I only ask because I ran into the exact same thing with Hetzner last year. Their panel lets you request the cert before it validates CAA, so you end up in this weird limbo where the order exists but can't finalize.
My SSL certificate took 4 days to propagate
Armstrongvds — I wouldn't call a support reply with full CT logs and a bullet list "silent patching". That is more transparency than most of us get from Contabo on a good day
Still, the broader point stands. OVHcloud could have sent a proactive DNS health check instead of letting the ticket sit. The tooling exists. They chose not to use it
Marcus, did you ever get that CAA record sorted? Ten days is plenty of time for even a 86400s TTL to clear, so the warnings should be gone by now unless something else is stuck
Twelve days late to this but I just had the same scare with Contabo. Uploaded CSR, panicked after 24 hours, then realized my TTL was set to 172800 from some ancient migration. Dropped it to 300 and the cert showed up in ten minutes.
This should be in bold at the top of every SSL onboarding page. Nobody reads the fine print.
Did you ever get that CAA record sorted, netop_mares?
I only ask because I am staring at a similar TTL problem on InterServer and wondering if I should even bother opening a ticket or just go make coffee for four days. Also 17 days late to this but the CAA thing keeps coming up. I have seen hosts that auto-add it and hosts that do not. Seems like a weird line to draw for "managed" service.
Twenty-one days and no word from netop_mares. I am left wondering whether the TTL drop resolved the warnings or if the silence means they migrated elsewhere
It is, yet I see this default constantly. Registrars and hosts both push long TTLs as a performance optimisation without warning users about the operational cost. The irony is that modern anycast resolvers make short TTLs nearly free
Has anyone here actually convinced their organisation to standardise on 300s globally? I have tried twice and been overruled by the network team citing "query load"
Actually re-reading Pieter's reply, I don't think there was any silent patch here. The cert really did issue in 15 minutes.
Not a silent patch, just normal issuance
The logs I pulled were from our public CT monitor — https://crt.sh
Nothing happened on our end that wasn't logged
It really is
I tell people this every week and they still leave it at a day
For anyone finding this later: drop your TTL *before* you need the change
Not after you're already waiting
Did anyone actually try the CAA record fix. I added one on Leaseweb last month and the difference was immediate. Without it you're just hoping the CA picks the right path.
Also
I keep meaning to add one to my own setup over at Vultr and then forgetting until the next renewal reminder hits.
55 days late to this but did you ever get that CAA record sorted
I only ask because I have seen missing CAA cause silent renewal failures six months down the line. The certificate looks fine in browser but the automated re-issue dies at 2am on a Sunday. Learned that one with Vultr a while back. Not fun.
Your TTL fix probably saved you the next time at least.