seit ca. vier Tagen funktioniert das SSL Zertifikat von Lets Encrypt nicht mehr auf meiiner Panel Domain.
Das Protokoll:
Code: Select all
[16-Jan-2021 00:00:13] INFO --> check domain "meine-domain.tld'
[16-Jan-2021 00:00:13] INFO --> certificate is valid until 2021-01-23 23:01:16 (7 days left)
[16-Jan-2021 00:00:13] INFO --> certificate is in renewal period
[16-Jan-2021 00:00:13] INFO --> renew cert
[16-Jan-2021 00:00:13] INFO --> Using certificate authority: "https://acme-v02.api.letsencrypt.org/" ().
[16-Jan-2021 00:00:13] INFO --> Getting endpoint URLs.
[16-Jan-2021 00:00:14] INFO --> Account "keyhelp" already registered. Continue.
[16-Jan-2021 00:00:14] INFO --> Requesting Key ID.
[16-Jan-2021 00:00:14] INFO --> Sending signed request to "https://acme-v02.api.letsencrypt.org/acme/new-acct".
[16-Jan-2021 00:00:16] INFO --> Start certificate generation.
[16-Jan-2021 00:00:17] INFO --> Token stored at: /home/keyhelp/www/.well-known/acme-challenge/local-check-60021e8103d850.48684051
[16-Jan-2021 00:00:17] INFO --> Local resolving checks of domains successfully completed.
[16-Jan-2021 00:00:17] INFO --> Requesting challenges for domain "meine-domain.tld".
[16-Jan-2021 00:00:17] INFO --> Sending signed request to "https://acme-v02.api.letsencrypt.org/acme/new-order".
[16-Jan-2021 00:00:18] INFO --> Start authorization process for "meine-domain.tld".
[16-Jan-2021 00:00:18] INFO --> Deploy challenge.
[16-Jan-2021 00:00:18] INFO --> Token stored at: /home/keyhelp/www/.well-known/acme-challenge/OTCWLzAmGCNVa1yhx0-A28T5LeKOz-88Hw9Un6j-hOY
[16-Jan-2021 00:00:18] INFO --> Notify CA that the challenge is ready.
[16-Jan-2021 00:00:18] INFO --> Sending signed request to "https://acme-v02.api.letsencrypt.org/acme/chall-v3/10106919324/YVX0Iw".
[16-Jan-2021 00:00:20] INFO --> Waiting for verification...
[16-Jan-2021 00:00:23] INFO --> Waiting for verification...
[16-Jan-2021 00:00:25] INFO --> Waiting for verification...
[16-Jan-2021 00:00:28] INFO --> Waiting for verification...
[16-Jan-2021 00:00:31] INFO --> Waiting for verification...
[16-Jan-2021 00:00:33] INFO --> Waiting for verification...
[16-Jan-2021 00:00:36] INFO --> Waiting for verification...
[16-Jan-2021 00:00:38] INFO --> Waiting for verification...
[16-Jan-2021 00:00:41] INFO --> Waiting for verification...
[16-Jan-2021 00:00:44] INFO --> Waiting for verification...
[16-Jan-2021 00:00:46] ERROR --> a Let's Encrypt error occurred: Verification ended with an error. Response: {"type":"http-01","status":"invalid","error":{"type":"urn:ietf:params:acme:error:connection","detail":"Fetching https:\/\/meine-domain.tld\/.well-known\/acme-challenge\/OTCWLzAmGCNVa1yhx0-A28T5LeKOz-88Hw9Un6j-hOY: Timeout during connect (likely firewall problem)","status":400},"url":"https:\/\/acme-v02.api.letsencrypt.org\/acme\/chall-v3\/10106919324\/YVX0Iw","token":"OTCWLzAmGCNVa1yhx0-A28T5LeKOz-88Hw9Un6j-hOY","validationRecord":[{"url":"http:\/\/meine-domain.tld\/.well-known\/acme-challenge\/OTCWLzAmGCNVa1yhx0-A28T5LeKOz-88Hw9Un6j-hOY","hostname":"meine-domain.tld","port":"80","addressesResolved":["37.120.184.174","2a03:4000:f:31d::1"],"addressUsed":"2a03:4000:f:31d::1"},{"url":"http:\/\/meine-domain.tld\/.well-known\/acme-challenge\/OTCWLzAmGCNVa1yhx0-A28T5LeKOz-88Hw9Un6j-hOY","hostname":"meine-domain.tld","port":"80","addressesResolved":["37.120.184.174","2a03:4000:f:31d::1"],"addressUsed":"37.120.184.174"},{"url":"https:\/\/meine-domain.tld\/.well-known\/acme-challenge\/OTCWLzAmGCNVa1yhx0-A28T5LeKOz-88Hw9Un6j-hOY","hostname":"meine-domain.tld","port":"443","addressesResolved":["37.120.184.174","2a03:4000:f:31d::1"],"addressUsed":"2a03:4000:f:31d::1"}]}
[16-Jan-2021 00:00:47] INFO --> send notification to admin "adminuser" (@)
[16-Jan-2021 00:00:47] INFO --> finished
Nun ist es so, dass ich die .well-known URL im Browser ohne Probleme aufrufen kann. In der Firewall selber habe ich nicht rumgespielt, das ist alles auf Keyhelp Standard.
---
Habt ihr eine Idee? Den Panel Hostname zu wechseln bringt nichts. Das gleiche Problem verhindert die Neuaustellung.
Viele Grüße