[[+content_image]]
D
D
Denis Korsachev2020-12-02 11:14:41
Digital certificates
Denis Korsachev, 2020-12-02 11:14:41

Let's Crypt - certificate renewal, DNS error?

Hello, I can not solve the problem with updating certificates and the list of domains in the certificate. When updating, it swears at incorrect DNS A records.

[[email protected] ~]# certbot certonly --cert-name srv.geolan.pp.ua -d srv.geolan.pp.ua -d srv.zflan.pp.ua
Saving debug log to /var/log/letsencrypt/ letsencrypt.log

How would you like to authenticate with the ACME CA?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: Spin up a temporary webserver (standalone)
2: Place files in webroot directory (webroot)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 1
Plugins selected: Authenticator standalone, Installer None
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for srv.geolan.pp.ua
http-01 challenge for srv.zflan.pp.ua
Waiting for verification...
Challenge failed for domain srv.geolan.pp.ua
Challenge failed for domain srv.zflan.pp.ua
http-01 challenge for srv.geolan.pp.ua
http-01 challenge for srv.zflan.pp.ua
Cleaning up challenges
Some challenges have failed .

IMPORTANT NOTES:
- The following errors were reported by the server:

Domain: srv.geolan.pp.ua
Type: unauthorized
Detail: Invalid response from
srv.geolan.pp.ua/.well-known/acme-challenge/iDBpG_...
[**.10.**.32]: ""-//IETF//DTD HTML
2.0//EN\"> \n\n404 Not
Found\n\nNot Found\n

Domain: srv.zflan.pp.ua
Type: unauthorized
Detail: Invalid response from
srv.zflan.pp.ua/.well-known/acme-challenge/DeSm7Xw.. .
[**.10.**.32]: ""-//IETF//DTD HTML
2.0//EN\">\n\n404 Not
Found\n\nNot Found\n
To fix these errors, please make make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.


The following entries are registered in DNS hosting settings for domains:

For geolan.pp.
For srv.geolan.pp.ua A ip of my personal mail server for which I renew certificates
For www.geolan.pp.ua A ip hosting

the same records for the zflan.pp.ua domain!

Tell me where you need to change another entry so that certbot renews the certificates.

Answer the question

In order to leave comments, you need to log in

[[+comments_count]] answer(s)
K
ky0, 2020-12-02
@ky0

You have a check not by DNS, but by using a file in .well-known, see the error more carefully.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question