Urgent certbot does not update due DNS issue

These have no A records:

acme-v1.api.letsencrypt.org
acme-v2.api.letsencrypt.org
acme-v01.api.letsencrypt.org

This does:

acme-v02.api.letsencrypt.org

2 Likes

I think the same with DST Root CA X3 expiration.
How can I resolve this?

1 Like

That's where @rg305 is headed. He has been the master of solving such here. :grin:

3 Likes
2 Likes

acme-v02.api.letsencrypt.org is reachable and seem to work.
Anyway I have updated to certbot 1.21. and it just worked well, too

So it seems that certbot 1.21 does not use the cli.ini located in /etc/letsencrypt/ anymore?
UPDATE: certbot 1.21 uses the cli.ini. And during the installation it has corrected the line

2 Likes

https://certbot.eff.org/docs/using.html#configuration-file

2 Likes

Anywho... this might also be useful:

But in this case, the acme api doesn't use the expired cert.
[fixing tomorrows problems today - LOL]

3 Likes

Be very careful if you keep using cli.ini. I've only ever really found it useful for coordinating docker containers.

2 Likes

Please show the output of:
echo | openssl s_client -connect letsencrypt.org:443 | head

2 Likes

Thank you.
Very quick response from all of you and this saved my day!
THank you very much

2 Likes

You're quite welcome. I'm just glad you were able to make such a bound so quickly. Most aren't so fortunate.

2 Likes

Just one (more) look before you go.

2 Likes
depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1
verify return:1
depth=1 C = US, O = Let's Encrypt, CN = R3
verify return:1
depth=0 CN = lencr.org
verify return:1
DONE
CONNECTED(00000003)
---
Certificate chain
 0 s:CN = lencr.org
   i:C = US, O = Let's Encrypt, CN = R3
 1 s:C = US, O = Let's Encrypt, CN = R3
   i:C = US, O = Internet Security Research Group, CN = ISRG Root X1
 2 s:C = US, O = Internet Security Research Group, CN = ISRG Root X1
   i:O = Digital Signature Trust Co., CN = DST Root CA X3
---
2 Likes

Super all "1"s!
You should be good to go!

3 Likes

Long chain verified.

:partying_face:

2 Likes

Cheers from Miami :beers:
Now back to trading crypto for :beer: ...

#FreeCUBA :cuba:

2 Likes

Cheers from Denver as well :beers:

2 Likes

:beer: :beers:

2 Likes

More :beers: (I hope micro brews, but any :beer: is better than none).

2 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.