Ik ben gisteren overgestapt op MIJN.HOST aangezien deze support heeft voor LEGO DNS-01.
Ik ben nu een validatie aan het doen op de STAGING omgeving.
We voeren het volgende commando uit:
Dit eindigt in een error
Het gekke is dat ik eigenlijk de challenge lijk te zien. Maar toch faalt het?
Getest met en zonder de "dns.resolvers". Lijken me overbodig toch? Hoewel de output dan wel iets anders is
vs
Ik ben nu een validatie aan het doen op de STAGING omgeving.
We voeren het volgende commando uit:
code:
1
2
3
4
5
6
7
8
9
10
| MIJNHOST_PROPAGATION_TIMEOUT=180 MIJNHOST_API_KEY=DIE_IS_GEHEIM lego \ > --email="ikke@mijndomein.com" \ > --domains="dryrun.mijndomein.com" \ > --domains="*.dryrun.mijndomein.com" \ > --dns="mijnhost" \ > --dns.resolvers="ns1.mijn.host:53,ns2.mijn.host:53,ns3.mijn.host:53" \ > --server="https://acme-staging-v02.api.letsencrypt.org/directory" \ > --path="/tmp/lego" \ > --accept-tos \ > run |
Dit eindigt in een error
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
| 2025/03/23 10:30:21 [INFO] [dryrun.mijndomein.com, *.dryrun.mijndomein.com] acme: Obtaining bundled SAN certificate 2025/03/23 10:30:22 [INFO] [*.dryrun.mijndomein.com] AuthURL: https://acme-staging-v02.api.letsencrypt.org/acme/authz/191041814/16513283914 2025/03/23 10:30:22 [INFO] [dryrun.mijndomein.com] AuthURL: https://acme-staging-v02.api.letsencrypt.org/acme/authz/191041814/16513283924 2025/03/23 10:30:22 [INFO] [*.dryrun.mijndomein.com] acme: use dns-01 solver 2025/03/23 10:30:22 [INFO] [dryrun.mijndomein.com] acme: Could not find solver for: tls-alpn-01 2025/03/23 10:30:22 [INFO] [dryrun.mijndomein.com] acme: Could not find solver for: http-01 2025/03/23 10:30:22 [INFO] [dryrun.mijndomein.com] acme: use dns-01 solver 2025/03/23 10:30:22 [INFO] [*.dryrun.mijndomein.com] acme: Preparing to solve DNS-01 2025/03/23 10:30:23 [INFO] [*.dryrun.mijndomein.com] acme: Trying to solve DNS-01 2025/03/23 10:30:23 [INFO] [*.dryrun.mijndomein.com] acme: Checking DNS record propagation. [nameservers=ns1.mijn.host:53,ns2.mijn.host:53,ns3.mijn.host:53] 2025/03/23 10:30:25 [INFO] Wait for propagation [timeout: 3m0s, interval: 2s] 2025/03/23 10:30:26 [INFO] [*.dryrun.mijndomein.com] acme: Waiting for DNS record propagation. ... ... 2025/03/23 10:33:25 [INFO] [*.dryrun.mijndomein.com] acme: Waiting for DNS record propagation. 2025/03/23 10:33:27 [INFO] [*.dryrun.mijndomein.com] acme: Cleaning DNS-01 challenge 2025/03/23 10:33:29 [INFO] [dryrun.mijndomein.com] acme: Preparing to solve DNS-01 2025/03/23 10:33:29 [INFO] [dryrun.mijndomein.com] acme: Trying to solve DNS-01 2025/03/23 10:33:29 [INFO] [dryrun.mijndomein.com] acme: Checking DNS record propagation. [nameservers=ns1.mijn.host:53,ns2.mijn.host:53,ns3.mijn.host:53] 2025/03/23 10:33:31 [INFO] Wait for propagation [timeout: 3m0s, interval: 2s] 2025/03/23 10:33:31 [INFO] [dryrun.mijndomein.com] acme: Waiting for DNS record propagation. 2025/03/23 10:33:33 [INFO] [dryrun.mijndomein.com] acme: Waiting for DNS record propagation. ... ... 2025/03/23 10:36:31 [INFO] [dryrun.mijndomein.com] acme: Waiting for DNS record propagation. 2025/03/23 10:36:33 [INFO] [dryrun.mijndomein.com] acme: Cleaning DNS-01 challenge 2025/03/23 10:36:35 [INFO] Deactivating auth: https://acme-staging-v02.api.letsencrypt.org/acme/authz/191041814/16513283914 2025/03/23 10:36:35 [INFO] Deactivating auth: https://acme-staging-v02.api.letsencrypt.org/acme/authz/191041814/16513283924 2025/03/23 10:36:35 Could not obtain certificates: error: one or more domains had a problem: [*.dryrun.mijndomein.com] propagation: time limit exceeded: last error: authoritative nameservers: NS ns2.mijn.host.:53 returned REFUSED for _acme-challenge.dryrun.mijndomein.com. [dryrun.mijndomein.com] propagation: time limit exceeded: last error: authoritative nameservers: NS ns3.mijn.host.:53 returned REFUSED for _acme-challenge.dryrun.mijndomein.com. |
Het gekke is dat ik eigenlijk de challenge lijk te zien. Maar toch faalt het?
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
| host -t TXT _acme-challenge.dryrun.mijndomein.com ns1.mijn.host ; host -t TXT _acme-challenge.dryrun.mijndomein.com ns2.mijn.host ; host -t TXT _acme-challenge.dryrun.mijndomein.com ns3.mijn.host Using domain server: Name: ns1.mijn.host Address: 5.254.117.200#53 Aliases: _acme-challenge.dryrun.mijndomein.com descriptive text "0km2QGgsfc0LwyayoWoEKb8v2bRg2waRd_WxYXLcnnI" Using domain server: Name: ns2.mijn.host Address: 45.140.188.195#53 Aliases: _acme-challenge.dryrun.mijndomein.com descriptive text "0km2QGgsfc0LwyayoWoEKb8v2bRg2waRd_WxYXLcnnI" Using domain server: Name: ns3.mijn.host Address: 83.96.241.95#53 Aliases: _acme-challenge.dryrun.mijndomein.com descriptive text "0km2QGgsfc0LwyayoWoEKb8v2bRg2waRd_WxYXLcnnI" |
Getest met en zonder de "dns.resolvers". Lijken me overbodig toch? Hoewel de output dan wel iets anders is
code:
1
| 2025/03/23 09:51:52 [INFO] [*.dryrun.mijndomein.com] acme: Checking DNS record propagation. [nameservers=192.168.1.1:53] |
vs
code:
1
| 2025/03/23 10:30:23 [INFO] [*.dryrun.mijndomein.com] acme: Checking DNS record propagation. [nameservers=ns1.mijn.host:53,ns2.mijn.host:53,ns3.mijn.host:53] |