OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • LetsEncrypt troubleshooting advice..
« previous next »
  • Print
Pages: [1]

Author Topic: LetsEncrypt troubleshooting advice..  (Read 5586 times)

erktrek

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
LetsEncrypt troubleshooting advice..
« on: May 20, 2018, 05:09:51 pm »
So am getting into the letsencrypt/acme.sh thing.. My provider is GoDaddy and I am using dns01 - "dns_gd". I am on OpnSense 18.1.8 and acme.sh v2.7.9

Seems straightforward but cannot add any certificates using staging (have not tried production) - from the logs I keep getting txt record errors but the txt records actually appear in GD.. and I can query them. Note there seems to be 2 challenge records - I do not know if this is normal or not.

Not sure how to go about troubleshooting this properly. Any advice would be appreciated.

Thx!

E.

Code: [Select]
...........
...........
[Sun May 20 10:38:45 EDT 2018] _post_url='https://api.godaddy.com/v1/domains/xxxxxxx.com/re
cords/TXT/_acme-challenge'
[Sun May 20 10:38:45 EDT 2018] _CURL='curl -L --silent --dump-header /var/etc/acme-client/h
ome/http.header  -g '
[Sun May 20 10:38:46 EDT 2018] _ret='0'
[Sun May 20 10:38:46 EDT 2018] Add txt record error.
[Sun May 20 10:38:46 EDT 2018]
[Sun May 20 10:38:46 EDT 2018] Error add txt for domain:_acme-challenge.xxxxxxx.com
[Sun May 20 10:38:46 EDT 2018] pid
...........
...........
Logged

erktrek

  • Newbie
  • *
  • Posts: 6
  • Karma: 0
    • View Profile
Re: LetsEncrypt troubleshooting advice..
« Reply #1 on: May 20, 2018, 07:19:02 pm »
Wanted to followup - I ended installing acme.sh on an internal server instead and was able to get everything running as expected. Even used a wildcard!

https://github.com/Neilpang/acme.sh/tree/master/dnsapi


Logged

djones

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: LetsEncrypt troubleshooting advice..
« Reply #2 on: May 28, 2018, 11:11:11 pm »
Same issue:

Code: [Select]
[Mon May 28 14:02:56 PDT 2018] pid
[Mon May 28 14:02:56 PDT 2018] Error add txt for domain:_acme-challenge.xxxxxxxx.com
[Mon May 28 14:02:56 PDT 2018] Add txt record error.
[Mon May 28 14:02:56 PDT 2018] _ret='0'
[Mon May 28 14:02:55 PDT 2018] _CURL='curl -L --silent --dump-header /var/etc/acme-client/home/http.header -g '
[Mon May 28 14:02:55 PDT 2018] _post_url='https://api.godaddy.com/v1/domains/xxxxxxxx.com/records/TXT/_acme-challenge'

Also using GoDaddy DNS.
18.1.8
acme.sh 2.7.8

Would like to get it working in opnsense if possible
Logged

DonSYS

  • Newbie
  • *
  • Posts: 11
  • Karma: 0
    • View Profile
Re: LetsEncrypt troubleshooting advice..
« Reply #3 on: June 23, 2018, 02:06:23 am »
is it possible that you open an issue in OPNsense Plugins repo https://github.com/opnsense/plugins, so we can investigate it later?
Logged

djones

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: LetsEncrypt troubleshooting advice..
« Reply #4 on: September 08, 2018, 09:19:48 pm »
I'm sorry I never got around to opening an issue but I did find the problem.

The acme script wasn't sleeping at all before checking the TXT record. It ignored the sleep time set in the validation methods.

After updating to 18.7.2 and acme.sh 2.7.9, it is now working as expecting and using the set sleep time.
Logged

Alphakilo

  • Newbie
  • *
  • Posts: 49
  • Karma: 6
    • View Profile
Re: LetsEncrypt troubleshooting advice..
« Reply #5 on: September 10, 2018, 12:12:24 pm »
I have the strong feeling that dns-01, like tls-sni-01, might be disabled in the foreseeable future:
https://www.theregister.co.uk/2018/09/06/certificate_authority_dns_validation/
Logged

tre4bax

  • Full Member
  • ***
  • Posts: 151
  • Karma: 4
    • View Profile
Re: LetsEncrypt troubleshooting advice..
« Reply #6 on: October 09, 2018, 10:03:25 pm »
Rule number one, never believe anything you see in the register.
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • General Discussion »
  • LetsEncrypt troubleshooting advice..
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2