惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
V
V2EX
T
The Blog of Author Tim Ferriss
腾讯CDC
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
爱范儿
爱范儿
GbyAI
GbyAI
H
Help Net Security
I
InfoQ
罗磊的独立博客
酷 壳 – CoolShell
酷 壳 – CoolShell
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
人人都是产品经理
人人都是产品经理
J
Java Code Geeks
Microsoft Security Blog
Microsoft Security Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
宝玉的分享
宝玉的分享
云风的 BLOG
云风的 BLOG
Project Zero
Project Zero
P
Privacy & Cybersecurity Law Blog
A
Arctic Wolf
Know Your Adversary
Know Your Adversary
G
Google Developers Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tor Project blog
V
Vulnerabilities – Threatpost
Y
Y Combinator Blog
WordPress大学
WordPress大学
V
Visual Studio Blog
博客园_首页
G
GRAHAM CLULEY
K
Kaspersky official blog
T
Tailwind CSS Blog
T
Threat Research - Cisco Blogs
博客园 - Franky
D
Docker
Security Latest
Security Latest
I
Intezer
有赞技术团队
有赞技术团队
Application and Cybersecurity Blog
Application and Cybersecurity Blog
博客园 - 【当耐特】
B
Blog RSS Feed
T
The Exploit Database - CXSecurity.com
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13 Lets encrypt certificate issued website scam Issues getting certificates for .de zone Certbot-dns-multi for dns-lego fails with request for two domains Will tlssever profile switch to 45 days next week? Certbot script searching Expired certs shut done websites Automatic renewal across multiple systems serving the same domain Account paused – Request to unpause domain exodus.digitalmansa.com Certificate for web theft phucnha.com DNS-PERSIST without spending an Order Certificate Expired, now I can't create a new one Account paused Invalid unpause URL I need to revoke a cert, how do i do this Recommended Certbot Config for 2 certs with same FQDN with different acme servers The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot Cannot load certificate "/etc/letsencrypt/live/laurexplore.fr/fullchain.pem" A small static ACME server to distribute certs Certferry - easy distribution of wildcard LE certificates Permission errors on Let's ENcrypt certificate requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot LetsEncrypt Consultation SSL/TLS certificate Issue ISRG may have received a National Security Letter or FISA Court Order? Deactivating pending authorization Perhaps this domain is at risk group and is blacklisted on the Let's Encrypt side Certificate renewal error Azuracast letsencrypt error Certbot change provider from Sectigo to CertiNext Privacy policy still mentions disabled services Letsencrypt[.]top is squatting on the LE name and acting as a web client Cert renews not working anymore Root Cert Protection and Signing Process for e.g. Intermediates or Cross-Signs of new Roots DNS Challenge failed incorrect TXT value FreeCert: a lightweight ACME management module for shared hosting and cPanel Not able to renew certificates Issue of SSL Certificate fails Today instantly SSL certificate problems CNAME and CAA clarification Issue an SSL certificate Wacs Domain cert generation - test successful but real fails 400 Posh-acme db_error submitting renewal Safari won't trust Let's Encrypt certs Does Certbot support CNAME challenge? How does CNAME validation work vs DNS-01? Win-Acme Renewal Failing Suddenly with DNS-01 (Dreamhost) My certicate is obsokete Certbot failed to authenticate some domains Possible deliberate publicly admitted violation of subscriber policy by Tom Murphy VII in the form of HTTPV ARI renewal-info Rate Limit Changes? Missing accounturi field in LE dns-persist-01 challenges Problem obtaining a certificate One cert failing to renew - don't know why Dns-persist-01 deployment status and timeline Issue (apparently) after upgrading certbot/ubuntu [nginx] IPv4 OK, IPv6 NOK Expressway ACME Certificate Renewal failing Certbot nginx challenge times out Certbot 5.5.0 Release Error unmarshaling request Try t Self-Host BitWarden - Having Issues Getting a Cert Various problems with three domains cme_registration.reg: Creating... ╷ │ Error: acme: error: 403 :: POST :: https://acme-v02.api.letsencrypt.org/acme/new-acct :: urn:ietf:params:acme:error:unauthorized :: An account with the provided public key exists but is deactivated Iran's internet outage and challenges for renewing letsencrypt certs Running multiple Certbot renewals in parallel — how to bypass the global lock file? Nginx ipv64.net Fritzbox Dietpi DNS-PERSIST-01 and _validation-persist CNAME Just a small certbot script check An easy way to publish dns-persist-01 records Problem finding dns-persist-01 in staging GoDaddy API access policy update
Certbot is rejecting its own specified _acme-challenge value
@AMnesia A · 2026-04-18 · via Let's Encrypt Community Support - Latest topics

April 18, 2026, 12:04am 1

Please fill out the fields below so we can help you better. Note: you must provide your domain name to get help. Domain names for issued certificates are all made public in Certificate Transparency logs (e.g. https://crt.sh/?q=example.com), so withholding your domain name here does not increase secrecy, but only makes it harder for us to provide help.

My domain is: whizmann.com

I ran this command:

certbot -v certonly --manual --preferred-challenge dns -d 'whizmann.com' -d '*.whizmann.com'

It produced this output:

Please deploy a DNS TXT record under the name:

_acme-challenge.whizmann.com.

with the following value:

x3fg8NY6aDVSBPgbn3ZJeZiZyesKKL6pcmzggPqXQjc

[ ... etc. ... ]

Waiting for verification...
Challenge failed for domain whizmann.com
dns-01 challenge for whizmann.com

Certbot failed to authenticate some domains (authenticator: manual). The Certificate Authority reported these problems:
Domain: whizmann.com
Type: unauthorized
Detail: Incorrect TXT record "x3fg8NY6aDVSBPgbn3ZJeZiZyesKKL6pcmzggPqXQjc" found at _acme-challenge.whizmann.com

Hint: The Certificate Authority failed to verify the manually created DNS TXT records. Ensure that you created these in the correct location, or try waiting longer for DNS propagation on the next attempt.

Note that certbot itself specified the following value:

x3fg8NY6aDVSBPgbn3ZJeZiZyesKKL6pcmzggPqXQjc

... but then certbot itself said that it indeed found this exact _acme-challenge value (see above), but certbot then rejected it.

Why did certbot find and then reject the exact,same _acme-challenge value that it specified?

My web server is (include version):

Lighttpd 1.4.79-2 (but I stopped lighttpd before running certbot and had certbot use its own web server).

The operating system my web server runs on is (include version):

Debian 13

My hosting provider, if applicable, is:

Directnic

I can login to a root shell on my machine (yes or no, or I don't know):

Yes. And I was logged on as root when I ran the above certbot command.

I'm using a control panel to manage my site (no, or provide the name and version of the control panel):

No

The version of my client is (e.g. output of certbot --version or certbot-auto --version if you're using Certbot):

certbot-5.2.2

You're authenticating two very similar domains whizmann.com and *.whizmann.com, there should be another TXT value specified for you to put at the same acme-challenge domain.

1 Like

danb35 April 18, 2026, 12:17am 3

The command you gave didn't do that; it used DNS validation. There was no reason to stop your web server, nor did certbot start its own. Now, why you did that, I have no idea--the --manual flag will make automated renewal impossible. Do you actually need the wildcard cert?

4 Likes

MikeMcQ April 18, 2026, 12:27am 4

I'll pile on a bit ... Certbot is the ACME Client and Let's Encrypt is the ACME Server. Certbot is not saying it saw that record and rejecting it, the LE Server is.

Certbot gives you the instructions to prepare for the Challenge (since you used --manual) and then it requests the cert from Let's Encrypt.

The LE Server is the one rejecting the request because it can't find the expected record. As @MaxHearnden already noted there should have been two values and LE Server is only finding one "wrong" one when it is validating the second domain name.

I mention this only to help you understand how these work together.

As @danb35 noted maybe the DNS Challenge isn't needed. But, if you continue with that you should use this site to verify the proper TXT records are in place before pressing Enter to proceed: https://unboundtest.com/

3 Likes

AMnesia April 18, 2026, 12:59am 5

(1) I stop my web server because it's always a complicated PITA to configure the various web servers that I've used to work properly with certbot. For years I've gotten certs by choosing the certbot-started web server, and I never had headaches nor any web server problems.

(2) Actually, I don't need any subdomain in this case, I just have an unthinking, knee-jerk habit over the years of always running certbot by requesting subdomain certs. I just got rid of that "-d *.whizmann.com" parameter, and now everything works.

This a more than good enough solution for me.

Many thanks to all!

MikeMcQ April 18, 2026, 1:55am 6

That's of course fine.

But, using the DNS Challenge like you are does not require you to stop your Lighttpd server.

Certbot has a --standalone option that starts a local server just for handling an HTTP Challenge. But, it does not start its own server of any kind for any other challenge type.

For the DNS Challenge, Certbot instructs or prepares the DNS records and then requests the cert from the Let's Encrypt Server. The LE Server validates the TXT record(s) and, if successful, issues the cert. Certbot then retrieves it. There are (currently) five LE Server farms across the world that do the validation but I digress.

A new challenge type called dns-persist-01 is planned to be out this quarter by Let's Encrypt. I don't known when the EFF plans to support it in Certbot. But, this would simplify your manual requests considerably. See: DNS-PERSIST-01: A New Model for DNS-based Challenge Validation - Let's Encrypt

1 Like

AMnesia April 18, 2026, 2:58pm 7

Thank you very much for this explanation.

I wrote my script which runs certbot (with whatever arguments I decide to pass to it) to always stop my local web server before the certbot invocation and then re-start it afterwards.

This is simply a convenience for me, because then I don't need to remember for which cases this web server shut-down and re-start are actually necessary.

Stopping my local web server for a couple minutes at most does not interfere with any of the things that I do on my local machine.

2 Likes