Ich habe einen IPv6 only dev host, den hatte ich erst mit einem anderem Namen aufgesetzt, aber da ich jetzt ganz auf Arm64 wechseln will, habe ich ihn noch mal geändert.
Wenn ich versuche, das panel auf LE umzustellen, bekomme ich diesen Fehler:
Code: Select all
[16-Jun-2024 20:07:14] INFO | Waiting for verification...
[16-Jun-2024 20:07:16] INFO | Sending signed request to "https://acme-v02.api.letsencrypt.org/acme/chall-v3/364792025797/Otry6w".
[16-Jun-2024 20:07:17] ERROR | error while acquiring lets encrypt certificate for server services: Verification ended with an error.
Details: 2a03:7847:2252:180:5054:ff:fe6c:13d1: Fetching http://keyhelp.lab.24unix.net/.well-known/acme-challenge/_TLYPs0-S69ZWyy-O3ayN_SCnW8w3dJ9ZODtX0IAV88: Timeout during connect (likely firewall problem)
Type: urn:ietf:params:acme:error:connection
Full response: {"type":"http-01","url":"https:\/\/acme-v02.api.letsencrypt.org\/acme\/chall-v3\/364792025797\/Otry6w","status":"invalid","validated":"2024-06-16T18:07:04Z","error":{"type":"urn:ietf:params:acme:error:connection","detail":"2a03:7847:2252:180:5054:ff:fe6c:13d1: Fetching http:\/\/keyhelp.lab.24unix.net\/.well-known\/acme-challenge\/_TLYPs0-S69ZWyy-O3ayN_SCnW8w3dJ9ZODtX0IAV88: Timeout during connect (likely firewall problem)","status":400},"token":"_TLYPs0-S69ZWyy-O3ayN_SCnW8w3dJ9ZODtX0IAV88","validationRecord":[{"url":"http:\/\/keyhelp.lab.24unix.net\/.well-known\/acme-challenge\/_TLYPs0-S69ZWyy-O3ayN_SCnW8w3dJ9ZODtX0IAV88","hostname":"keyhelp.lab.24unix.net","port":"80","addressesResolved":["2a03:7847:2252:180:5054:ff:fe6c:13d1"],"addressUsed":"2a03:7847:2252:180:5054:ff:fe6c:13d1"}]}
[1
Code: Select all
[16-Jun-2024 20:14:21] INFO | Waiting for verification...
[16-Jun-2024 20:14:23] INFO | Sending signed request to "https://acme-v02.api.letsencrypt.org/acme/chall-v3/364794017927/zPE_5A".
[16-Jun-2024 20:14:23] ERROR | Apache: a Let's Encrypt error occurred: Verification ended with an error.
Details: 2a03:7847:2252:180:5c65:88ff:fef2:b9a1: Fetching http://dev.tierschnack.de/.well-known/acme-challenge/r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0: Timeout during connect (likely firewall problem)
Type: urn:ietf:params:acme:error:connection
Full response: {"type":"http-01","url":"https:\/\/acme-v02.api.letsencrypt.org\/acme\/chall-v3\/364794017927\/zPE_5A","status":"invalid","validated":"2024-06-16T18:14:10Z","error":{"type":"urn:ietf:params:acme:error:connection","detail":"2a03:7847:2252:180:5c65:88ff:fef2:b9a1: Fetching http:\/\/dev.tierschnack.de\/.well-known\/acme-challenge\/r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0: Timeout during connect (likely firewall problem)","status":400},"token":"r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0","validationRecord":[{"url":"http:\/\/dev.tierschnack.de\/.well-known\/acme-challenge\/r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0","hostname":"dev.tierschnack.de","port":"80","addressesResolved":["2a03:7847:2252:180:5c65:88ff:fef2:b9a1"],"addressUsed":"2a03:7847:2252:180:5c65:88ff:fef2:b9a1"}]}
[16-Jun-2024 20:14:25] INFO | SNI configuration updated
Code: Select all
==> access.log <==
2a03:7847:2252:180:5c65:88ff:fef2:b9a1 - - [16/Jun/2024:20:14:07 +0200] "GET /.well-known/acme-challenge/local-check-666f2b6d0b3fc9.38248884 HTTP/1.1" 200 35 "-" "KeyHelp/24.1 (https://www.keyhelp.de) PHP/8.2.18 curl/7.88.1" 193 255
2a03:7847:2252:180:5c65:88ff:fef2:b9a1 - - [16/Jun/2024:20:14:10 +0200] "GET /.well-known/acme-challenge/r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0 HTTP/1.1" 200 87 "-" "KeyHelp/24.1 (https://www.keyhelp.de) PHP/8.2.18 curl/7.88.1" 201 307
(Alle vm die LE nutzen sind in einem Alias in OPNsense, fur den Regeln Zugriff auf Port 80 und 443 zulassen).
Und Zugriff von extern ist möglich:
Code: Select all
❯ wget http:\/\/dev.tierschnack.de\/.well-known\/acme-challenge\/r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0
--2024-06-16 20:17:46-- http://dev.tierschnack.de/.well-known/acme-challenge/r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0
Resolving dev.tierschnack.de (dev.tierschnack.de)... 2a03:7847:2252:180:5c65:88ff:fef2:b9a1
Connecting to dev.tierschnack.de (dev.tierschnack.de)|2a03:7847:2252:180:5c65:88ff:fef2:b9a1|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 87
Saving to: ‘r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0’
r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0 100%[=============================================================================================================>] 87 --.-KB/s in 0s
2024-06-16 20:17:46 (10.7 MB/s) - ‘r55MCKTRbZ3N_tSgH895Ax6df2AyB9ZuUYeOcr8BvZ0’ saved [87/87]
Einzige Besonderheit:
Code: Select all
root@keyhelp:/etc/systemd/network# cat enp0s1.network
[Match]
Name=enp0s1
[Network]
DHCP=yes
Address=2a03:7847:2252:180:5054:ff:fe6c:13d1/64
Gateway=fe80::20d:b9ff:fe4c:5324
Aber genau das Setup habe ich mit einem anderem Rechner ohne KH, mittels certbot klappt da alles.
Ich erreiche die Kiste auch per ping, also am Gateway liegt es wohl auch nicht.
Code: Select all
❯ ping 2a03:7847:2252:180:5c65:88ff:fef2:b9a1
PING 2a03:7847:2252:180:5c65:88ff:fef2:b9a1(2a03:7847:2252:180:5c65:88ff:fef2:b9a1) 56 data bytes
64 bytes from 2a03:7847:2252:180:5c65:88ff:fef2:b9a1: icmp_seq=1 ttl=56 time=36.3 ms
64 bytes from 2a03:7847:2252:180:5c65:88ff:fef2:b9a1: icmp_seq=2 ttl=56 time=35.5 ms
64 bytes from 2a03:7847:2252:180:5c65:88ff:fef2:b9a1: icmp_seq=3 ttl=56 time=35.0 ms
^C
--- 2a03:7847:2252:180:5c65:88ff:fef2:b9a1 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
rtt min/avg/max/mdev = 35.007/35.582/36.258/0.515 ms