We have an very strict firewall policy to block all AWS incoming traffic. We block all IP V4 ranges of AWS.
Due new multivalidation process our certificates renew requests fails on Secondary validation.
Lookin for info about it I read that this secondary validation initiates on Amazon. I Turned off our AWS firewall policy and everything works fine! All certificates renew in seconds.
I also read LetsEncrypt will not provide IP address to whitelist it on firewall to keep this new process more secure… so…
you got at least two valid options, and here's a third: use your client's hooks (--pre-hook and --post-hook usually) to only open port 80 worldwide during the validation.
thank you! I cant do that (allow just .well-kwown… path) , because my hardware firewall caped AWS IP addresses before they arrive to the Software (second firewall and webserver)
To whom answered about port 80 and 443, AWS cant see any open any port on our server.
I am using Cert the web client, and for DNS validation ask for a code to add in my dns.
I have full access to our dns, i can create a TXT record for it, BUT I cant find what really put in these record.
I found some entrys talking about it in forums and docs, but none works fine for me. Also some guys recomends dont use this method.
If this is still an issue (not knowing how to do DNS validation with Certify The Web) please drop by https://community.certifytheweb.com/ or email support at certifytheweb.com.
You may also find relevant info about DNS validation at https://docs.certifytheweb.com/docs/dns-validation if you are using a supported DNS provider. We are about to add many more DNS providers in v5.