惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
About on SuperTechFans
人人都是产品经理
人人都是产品经理
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
月光博客
月光博客
T
Tailwind CSS Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
Visual Studio Blog
博客园 - 叶小钗
博客园 - 司徒正美
美团技术团队
博客园_首页
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
D
DataBreaches.Net
Google DeepMind News
Google DeepMind News

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13
Certbot failed to authenticate some domains
riskcognizan · 2026-04-15 · via Let's Encrypt Community Support - Latest topics

April 14, 2026, 10:34pm 1

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:cypherintel.com

I ran this command:: sudo certbot certonly --manual --preferred-challenges dns --email support@riskcognizance.com --agree-tos --no-eff-email -d cypherintel.com -d compliance.cypherintel.com

It produced this output:sudo certbot certonly --manual --preferred-challenges dns --email support@riskcognizance.com --agree-tos --no-eff-email -d cypherintel.com -d compliance.cypherintel.com

My web server is (include version): LiteSpeed/1.8.4 Open (BUILD built: Tue Nov 4 13:44:54 UTC 2025)
module versions:
lsquic 4.3.1
modgzip 1.1
cache 1.66
mod_security 1.4 (with libmodsecurity v3.0.14)

The operating system my web server runs on is (include version): Ubuntu

My hosting provider, if applicable, is: N/A

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): Cyberpanel version": "2.4", "build": "4"

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):certbot 1.21.0

rg305 April 14, 2026, 11:03pm 2

You seem to have pasted the same thing for both.
Please provide the output that command produced.

3 Likes

root@ip-172-31-91-223:~# sudo certbot certonly --manual --preferred-challenges dns --email support@riskcognizance.com --agree-tos --no-eff-email -d cypherintel.com -d compliance.cypherintel.com
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for cypherintel.com and compliance.cypherintel.com

Please deploy a DNS TXT record under the name:

_acme-challenge.compliance.cypherintel.com.

with the following value:

e-WJUNcgFIMHpEjTdg-EaTS5Egdwtc5ESp1sDS7Z8W8

Press Enter to Continue

Please deploy a DNS TXT record under the name:

_acme-challenge.cypherintel.com.

with the following value:

IhJonoT88CHvozkTt7QFs42Z-MFQh0CeYV7NbDZV_ME

(This must be set up in addition to the previous challenges; do not remove,
replace, or undo the previous challenge tasks yet. Note that you might be
asked to create multiple distinct TXT records with the same name. This is
permitted by DNS standards.)

Before continuing, verify the TXT record has been deployed. Depending on the DNS
provider, this may take some time, from a few seconds to multiple minutes. You can
check if it has finished deploying with aid of online tools, such as the Google
Admin Toolbox: Dig (DNS lookup).
Look for one or more bolded line(s) below the line ';ANSWER'. It should show the
value(s) you've just added.

Press Enter to Continue

Certbot failed to authenticate some domains (authenticator: manual). The Certificate Authority reported these problems:
Domain: compliance.cypherintel.com
Type: unauthorized
Detail: Incorrect TXT record "AQhtN7ylqlNfd0JJ6QrAtlsJVAzkmpw717_ELFajNGA" found at _acme-challenge.compliance.cypherintel.com

Domain: cypherintel.com
Type: unauthorized
Detail: Incorrect TXT record "OHOVZaBc9E0PSV0Jrw7i1F9FwWHVf2OazBj0fwnqlzM" found at _acme-challenge.cypherintel.com

Hint: The Certificate Authority failed to verify the manually created DNS TXT records. Ensure that you created these in the correct location, or try waiting longer for DNS propagation on the next attempt.

Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

propably DNS propagation delays. It should "tolerate" incorrect records as long as it founds one correct.

Do you have a DNS provider, or do you host DNS yourself? If you host DNS yourself you should be able to force a transfer from your slaves, or even better, point the master and slave IP to the same machine, thus bypassing registrar limitations like "at least 2 DNS servers" but still having one DNS server.

DNS Godaddy.: propagation doesn't seems to be the issue

Public Digs

MikeMcQ April 15, 2026, 12:03pm 7

But, that isn't the value that Let's Encrypt saw when it checked that record. In fact, that "wrong" record value shown is still present in your DNS TXT record.

See: https://unboundtest.com/m/TXT/_acme-challenge.compliance.cypherintel.com/3WXSGLVY

3 Likes

I have no response with the above, can you confrim where this came from?

MikeMcQ April 15, 2026, 12:12pm 9

From post #3. It was output from Certbot giving you instructions what to do. It was your post.

2 Likes

It seems like GoDaddy have too many DNS servers and only half of them have updated. Thus, corraboration fails even if a few returns the right record.

Seriously. Godaddy is crap as DNS. Host your own DNS instead.

I don't know if you have full control of the compliance.cypherintel.com since that CNAME's to cypherintel.riskcognizance.com

But if you have, you can easily make so for example 172.67.72.8:53 --DNAT--> 141.193.213.10:53

Then you put your DNS records like this:
cypherintel.com IN NS ns1.cypherintel.com
ns1.cypherintel.com IN A 141.193.213.10
cypherintel.com IN NS ns2.cypherintel.com
ns2.cypherintel.com IN A 172.67.72.8

Then just host ONE single DNS server on 141.193.213.10

Then any updates you do, will go live instantly.

MikeMcQ April 15, 2026, 1:10pm 11

It is worth asking why they are doing a manual DNS challenge at all. Automation should be the goal.

Further, both their domains look to point at different services that both rely on Cloudflare. It would be worth understanding more about what they will use this cert for and perhaps offer a better solution.

It might just be for a custom domain for those services. In which case asking those services what kind of automated method they recommend for getting certs. If they could find a way to set something up to use Cloudflare's Origin CA cert, for example, might be a great fit.

2 Likes