Error in let's encrypt certificate generation

AmaZili Communication

Basic Pleskian
Username:

TITLE


Error in let's encrypt certificate generation

PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE

Plesk Obsidian 18.0.74 Update #2 Web Host Edition, Almalinux 9.7 directly bought from plesk.com

PROBLEM DESCRIPTION

Using plesk for years now, we had the surpise to dicover that LE certificate génération failed for the last two days especially for certificates for mail (wilcard or not).

Our domain dns records are managed externally.

The certificate generation process is looking for a mail subdomain that does not exists (since it is not used for email declaration with LE).

STEPS TO REPRODUCE

create a domain with external DNS, generate à wildcard certificate

ACTUAL RESULT

plesk obsidian Could not issue an SSL/TLS certificate for whateverdomain.tld Details Could not issue a Let's Encrypt SSL/TLS certificate for xxxxxx.com. Authorization for the domain failed. Details Invalid response from https://acme-v02.api.letsencrypt.org/acme/authz/2167655685/621540772606
Details: Type: urn:ietf:params:acme:error:dns Status: 400 Detail: DNS problem: NXDOMAIN looking up A for mail.whateverdomain.tld - check that a DNS record exists for this domain; DNS problem: NXDOMAIN looking up AAAA for mail.whateverdomain.tld - check that a DNS record exists for this domain

EXPECTED RESULT

certificate generation

ANY ADDITIONAL INFORMATION

(DID NOT ANSWER QUESTION)

YOUR EXPECTATIONS FROM PLESK SERVICE TEAM

Confirm bug
 
Last edited by a moderator:
Thank you for the report, @AmaZili Communication . There are some critical steps and details missed in the report. As in what settings exactly are selected during the Let's Encrypt installation attempt. If you are installing a wildcard SSL have you tried adding the acme_challeange record in the external DNS zone, etc.

Looks like the domain name has been incidentally left in your message (I removed it now) and it appears that the same doesn't have a mail DNS record. Thus, the reported message is somehow expected deepening on your settings.
 
Back
Top