I ran this command: I did not run a command - I received an email message with a problem report after automatic renew attempt of the certificate, I presume (see below for the problem message)
It produced this output:
The complete error message is
“Subject: Error during automated certificate renewal for sexpertise-online.nl
Requesting new certificate order…
Processing https://acme-v02.api.letsencrypt.org/acme/authz-v3/4819831468…
Processing authorization for sexpertise-online.nl…
Waiting for domain verification…
Let’s Encrypt was unable to verify the challenge. Unable to update challenge :: authorization must be pending. Exiting…”
My web server is (include version): I cannot see the system info which should contain info about the web server (this info is hidden for me as reseller)
The operating system my web server runs on is (include version):
I don’t know - this info should be in the system info which I can’t see…
I can login to a root shell on my machine (yes or no, or I don’t know): no
I’m using a control panel to manage my site (no, or provide the name and version of the control panel): DirectAdmin - I can’t see a version number
The version of my client is (e.g. output of certbot --version or certbot-auto --version if you’re using Certbot): I’m not aware of something like a ‘client’
Validation failed, but the ACME client tried to proceed anyway, and failed with the "authorization must be pending" error message instead of showing you why the authorization failed. If you click on the authz link, you can see the original error message:
"detail": "DNS problem: SERVFAIL looking up CAA for sexpertise-online.nl - the domain's nameservers may be malfunctioning",
I'm not sure why, but there seem to be issues with the domain's DNS.
Hi MNordhoff,
Thanks for your quick response!
I’ll take your info and ask the company that hosts my domains and DNS setup what can be wrong here.
Thanks again for your help!
wkr, Otto
I did add the CAA record and don’t get an error message any more referring to CAA, but now I got another error message when Let’s Encrypt tried to update the cert last night:
I asked my hosting provider for the setup of this on their server and they confirmed that the .well-known is available on their server, but added as remart that in the DNS record also an A record for sexpertise-online.nl should be there (so without the www), but this is already the case since the domain was setup years ago…, so it seems that the problem lies somewhere else…
Could you provide me with another hint how to solve the problem of Let’s Encrypt not being able to update the cert for sexpertise-online.nl?
Thanks for your help!
wkr, Otto