBinson.it. IN A
;; ANSWER SECTION:
poP3.roBinson.it. 86400 IN A 89.96.131.132
;; Query time: 16 msec
;; SERVER: 89.96.131.135#53(89.96.131.135)
;; WHEN: Thu Apr 13 10:00:13 CEST 2017
;; MSG SIZE rcvd: 61
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 3238
;; flags: qr aa rd; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 1
;; WARNING: recursion requested but not available
;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4000
;; QUESTION SECTION:
;caa. IN A
;; AUTHORITY SECTION:
. 3600 IN SOA webm01. hostmaster. 228 900 600 86400 3600
;; Query time: 15 msec
;; SERVER: 89.96.131.135#53(89.96.131.135)
;; WHEN: Thu Apr 13 10:00:13 CEST 2017
;; MSG SIZE rcvd: 83
please help me to address the problem.