~~~ Please read before posting. ~~~

Important: We need your Club Number at a minimum, and as many details as possible.
For further info please read This page before posting.

"unable to create/renew a HTTPS certificate..." message

  • JTyson
  • JTyson's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 2
  • Thanks: 0

"unable to create/renew a HTTPS certificate..." message

3 years 11 months ago
#85167
Club 907529. Custom domain SkwimTM.org. The certificate expired, and is not renewing. I've reviewed the custom domain documentation and see nothing wrong. HELP!

Jon Tyson
The topic has been locked.
  • Brian
  • Brian's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 10619
  • Thanks: 3569

Re: "unable to create/renew a HTTPS certificate..." message

3 years 11 months ago
#85168
Your domain is not setup correct you are missing several DNS records

www record missing
mail record missing
Mail MX record missing

Please read the documentation and correct the issues.
support.toastmastersclubs.org/doc/item/dns-settings-overview
The topic has been locked.
  • SteveTheTechie
  • SteveTheTechie's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 11526
  • Thanks: 3050

Re: "unable to create/renew a HTTPS certificate..." message

3 years 11 months ago - 3 years 11 months ago
#85169
In addition, here are some log entries from our cert renewal loop--the renewal loop has tried three times already to renew this cert:

(Notice the part below that says "DNS problem: NXDOMAIN looking up A for www.skwimtm.org - check that a DNS record exists for this domain")
Code:
[Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Domain List (1 domains) = skwimtm.org [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Crypt::LE Module Version = 0.36 [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Let's Encrypt API version = 2 [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Loaded/generated Let's Encrypt account key. [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Loaded/generated private key for Certificate Signing Request (CSR) and loaded/generated encrypted CSR for these domains [skwimtm.org]. [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Registered/re-registered with ACME server and accepted Terms of Service. Account ID = 14899026 [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Created token file [/tmp/certvalidation/acme-challenge/_l79yIbGGKJ9b0enmNHyK3_k0v00r7RTOB8TxEQZa_o] for domain verification. [Sat Sep 18 08:27:59 2021 GMT - Renewal Loop] Created token file [/tmp/certvalidation/acme-challenge/DMGLTleGBiyv6eSC_GKhpV5XqaJXcZ9IuE_pIBtQNoI] for domain verification. [Sat Sep 18 08:28:01 2021 GMT - Renewal Loop] Domain verification results for 'skwimtm.org': success. [Sat Sep 18 08:28:01 2021 GMT - Renewal Loop] Deleted token file [/tmp/certvalidation/acme-challenge/_l79yIbGGKJ9b0enmNHyK3_k0v00r7RTOB8TxEQZa_o] used for domain verification. [Sat Sep 18 08:28:04 2021 GMT - Renewal Loop] Domain verification results for 'www.skwimtm.org': error. DNS problem: NXDOMAIN looking up A for www.skwimtm.org - check that a DNS record exists for this domain [Sat Sep 18 08:28:04 2021 GMT - Renewal Loop] Deleted token file [/tmp/certvalidation/acme-challenge/DMGLTleGBiyv6eSC_GKhpV5XqaJXcZ9IuE_pIBtQNoI] used for domain verification. [Sat Sep 18 08:28:04 2021 GMT - Renewal Loop] Could not generate the certificate--request_certificate() failed: Could not finalize an order.
Last edit: 3 years 11 months ago by SteveTheTechie.
The topic has been locked.
  • JTyson
  • JTyson's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 2
  • Thanks: 0

Re: "unable to create/renew a HTTPS certificate..." message

3 years 11 months ago
#85175
Google Domains showed all of those, but I did see they were not showing. I deleted them al and recreated them and they are showing now. Of course the DNS entries have to propogate, and I believe there is a nioghtky cycle to check certificates? Is there any way for you to verify my settings now?

Thanks for all your help!
The topic has been locked.
  • Brian
  • Brian's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 10619
  • Thanks: 3569

Re: "unable to create/renew a HTTPS certificate..." message

3 years 11 months ago
#85187
[Wed Sep 22 15:48:53 2021 GMT] SSL certificate successfully created for the following domains [skwimtm.org www.skwimtm.org ].
[Wed Sep 22 15:48:53 2021 GMT] Cert Expires: Tue Dec 21 14:48:52 2021 UTC [skwimtm.org.crt]
The topic has been locked.
Moderators: BrianJane AtkinsonPamrhtaylor3marc33NotLiablejgavinLcala305peterb323
Time to create page: 0.212 seconds