What ip address do i need to put in geoblock

Let's Encrypt does not publish the IP addresses of its auth servers. The IP addresses often change from one challenge to the next.

I don't see any problems connecting to your domain. I can even connect using HTTPS and see your (expired) Sectigo cert.

Sorry, I now see you allow only US sources to connect to you. Bruce already described the countries that Let's Encrypt currently uses. These may change anytime.

Also, other Certificate Authorities will need to be doing similar things as standards are changing. But maybe one of them will work now. You could also just renew your paid Sectigo cert. The validation process may be different.

Another option is to use a DNS Challenge. These are often harder to setup and require your DNS Server to accept queries from non-USA origins too. But, this is often the case.

Below is a very good post describing the validation and choices

4 Likes