Discussion:
[webmin-l] Let's Encrypt Acme Challenge
Kimberly
2017-05-26 20:12:19 UTC
Permalink
This is what I have figured out when trying to added the www.domain.tld
to the Let's Encrypt certificate; it is not adding the
_acme.challenge.www.domain.tld to the DNS records. I am running DNS
Bind server on Virtualmin. It adds the _acme.challenge.domain.tld to
the record. The DNS does have an A record for www.domain.tld and it is
pointing to the server's IP address. What should I inspect here?
Kimberly
2017-05-27 17:46:36 UTC
Permalink
I have spent a lot of time searching the net on this issue without any
success. It does seem strange to me that it can do the first, but not
the second with www. So tell me this, is the Let's Encrypt script for
Virtualmin an in-house Virtualmin script or is it a script from Let's
Encrypt?
Post by Kimberly
This is what I have figured out when trying to added the
www.domain.tld to the Let's Encrypt certificate; it is not adding the
_acme.challenge.www.domain.tld to the DNS records. I am running DNS
Bind server on Virtualmin. It adds the _acme.challenge.domain.tld to
the record. The DNS does have an A record for www.domain.tld and it
is pointing to the server's IP address. What should I inspect here?
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
-
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
Jamie Cameron
2017-05-28 04:26:03 UTC
Permalink
Does the error message ask for a domain called _acme.challenge or _acme-challenge?

On 26/May/2017 13:12 Kimberly <***@gmx.com> wrote ..

This is what I have figured out when trying to added the www.domain.tld to the Let's Encrypt certificate; it is not adding the _acme.challenge.www.domain.tld to the DNS records. I am running DNS Bind server on Virtualmin. It adds the _acme.challenge.domain.tld to the record. The DNS does have an A record for www.domain.tld and it is pointing to the server's IP address. What should I inspect here?
Pablo Manuel Rizzo
2017-05-30 00:19:35 UTC
Permalink
This is what I get:


An error occurred requesting a new certificate for pablorizzo.com,www.pablorizzo.com from Let's Encrypt : <pre>Saving debug log to /var/log/letsencrypt/letsencrypt.log
Obtaining a new certificate
Performing the following challenges:
dns-01 challenge for pablorizzo.com
dns-01 challenge forwww.pablorizzo.com
Waiting for verification...
Cleaning up challenges
Failed authorization procedure.www.pablorizzo.com (dns-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Correct value not found for DNS challenge, pablorizzo.com (dns-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Correct value not found for DNS challenge
IMPORTANT NOTES:
- The following errors were reported by the server:

Domain:www.pablorizzo.com
Type: unauthorized
Detail: Correct value not found for DNS challenge

Domain: pablorizzo.com
Type: unauthorized
Detail: Correct value not found for DNS challenge

To fix these errors, please make sure that your domain name was
entered correctly and the DNS A record(s) for that domain
contain(s) the right IP address.
</pre>
Post by Jamie Cameron
Does the error message ask for a domain called _acme.challenge or _acme-challenge?
Post by Kimberly
This is what I have figured out when trying to added the
www.domain.tld to the Let's Encrypt certificate; it is not adding the
_acme.challenge.www.domain.tld to the DNS records. I am running DNS
Bind server on Virtualmin. It adds the _acme.challenge.domain.tld to
the record. The DNS does have an A record for www.domain.tld and it
is pointing to the server's IP address. What should I inspect here?
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
-
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
Loading...