惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Palo Alto Networks Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
C
CERT Recently Published Vulnerability Notes
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
S
Securelist
酷 壳 – CoolShell
酷 壳 – CoolShell
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
GbyAI
GbyAI
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
Webroot Blog
Webroot Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
TaoSecurity Blog
TaoSecurity Blog
C
Cisco Blogs
博客园 - 【当耐特】
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
B
Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Attack and Defense Labs
Attack and Defense Labs
The Last Watchdog
The Last Watchdog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
Project Zero
Project Zero
WordPress大学
WordPress大学
L
LINUX DO - 最新话题
F
Fortinet All Blogs
L
LINUX DO - 热门话题
PCI Perspectives
PCI Perspectives
Simon Willison's Weblog
Simon Willison's Weblog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
MongoDB | Blog
MongoDB | Blog
Latest news
Latest news
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
The Hacker News
The Hacker News
爱范儿
爱范儿
O
OpenAI News
J
Java Code Geeks
T
The Exploit Database - CXSecurity.com
H
Hackread – Cybersecurity News, Data Breaches, AI and More

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13 Lets encrypt certificate issued website scam Issues getting certificates for .de zone Certbot-dns-multi for dns-lego fails with request for two domains Will tlssever profile switch to 45 days next week? Certbot script searching Expired certs shut done websites Automatic renewal across multiple systems serving the same domain Account paused – Request to unpause domain exodus.digitalmansa.com Certificate for web theft phucnha.com DNS-PERSIST without spending an Order Certificate Expired, now I can't create a new one Account paused Invalid unpause URL I need to revoke a cert, how do i do this Recommended Certbot Config for 2 certs with same FQDN with different acme servers The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot Cannot load certificate "/etc/letsencrypt/live/laurexplore.fr/fullchain.pem" A small static ACME server to distribute certs Certferry - easy distribution of wildcard LE certificates Permission errors on Let's ENcrypt certificate requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot LetsEncrypt Consultation SSL/TLS certificate Issue ISRG may have received a National Security Letter or FISA Court Order? Deactivating pending authorization Perhaps this domain is at risk group and is blacklisted on the Let's Encrypt side Certificate renewal error Azuracast letsencrypt error Certbot change provider from Sectigo to CertiNext Privacy policy still mentions disabled services Letsencrypt[.]top is squatting on the LE name and acting as a web client Cert renews not working anymore Root Cert Protection and Signing Process for e.g. Intermediates or Cross-Signs of new Roots DNS Challenge failed incorrect TXT value FreeCert: a lightweight ACME management module for shared hosting and cPanel Certbot is rejecting its own specified _acme-challenge value Not able to renew certificates Issue of SSL Certificate fails Today instantly SSL certificate problems CNAME and CAA clarification Issue an SSL certificate Wacs Domain cert generation - test successful but real fails 400 Posh-acme db_error submitting renewal Safari won't trust Let's Encrypt certs Does Certbot support CNAME challenge? How does CNAME validation work vs DNS-01? Win-Acme Renewal Failing Suddenly with DNS-01 (Dreamhost) My certicate is obsokete Possible deliberate publicly admitted violation of subscriber policy by Tom Murphy VII in the form of HTTPV ARI renewal-info Rate Limit Changes? Missing accounturi field in LE dns-persist-01 challenges Problem obtaining a certificate One cert failing to renew - don't know why Dns-persist-01 deployment status and timeline Issue (apparently) after upgrading certbot/ubuntu [nginx] IPv4 OK, IPv6 NOK Expressway ACME Certificate Renewal failing Certbot nginx challenge times out Certbot 5.5.0 Release Error unmarshaling request Try t Self-Host BitWarden - Having Issues Getting a Cert Various problems with three domains cme_registration.reg: Creating... ╷ │ Error: acme: error: 403 :: POST :: https://acme-v02.api.letsencrypt.org/acme/new-acct :: urn:ietf:params:acme:error:unauthorized :: An account with the provided public key exists but is deactivated Iran's internet outage and challenges for renewing letsencrypt certs Running multiple Certbot renewals in parallel — how to bypass the global lock file? Nginx ipv64.net Fritzbox Dietpi DNS-PERSIST-01 and _validation-persist CNAME Just a small certbot script check An easy way to publish dns-persist-01 records Problem finding dns-persist-01 in staging GoDaddy API access policy update
Certbot failed to authenticate some domains
riskcognizan · 2026-04-15 · via Let's Encrypt Community Support - Latest topics

April 14, 2026, 10:34pm 1

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is:cypherintel.com

I ran this command:: sudo certbot certonly --manual --preferred-challenges dns --email support@riskcognizance.com --agree-tos --no-eff-email -d cypherintel.com -d compliance.cypherintel.com

It produced this output:sudo certbot certonly --manual --preferred-challenges dns --email support@riskcognizance.com --agree-tos --no-eff-email -d cypherintel.com -d compliance.cypherintel.com

My web server is (include version): LiteSpeed/1.8.4 Open (BUILD built: Tue Nov 4 13:44:54 UTC 2025)
module versions:
lsquic 4.3.1
modgzip 1.1
cache 1.66
mod_security 1.4 (with libmodsecurity v3.0.14)

The operating system my web server runs on is (include version): Ubuntu

My hosting provider, if applicable, is: N/A

I can login to a root shell on my machine (yes or no, or I don't know): Yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): Cyberpanel version": "2.4", "build": "4"

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):certbot 1.21.0

rg305 April 14, 2026, 11:03pm 2

You seem to have pasted the same thing for both.
Please provide the output that command produced.

3 Likes

root@ip-172-31-91-223:~# sudo certbot certonly --manual --preferred-challenges dns --email support@riskcognizance.com --agree-tos --no-eff-email -d cypherintel.com -d compliance.cypherintel.com
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for cypherintel.com and compliance.cypherintel.com

Please deploy a DNS TXT record under the name:

_acme-challenge.compliance.cypherintel.com.

with the following value:

e-WJUNcgFIMHpEjTdg-EaTS5Egdwtc5ESp1sDS7Z8W8

Press Enter to Continue

Please deploy a DNS TXT record under the name:

_acme-challenge.cypherintel.com.

with the following value:

IhJonoT88CHvozkTt7QFs42Z-MFQh0CeYV7NbDZV_ME

(This must be set up in addition to the previous challenges; do not remove,
replace, or undo the previous challenge tasks yet. Note that you might be
asked to create multiple distinct TXT records with the same name. This is
permitted by DNS standards.)

Before continuing, verify the TXT record has been deployed. Depending on the DNS
provider, this may take some time, from a few seconds to multiple minutes. You can
check if it has finished deploying with aid of online tools, such as the Google
Admin Toolbox: Dig (DNS lookup).
Look for one or more bolded line(s) below the line ';ANSWER'. It should show the
value(s) you've just added.

Press Enter to Continue

Certbot failed to authenticate some domains (authenticator: manual). The Certificate Authority reported these problems:
Domain: compliance.cypherintel.com
Type: unauthorized
Detail: Incorrect TXT record "AQhtN7ylqlNfd0JJ6QrAtlsJVAzkmpw717_ELFajNGA" found at _acme-challenge.compliance.cypherintel.com

Domain: cypherintel.com
Type: unauthorized
Detail: Incorrect TXT record "OHOVZaBc9E0PSV0Jrw7i1F9FwWHVf2OazBj0fwnqlzM" found at _acme-challenge.cypherintel.com

Hint: The Certificate Authority failed to verify the manually created DNS TXT records. Ensure that you created these in the correct location, or try waiting longer for DNS propagation on the next attempt.

Some challenges have failed.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

propably DNS propagation delays. It should "tolerate" incorrect records as long as it founds one correct.

Do you have a DNS provider, or do you host DNS yourself? If you host DNS yourself you should be able to force a transfer from your slaves, or even better, point the master and slave IP to the same machine, thus bypassing registrar limitations like "at least 2 DNS servers" but still having one DNS server.

DNS Godaddy.: propagation doesn't seems to be the issue

Public Digs

MikeMcQ April 15, 2026, 12:03pm 7

But, that isn't the value that Let's Encrypt saw when it checked that record. In fact, that "wrong" record value shown is still present in your DNS TXT record.

See: https://unboundtest.com/m/TXT/_acme-challenge.compliance.cypherintel.com/3WXSGLVY

3 Likes

I have no response with the above, can you confrim where this came from?

MikeMcQ April 15, 2026, 12:12pm 9

From post #3. It was output from Certbot giving you instructions what to do. It was your post.

2 Likes

It seems like GoDaddy have too many DNS servers and only half of them have updated. Thus, corraboration fails even if a few returns the right record.

Seriously. Godaddy is crap as DNS. Host your own DNS instead.

I don't know if you have full control of the compliance.cypherintel.com since that CNAME's to cypherintel.riskcognizance.com

But if you have, you can easily make so for example 172.67.72.8:53 --DNAT--> 141.193.213.10:53

Then you put your DNS records like this:
cypherintel.com IN NS ns1.cypherintel.com
ns1.cypherintel.com IN A 141.193.213.10
cypherintel.com IN NS ns2.cypherintel.com
ns2.cypherintel.com IN A 172.67.72.8

Then just host ONE single DNS server on 141.193.213.10

Then any updates you do, will go live instantly.

MikeMcQ April 15, 2026, 1:10pm 11

It is worth asking why they are doing a manual DNS challenge at all. Automation should be the goal.

Further, both their domains look to point at different services that both rely on Cloudflare. It would be worth understanding more about what they will use this cert for and perhaps offer a better solution.

It might just be for a custom domain for those services. In which case asking those services what kind of automated method they recommend for getting certs. If they could find a way to set something up to use Cloudflare's Origin CA cert, for example, might be a great fit.

2 Likes