Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. crt.sh | example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.
This post is being made by SFMC Account Engagement support on behalf of a customer - RealPage, Inc.
My domain is: realpage.com (root domain)
SSL certificate is to be issued for sub domain - success.realpage.com
I ran this command: Subdomain is added to Salesforce Marketing Cloud Account Engagement application as a tracker domain. When we try to issue the domain a certificate, we get the following error:
{"type":"urn:ietf:params:acme:error:dns","detail":"DNS problem: query timed out looking up CAA for realpage.com","instance":"","code":400}
It produced this output: SSL error, certificate is not getting issued. Root domain does not have a CAA record so SSL should get issued. However since this is query timed out error no checks can be made on the root domain resulting in the SSL error.
My web server is (include version): Not applicable (customer provided answer)
The operating system my web server runs on is (include version): Not applicable (customer provided answer)
My hosting provider, if applicable, is: Not applicable (customer provided answer)
I can login to a root shell on my machine (yes or no, or I don't know): Yes (customer provided answer)
I'm using a control panel to manage my site (no, or provide the name and version of the control panel): No (customer provided answer)
The version of my client is (e.g. output of certbot --version
or certbot-auto --version
if you're using Certbot): Not answered