• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Resolved Lets Engrypt - Could not obtain directory: Host must be a string

moswak

Regular Pleskian
CentOS 6.10
Obsidian 18.0.25 Update #2

For a few days now I have received the message, but only from centos 6 servers:

"Could not renew Let`s Encrypt certificates for ...."

Could not obtain directory: Host must be a string

The manual renewal in Plesk works without problems.

What could that be ?
 
That has something to do with the last update of SSLIT. This seems to cause problems with the old Centos 6.

Code:
[2020-04-14 10:26:02.298] ERR [panel] PHP Warning: Use of undefined constant INTL_IDNA_VARIANT_UTS46 - assumed 'INTL_IDNA_VARIANT_UTS46' (this will throw an Error in a future version of PHP); File: /usr/local/psa/admin/plib/modules/sslit/vendor/guzzlehttp/guzzle/src/Client.php, Line: 221
[2020-04-14 10:26:02.498] ERR [panel] PHP Warning: idn_to_ascii() expects parameter 3 to be int, string given; File: /usr/local/psa/admin/plib/modules/sslit/vendor/guzzlehttp/guzzle/src/Client.php, Line: 221
[2020-04-14 10:26:02.714] ERR [extension/sslit] Failed to renew certificate of domain 'xxxxxxxx.TLD': Could not obtain directory: Host must be a string
 
@IgorG

we have to manually renew dozens of certificates every day. only with centos 6 servers.
I have created a report.
 
Thank you for your report!
We've reproduced the issue and create bug with id EXTSSLIT-821 which will be fixed in the nearest release.
 
Changes
1.3.1 (16 April 2020)

  • [-] On CentOS 6 servers, automatic renewal of SSL/TLS certificates issued via the Let's Encrypt extension no longer fails. (EXTSSLIT-821)
 
ok great, then I'll wait and see if such messages still come.

What completely irritates me is that today I get another email notifications regarding the certificates that could not be renewed yesterday "although" the certificates were all manually renewed yesterday.
 
Back
Top