# Unable to generate a wildcard certificate using cloudflare DNS Challenge

**URL:** <https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336>\
**Category:** Help\
**Created:** [September 18, 2023, 1:17pm UTC](https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336 "2023-09-18T13:17:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![xd003](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xd003/32/72821_2.png) [@xd003](https://community.letsencrypt.org/u/xd003)\
**Post date:** [September 18, 2023, 1:17pm UTC](https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336/1 "2023-09-18T13:17:39Z")

</div>

I ran this command: `sudo certbot certonly --dns-cloudflare --dns-cloudflare-credentials /opt/secrets/cloudflare.ini -d xd003.site -d *.xd003.site -d *.adguard.xd003.site --preferred-challenges dns-01`  
and got the follwing output

```plaintext
Certbot failed to authenticate some domains (authenticator: dns-cloudflare). The Certificate Authority reported these problems:
  Domain: xd003.site
  Type: unauthorized
  Detail: Incorrect TXT record "3yQTcOuFTEMVBnH2nXu_DQp10M_merMuiAxd-3_5oYQ" found at _acme-challenge.xd003.site

Hint: The Certificate Authority failed to verify the DNS TXT records created by --dns-cloudflare. Ensure the above domains are hosted by this DNS provider, or try increasing --dns-cloudflare-propagation-seconds (currently 10 seconds).
Some challenges have failed.

```

I have also confirmed that there's not really any issue on my host machine. Port 80 and 443 both are accessible from it and no other process is utilising it. The telnet command proves that both ports are accessible while empty response from ss tupln shows its not being utilised by other process

```plaintext
ubuntu@xd003:~$ telnet google.com 80
Trying 142.250.192.110...
Connected to google.com.
Escape character is '^]'.
^C
Connection closed by foreign host.
ubuntu@xd003:~$ telnet google.com 443
Trying 142.250.199.174...
Connected to google.com.
Escape character is '^]'.
^C
Connection closed by foreign host.
ubuntu@xd003:~$ sudo ss -tulpn | grep LISTEN | grep :80
ubuntu@xd003:~$ sudo ss -tulpn | grep LISTEN | grep :443

```

domain - xd003.site  
root shell access available  
Hosting Provider - Hostinger  
certbot v2.6.0  
Ubuntu 22.04.3  
Logs - [https://pastebin.com/raw/8WxBgFQq](https://pastebin.com/raw/8WxBgFQq)

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 18, 2023, 5:14pm UTC](https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336/2 "2023-09-18T17:14:52Z")

</div>

Have you tried "increasing --dns-cloudflare-propagation-seconds" as mentioned in the error message?

---

<div class="post-metadata">

**Author:** ![xd003](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/xd003/32/72821_2.png) [@xd003](https://community.letsencrypt.org/u/xd003)\
**Post date:** [September 18, 2023, 5:39pm UTC](https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336/3 "2023-09-18T17:39:17Z")

</div>

I didn't really thought that could have been the issue as i have been always hearing that its instant in cloudflare. Using `--dns-cloudflare-propagation-seconds 60` has generated the certificates successfully. Maybe there was some temporary issue at that time who knows but 60 seconds sounds like a safe value to me

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [September 18, 2023, 5:42pm UTC](https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336/4 "2023-09-18T17:42:23Z")

</div>

My experience with Cloudflare is, is that while they're _fast_, they're sometimes not _THAT_ fast. Especially when adding/removing a bunch of records after each other, it seems the first goes fine, but the others require some more time. Usually 30 seconds works fine for me, but for automatic runs 60 is fine too of course, no harm in that, unless you're perhaps renewing thousands of certs. 😛

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 18, 2023, 5:42pm UTC](https://community.letsencrypt.org/t/unable-to-generate-a-wildcard-certificate-using-cloudflare-dns-challenge/205336/5 "2023-10-18T17:42:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
