I ran this command:
MDaemon Internal Letsencypt Sktript
It produced this output:
Selecting the http-01 challenge and getting challenge data for dns:gamma1.b-s-technic.de.
The challenge status URL is https://acme-v02.api.letsencrypt.org/acme/chall-v3/307619609916/PW_Akw.
The challenge identifier is dns:gamma1.b-s-technic.de.
The URL to verify the challenge is gamma1.b-s-technic.de/.well-known/acme-challenge/l1TdoTcnmNjvzOK0mVjuocHrVa0qiB-QypB4sc8Tpao.
The Challenge file name for dns:gamma1.b-s-technic.de is l1TdoTcnmNjvzOK0mVjuocHrVa0qiB-QypB4sc8Tpao
The Challenge Content for dns:gamma1.b-s-technic.de is l1TdoTcnmNjvzOK0mVjuocHrVa0qiB-QypB4sc8Tpao.wpLIexSUADQZK-yKEsvDmhdUCuqNjOVl-bnuGw-m17Y
Creating D:\MDaemon\WorldClient\HTML.well-known\Acme-challenge\l1TdoTcnmNjvzOK0mVjuocHrVa0qiB-QypB4sc8Tpao for dns:gamma1.b-s-technic.de.
Submitting the ACME challenge for dns:gamma1.b-s-technic.de for verification.
Selecting the http-01 challenge and getting challenge data for dns:mst.b-s-technic.de.
The challenge status URL is https://acme-v02.api.letsencrypt.org/acme/chall-v3/307619609926/Qt0U0g.
The challenge identifier is dns:mst.b-s-technic.de.
The URL to verify the challenge is mst.b-s-technic.de/.well-known/acme-challenge/Iz8xp8HNwMkT0RNup1s6IVzKj65zm_4yLBDSt5NNo2E.
The Challenge file name for dns:mst.b-s-technic.de is Iz8xp8HNwMkT0RNup1s6IVzKj65zm_4yLBDSt5NNo2E
The Challenge Content for dns:mst.b-s-technic.de is Iz8xp8HNwMkT0RNup1s6IVzKj65zm_4yLBDSt5NNo2E.wpLIexSUADQZK-yKEsvDmhdUCuqNjOVl-bnuGw-m17Y
Creating D:\MDaemon\WorldClient\HTML.well-known\Acme-challenge\Iz8xp8HNwMkT0RNup1s6IVzKj65zm_4yLBDSt5NNo2E for dns:mst.b-s-technic.de.
Submitting the ACME challenge for dns:mst.b-s-technic.de for verification.
Selecting the http-01 challenge and getting challenge data for dns:omega1.b-s-technic.de.
The challenge status URL is https://acme-v02.api.letsencrypt.org/acme/chall-v3/307619609936/kf9WvQ.
The challenge identifier is dns:omega1.b-s-technic.de.
The URL to verify the challenge is omega1.b-s-technic.de/.well-known/acme-challenge/4uS-VyYr2bQ5Ftrv5qKGJUs3UzMCtrXAOiRUyGoL8H0.
The Challenge file name for dns:omega1.b-s-technic.de is 4uS-VyYr2bQ5Ftrv5qKGJUs3UzMCtrXAOiRUyGoL8H0
The Challenge Content for dns:omega1.b-s-technic.de is 4uS-VyYr2bQ5Ftrv5qKGJUs3UzMCtrXAOiRUyGoL8H0.wpLIexSUADQZK-yKEsvDmhdUCuqNjOVl-bnuGw-m17Y
Creating D:\MDaemon\WorldClient\HTML.well-known\Acme-challenge\4uS-VyYr2bQ5Ftrv5qKGJUs3UzMCtrXAOiRUyGoL8H0 for dns:omega1.b-s-technic.de.
Submitting the ACME challenge for dns:omega1.b-s-technic.de for verification.
Waiting for the order status to update... 0
Error: The challenge did not complete.
Welcome to the community @fagopon
And thank you for the detailed results
These are slightly different but both are most often caused by a firewall at your facility.
Do you have any firewalls in Windows? Or in your comms gear like routers and similar that might block the IP addresses used by Let's Encrypt?
Have you contacted the MDaemon support to see if something in their software could cause this? Maybe their software is conflicting with other things running on your system so the HTTP request is not getting to it.
The HTTP request works fine. I checked it from another location. Ports are opened. It worked fine for the last months. Now i tried to renewed the certificate. And this happened. Checked the IP is reachable from USA. This was fine too. I contacted the MDaemon reseller also. But actually they have no idea whats wrong.
I see your past successful cert history. Something has changed since your last cert issued Oct27
Have you tried rebooting your server? I rarely suggest it but sometimes it helps
I tested access from US and Germany. One of the Let's Encrypt server farms is there. But, all of that worked fine. I also used Let's Debug test site which uses the Let's Encrypt Staging system as one of its tests and that worked too (link here).
Is there any kind of firewall?. Maybe blocking just some inbound IP addresses? Or, some sort of DDoS firewall that is blocking repeated requests (like from Let's Encrypt servers?).
Do you have ability to see logs of internet traffic into your system? Like at the router if a residential system?
Maybe. I would expect to see three sets of challenges for each domain name and those are only two. More importantly, those IP addresses belong to Apple and are not from let's encrypt. Do you have any communications gear from Apple that might be handling requests at your site?
No there is no communication gear from Apple. There is a cisco router RV042 behind a AVM Fritzbox. The Cisco is setup as a exposed host behind the Fritzbox. I will try to check logs in the past how it looked.
A routing problem somewhere, yes. The IP addresses in the Oct27 log are normal Let's Encrypt IP. They may change each time but those are LE IP. There are 2 US locations and one Cloudflare magic transit IP.
Your latest log IP look very different. Because of that any routing problem is likely closer to you than nearer each different LE location.
Did you just reset something. Because I got several HTTP connect failures just now but after that can connect again.
That is the IP I used for that test. It was from an AWS EC2 server on the US East Coast (I am no longer using that IP). So, at least whatever this Apple thing is wasn't involved with that.
Yeah, those latest IP from Apple are very similar to the IP you showed in your 16:12 log
Agree with @rg305 would be interested to see the user-agent in the log record too.