Solved LetsEncrypt Renewal Failure V20

Status
Not open for further replies.

prolateral

Bronze Partner
Basic Certified
Joined
Feb 18, 2019
Messages
25
Reaction score
12
Hi - our internal system is a self-hosted V20U2 (upgraded from V18 in Mar24).

We are using the 3cx.co.uk FQDN Letsencrypt certs - and we have got the below error two nights running now:

SSL Certificate renewal has been failed. Error: IpUpdater.FqdnGenerationException: Can not create FQDN in 600 seconds at PostInstall.CertificateGenerator.ProcessCertificatesDirectory(String directory, Boolean temporaryCertificateGenerated, Int32 regenerateNotSelfSignedCertificatesFrom, Int32 regenerateNotSelfSignedCertificatesTo, PhoneSystem ps, Int32 regenerateCertificateExiredInDays, UInt16 sipPort, UInt16 tunnelPort, Nullable`1 httpPort, Nullable`1 httpsPort, Boolean isPassiveFailoverMode, Boolean enableDnsHelper) at PostInstall.CertificateGenerator.RenewCertificates(String appBin, String appData) A communication error occurred between the DNS Servers and LetsEncrypt. This rarely happens and is usually resolved on the second attempt. 3CX will try again.

Current cert was issued (without any problem) on 8th Aug. We have until 10th Nov to resolve.

There have been no networking changes (that we know of) since the last cert renewal...

Any ideas as to what the issue could be?
 
I've only ever seen this when there's been a problem with the DNS provider or letsencrypt (i.e. not a fault at your end).

I would give it a day or two to resolve itself, and maybe restart your services before digging too deep into the cause.

Keep your eyes peeled for any similar threads or "Me too" replies to your thread which might suggest an outage somewhere.
 
  • Like
Reactions: prolateral
Just going to chime in to keep an eye on this as well. I saw another post yesterday stating there were some failures, and we had 2 overnight. In the past, these have cleared up by themselves but since it appears to be spanning a few days now, its on the radar.
 
  • Like
Reactions: prolateral
Our domain LetsEncrypt worked this morning - after three days of failures. :shrug:....

Thanks folks...
 
  • Like
Reactions: pmterp
This is the reason why we start the renewal process at the 2 month mark, instead of waiting for the last day.

Sometimes things do not go according to plan. Sometimes Let's Encrypt might be running with degraded performance, causing the renewals, or even issuing of certificates to fail.

You can always monitor the staus of Lets Encrypt at https://letsencrypt.status.io/
 
  • Like
Reactions: prolateral
Thank you for the feedback
 
  • Like
Reactions: prolateral
Status
Not open for further replies.

Forum statistics

Threads
111,969
Messages
590,050
Members
164,881
Latest member
mdavis@housingresourcesin