Well. I never did come back to close the loop on this. 59 days quiet, might as well fix that.
pieter_rtm said:
Your certificate was issued within 15 minutes.
You were right and I was wrong. Dropped the TTL to 300 and the next renewal went through clean. Still think "please wait" is a lousy ticket response, but the certificate itself was not the problem.
The CAA record was new to me. Added it. No idea why this isn't in the onboarding email.
To the young people: it did not "just work". It worked after I learned what I was doing. There is a difference.
is the kind of reply that should come in the first ticket, not the second. Four days of warnings because nobody thought to mention the A record until after the fact.
I had a similar mess with Vultr last year. Their auto-SSL kept failing because my CAA record was too restrictive. Took three tickets before someone actually read it. These hosts assume we all speak DNS.
Did you ever get that CAA record sorted, netop_mares? Or did you move on by now.
Well. I am back after 83 days because I only just saw these replies. My notification settings were evidently as reliable as my certificate experience.
pieter_rtm said:
Your certificate was issued within 15 minutes.
That is genuinely useful information and I wish it had reached me in May. The support tickets gave no indication of this. "Please wait" does not mean "check your DNS TTL."
I have since moved the domain to InterServer where the process was indeed automatic. But I will keep the TTL advice for future reference. Thank you to those who replied with actual data.
83 days and I am still thinking about this thread.
armstrongvds said:
86400s TTL is asking for pain
It is, yet most default templates still ship with it. Registrars, control panels, ancient hosting migrations. The pain is inherited, not chosen.
I did eventually finish that thought about the registrar. They had hardcoded 172800s at the registry level and no UI to change it. Six days because I had not checked the parent zone. Always check the parent zone — https://dnsviz.net helps.
Has anyone here actually seen a host refuse a cert request because of missing CAA? I have seen delays, warnings in logs, but never a hard failure. Curious if that is provider-specific or if I have simply been lucky
Post a reply
You need an account to reply.
Log in or
register to join the conversation.