TITLE:
Let's Encrypt - bad domain alias prevents main certificate renewal
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE:CloudLinux 7.5, Plesk Onyx 17.8.11 Update #19
PROBLEM DESCRIPTION:If a subscription has a domain alias that's inaccessible due to various reasons - i.e the domain is expired and no longer active, or the DNS incorrectly doesn't point to the current server, then Let's Encrypt will fail to generate or renew an SSL certificate for the subscription's main domain.
STEPS TO REPRODUCE:If the bad alias is removed from the subscription, then the certificate for the main domain will be generated successfully when attempted.
ACTUAL RESULT:An invalid alias shouldn't prevent certificate generation or automatic renewal for the main domain or other valid aliases.
EXPECTED RESULT:This issue can also break the auto-regeneration of the main domain's certificate that happens approximately every 3 months - for example if the alias domain expires before the next automated renewal of the main domain's certificate, the main domain's certificate may fail to renew.
ANY ADDITIONAL INFORMATION:
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM:Confirm bug