Skip to content

My SSL certificate took 4 days to propagate

Reviews by netop_mares 23 replies 5.2K views
#11

I only ask because I ran into the exact same thing with Hetzner last year. Their panel lets you request the cert before it validates CAA, so you end up in this weird limbo where the order exists but can't finalize.

pieter_rtm said:
Flush local resolver: ipconfig /flushdns or systemd-res
That part only helps if your local machine is the one with stale cache. The real problem is every recursive resolver between you and your visitors also held that 86400s record. No amount of flushing on your laptop fixes that. I ended up just eating the wait. Dropped TTL to 300 for next time though.

436 days. reboot is surrender.
#12

Armstrongvds — I wouldn't call a support reply with full CT logs and a bullet list "silent patching". That is more transparency than most of us get from Contabo on a good day

Still, the broader point stands. OVHcloud could have sent a proactive DNS health check instead of letting the ticket sit. The tooling exists. They chose not to use it

netop_mares said:
Back in my day we had to walk uphill both ways

Marcus, did you ever get that CAA record sorted? Ten days is plenty of time for even a 86400s TTL to clear, so the warnings should be gone by now unless something else is stuck

#13

Twelve days late to this but I just had the same scare with Contabo. Uploaded CSR, panicked after 24 hours, then realized my TTL was set to 172800 from some ancient migration. Dropped it to 300 and the cert showed up in ten minutes.

pieter_rtm said:
Drop TTL to 300s before any change

This should be in bold at the top of every SSL onboarding page. Nobody reads the fine print.

Did you ever get that CAA record sorted, netop_mares?

phở at 3AM, deploy at 4
#14

I only ask because I am staring at a similar TTL problem on InterServer and wondering if I should even bother opening a ticket or just go make coffee for four days. Also 17 days late to this but the CAA thing keeps coming up. I have seen hosts that auto-add it and hosts that do not. Seems like a weird line to draw for "managed" service.

#15

Twenty-one days and no word from netop_mares. I am left wondering whether the TTL drop resolved the warnings or if the silence means they migrated elsewhere

armstrongvds said:
86400s TTL is asking for pain

It is, yet I see this default constantly. Registrars and hosts both push long TTLs as a performance optimisation without warning users about the operational cost. The irony is that modern anycast resolvers make short TTLs nearly free

Has anyone here actually convinced their organisation to standardise on 300s globally? I have tried twice and been overruled by the network team citing "query load"

#16

Actually re-reading Pieter's reply, I don't think there was any silent patch here. The cert really did issue in 15 minutes.

netop_mares said:
The young people tell me "it just works"
They aren't wrong, but they skip the part where your DNS has to not fight you.

one small ping for man...
#17

Not a silent patch, just normal issuance

The logs I pulled were from our public CT monitor — https://crt.sh
Nothing happened on our end that wasn't logged

armstrongvds said:
86400s TTL is asking for pain

It really is
I tell people this every week and they still leave it at a day

For anyone finding this later: drop your TTL *before* you need the change
Not after you're already waiting

Containers before it was cool
#18

Did anyone actually try the CAA record fix. I added one on Leaseweb last month and the difference was immediate. Without it you're just hoping the CA picks the right path.

Also

armstrongvds said:
86400s TTL is asking for pain
— honestly most defaults are still 3600 or higher. The real pain is nobody tells you to drop it *before* you start.

sync, encrypt, forget, restore
#19

I keep meaning to add one to my own setup over at Vultr and then forgetting until the next renewal reminder hits.

pieter_rtm said:
Drop TTL to 300s before any change
This is the bit I always forget until I'm already mid-migration and watching paint dry. Forty days on, hopefully your DNS is behaving itself now.

#20

55 days late to this but did you ever get that CAA record sorted

pieter_rtm said:
Your CAA record: missing entirely

I only ask because I have seen missing CAA cause silent renewal failures six months down the line. The certificate looks fine in browser but the automated re-issue dies at 2am on a Sunday. Learned that one with Vultr a while back. Not fun.

Your TTL fix probably saved you the next time at least.

436 days. reboot is surrender.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft