In this case is not necessary; because the issue was the external protection firewall that stop some ip’s that have problems with blacklist reputation and malware on it.

When we add this ip’s temporarily in a ACL, the process complete the validation of the acme-challenge, but we are not sure of have confidence of this ip’s from Amazon AWS.

We suppose that this ip’s are part of your content delivery network services.

In our perimeter protection service we had ACL for the next IP’s

With the before ACL, the service always work, but this stop working this week.

The next list of the ip’s; the we enter in the temporal ACL, to validate the renew or the create of the new certificate, but the info of IP’s apparently don’t have any relation with

Of Course after the renew/recreate cert; we disable the ACL because we don’t confidence on it, but when the renew time come, the automatic task will be fail.

Exist some list of the ip services, cname or something that tell us what are trusted and put it on a ACL?

We use letsencrypt-win-simple.V1.9.6.2 and we change to win-acme.v2.1.5.742.x64.pluggable

wacs.exe --target manual --host --validation filesystem --webroot “C:\sites\www\demos\web” --store pemfiles --pemfilespath C:\sites\www\domain\ssl

If you can’t leave port 80 open, then you should probably just switch to DNS authentication.
There are plenty of threads/topics here that cover how LE is now using multiple validation points and those IPs are NOT set in stone - they can, and will, change without notice.


Thank you .

I understand now the change and the reason.

