Skip to content

Timeout waiting for DNS record propagation #1850

Answered by ieure
ieure asked this question in Q&A
Discussion options

You must be logged in to vote

Okay, I was able to figure this out.

I was asking for certs for lab.pins.atomized.org (and a wildcard of that). But pins.atomized.org was delegated to a nameserver that's only reachable on my LAN, so when LE tried to validate the challenge, it couldn't reach it and reported SERVFAIL.

And also, the DDNS update put the challenge response into a place where LE would never look, again, because of the delegation of the subdomain.

I removed the NS record which delegated it, ran lego again, and it worked fine.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by ieure
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
1 participant