Are those compatible with IPv6 only too ?
I don't have any explicit blocking and my subnet is globally reachable so I don't really understand why I don't see them coming.
I could test reachability from various points (like AWS) and did not have any issues.
The DNS may be but the AAAA address is not reachable by various Let's Encrypt server farms
The increase to 5 vantage points (from 3) just went into Staging a couple days ago but not yet in production according to the post @Osiris linked. So, you should be seeing 3 or at least 2 right now in production.
That said, a test using Let's Debug (link here) uses staging and also gets timeout
I see your DNS CNAMEs. Which is fine. Can you contact the people that run that IPv6 address and check their firewall logs? You could run Let's Debug test and have them check the logs for that time to see how many (should see 5 incoming requests)
nslookup docs.keda.re
docs.keda.re canonical name = nc1.mlg1.es.net.keda.re.
nc1.mlg1.es.net.keda.re canonical name = ens18.nc1.mlg1.es.v6.net.keda.re.
Name: ens18.nc1.mlg1.es.v6.net.keda.re
Address: 2001:67c:da8:1004:b474:eff:fe14:9ad3
By getting the challenge I mean I do receive the challenge http request (over IPv6 as expected, as I don't have IPv4 on this part)
I tested with let's debug, I do see 3 requests coming fine in my http logs (but 404 as expected) but the systems still says there is an issue : Let's Debug
Ok it looks like some of the let's encrypt servers cannot be reached from my ASN, this is strange (I see the traffic coming and leaving my network but looks like it's dropped/blocked somewhere in transit on the return packets for some of the let's encrypt server).
I will investigate with my transit provider.
PCAP from my link to my transit acme.pcap (30.3 KB)
I agree with your deduction, looking at the SYN,ACK replies from your server, but the repetitive SYN retransmissions from the Let's Encrypt servers, which includes the primary validation location from within the US at Flexential.
Note the increased number of vantage points from Staging is still rolling out.
As this rolls out a successful challenge from staging should show 3 to 5 challenges in your logs. Production right now should show 2-3 but will change to 3 to 5 when that begins to roll out the expanded vantage points (schedule tbd).
When the increased vantage points are fully rolled out you should see 4-5 for a successful challenge