acmesh-official / acme.sh

A pure Unix shell script implementing ACME client protocol
https://acme.sh
GNU General Public License v3.0
38.67k stars 4.91k forks source link

Unable to renew with Yandex DNS API #2351

Open webhive opened 5 years ago

webhive commented 5 years ago

Steps to reproduce

I had a domain what was updated automatically for a long time. But recently I got message about certificate expiration so a I was going to check and found what certificates are not renewed

After brief investigation I discovered what script unable to check inserted DNS txt record while really such a record present. Strange what it checked it vis cloudflare-dns - may be cloudflare access to yandex restricted?

Debug log

[Fri Jun 21 07:25:23 UTC 2019] d='diytronic.ru'
[Fri Jun 21 07:25:23 UTC 2019] txtdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:25:23 UTC 2019] aliasDomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:25:23 UTC 2019] txt='U9TnB8JNRvNIFRa7ZXe1-eCPcXMicA1pJfi_9j1DL4c'
[Fri Jun 21 07:25:23 UTC 2019] d_api='/root/.acme.sh/dnsapi/dns_yandex.sh'
[Fri Jun 21 07:25:23 UTC 2019] Checking diytronic.ru for _acme-challenge.diytronic.ru
[Fri Jun 21 07:25:23 UTC 2019] _c_txtdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:25:23 UTC 2019] _c_aliasdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:25:23 UTC 2019] _c_txt='U9TnB8JNRvNIFRa7ZXe1-eCPcXMicA1pJfi_9j1DL4c'
[Fri Jun 21 07:25:23 UTC 2019] GET
[Fri Jun 21 07:25:23 UTC 2019] url='https://cloudflare-dns.com/dns-query?name=_acme-challenge.diytronic.ru&type=TXT'
[Fri Jun 21 07:25:23 UTC 2019] timeout=
[Fri Jun 21 07:25:23 UTC 2019] _CURL='curl -L --silent --dump-header /acme.sh/http.header  -g '
[Fri Jun 21 07:25:23 UTC 2019] ret='0'
[Fri Jun 21 07:25:23 UTC 2019] Not valid yet, let's wait 10 seconds and check next one.
[Fri Jun 21 07:25:33 UTC 2019] _p_txtdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:25:33 UTC 2019] Cloudflare purge TXT record for domain _acme-challenge.diytronic.ru
[Fri Jun 21 07:25:33 UTC 2019] POST
[Fri Jun 21 07:25:33 UTC 2019] _post_url='https://1.1.1.1/api/v1/purge?domain=_acme-challenge.diytronic.ru&type=TXT'
[Fri Jun 21 07:25:33 UTC 2019] _CURL='curl -L --silent --dump-header /acme.sh/http.header  -g '
[Fri Jun 21 07:25:34 UTC 2019] _ret='0'
[Fri Jun 21 07:25:34 UTC 2019] Let's wait 10 seconds and check again.

Record on Yandex side

Снимок экрана 2019-06-21 в 10 41 26

Debug = 2

[Fri Jun 21 07:31:39 UTC 2019] Let's wait 10 seconds and check again.
[Fri Jun 21 07:31:49 UTC 2019] _is_idn_d='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] _idn_temp
[Fri Jun 21 07:31:49 UTC 2019] _is_idn_d='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] _idn_temp
[Fri Jun 21 07:31:49 UTC 2019] d='diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] txtdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] aliasDomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] txt='wF6ICHTx5dVBsJFClqmqfB80Sny6U4W0k0HqcnQih7o'
[Fri Jun 21 07:31:49 UTC 2019] d_api='/root/.acme.sh/dnsapi/dns_yandex.sh'
[Fri Jun 21 07:31:49 UTC 2019] Checking diytronic.ru for _acme-challenge.diytronic.ru
[Fri Jun 21 07:31:49 UTC 2019] _c_txtdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] _c_aliasdomain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] _c_txt='wF6ICHTx5dVBsJFClqmqfB80Sny6U4W0k0HqcnQih7o'
[Fri Jun 21 07:31:49 UTC 2019] _ns_ep='https://cloudflare-dns.com/dns-query'
[Fri Jun 21 07:31:49 UTC 2019] _ns_domain='_acme-challenge.diytronic.ru'
[Fri Jun 21 07:31:49 UTC 2019] _ns_type='TXT'
[Fri Jun 21 07:31:49 UTC 2019] GET
[Fri Jun 21 07:31:49 UTC 2019] url='https://cloudflare-dns.com/dns-query?name=_acme-challenge.diytronic.ru&type=TXT'
[Fri Jun 21 07:31:49 UTC 2019] timeout=
[Fri Jun 21 07:31:49 UTC 2019] Http already initialized.
[Fri Jun 21 07:31:49 UTC 2019] _CURL='curl -L --silent --dump-header /acme.sh/http.header  --trace-ascii /tmp/tmp.tYEBWEKw5z  -g '
[Fri Jun 21 07:31:50 UTC 2019] ret='0'
[Fri Jun 21 07:31:50 UTC 2019] response='{"Status": 0,"TC": false,"RD": true, "RA": true, "AD": false,"CD": false,"Question":[{"name": "_acme-challenge.diytronic.ru.", "type": 16}],"Answer":[{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"0_Pxz1tXoQB78iCnk3lnMxwF_wIPLE30lW5yMFVn_zw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"0y9o5Q6Kc6_D8PHq9UXwh8nw3y8qAuFvzOe5QtM_lMU\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"1r4KLIpErZfVLqaSMA9K7AeAIXtW6BWIJXmXUxSzTrc\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"2rMef8a6MiS5Kruynfol3CIgYUfxQ_HC6cL1NwBhoXc\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"3LeKnPEp8pCLJJllrsktLBkul9ubfdMILhzNaVQwStI\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"3TQe5xdL8ywhidmjDPDKuZt-jXUpeI44oqGskTVqD9E\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"5EO8SM_nru0tN3iexCUdjaxLRacgWjtF-hHEx3CycIA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"5hqg0hb-QumffSRl5U6qSjWImJY14DCdPGxvPb3rt64\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"6JMNgCM-fSEw0BCkwxLy2WXSrb1IFEopdzrQ4mra28Q\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"6Y3X5-NlfNzaDOFARrafMggm5PZkleyhTKNLsgyBagM\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"6kf-9RqI1XuuT6cVEYbcCPpgxiGMfYCT3u5PcYXHwRg\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"7QoZz-e-KUqI7NhkHlf3xxAJu10MQH2-Elq125EXRow\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"8czPRvikgexiHtqHtWMrB5L4VOJNxrMOvFHVI5RunMQ\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"A627WoiHnWeVSBGjEffK11nUIUaKKqLquu9v_KjnBdo\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"AoAEZDbVhixJVD9iKDMsLEySVI7HMjVmRlkML6EJwJA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"B4_PVOZqcW3mGD6LgYXQs9CjcY37EAAo6bfV9Aa4yhU\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"C67aLjzAgQjGwD8iqHZx4qjcjHUeDqAPbrLvLM0OZIw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"CiNLXkxV4kqMHQUb6aPjAvMTCiyt6Llpn2AKxjF4Izw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"DisJTB-ysloQ6H7zMeKao2bNpjN80vVY8iZBM_yr5mc\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Dw18Zx-lqtE4dWiM-85PMs8En_U7q3XRbiZsWhtYHUY\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"E8pzc_Is1z2KkfXp__jb1DvTv67d_3wzzK7gRdpfN7Y\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"FlHlvU70EsW4lIhM0Ox0jG4lPHr2KuynbOTfeL78UFQ\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Fm-yVFPU_-deHwr9iW0NLyLwKdJVFVq9Qu0wbhgB9aU\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"G8E28Sd8lBzZyyBhCH6_gO2OzDQAxluuG7W9m176m0M\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"GvTCt4IjnVfE7OweztTvGpEWLnE1GR25VIkZwFD2W6A\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"GzB4UXoWqMatGfbCZndpMrd8J2qUu4AYTsOA6OmG-Q4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"IQjza_mdIpvlS2x55e7qoi_anC-cahGxQ_mU7mhqYUI\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"LoH1CUOuh4dtoZjGeGucYRE-YPL3weIC_JciAkLY6DM\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"NbYOSaL-HWlP3oyDR6bRcT1bBiFaBo5GW5VA3INQBe4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Ogu1FVmS9IztpG1DU6aDcYXCQVy72Hv-H_F83tfznPA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"QJryN0WpXcLc6qyDmwT1rxlHwp8PZsgzlSS_9FwC5W4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"UjWWnV8GBGbVZ9uHj4gEuvoWvFZNGNB3kHe0Gun3vg4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"V9INLMHfAuwKHeTLYyL00X4vl5FuiVKvKvwYj69E6k0\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"VeQjKClCbXpb2cc4UNIYChYYh5FDCRrCbKjkNYJ2b4M\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"XYpv_5ps5zHiqJODMaW6aPQO3lSmDKFtqvsE379rREA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"YYjljhv2FXNjLNv7YT8vIb14ANohGBXpj4Lm5fR-T5M\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Zs6UWn8atnR3c-DUZCIrqPLmzrDlzoIMIbTGdsutPi4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"ahCYKsB3Fkd0iI6GGnhTvXZBkvUJ8fL2cHVz8E52xyA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"bw3E3L44VUk4DMFD7sj34txwvipo-7IOYTJgWH7RQK4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"d1M0ZVWNEdbuXArv3NLFnABVGGQrxxTF7hAd4B2gb7s\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"d1nWzNU1BFln9xMlqFG-OtaEbllsKwz-Wfc3oadb2Sw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"dsQFJwkQ1nirSMOR1Lp0TaRq1tvxalCxQjEcLRcfs00\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"eM1MhCrat-eOGK81QzM6XBc8i7Yos9ewFqlXHDuFK-M\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"erje-17QbQ6a-ahO_5Fmyz9be-rkQeibNlzpfzeZ0X8\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"ft84cEc64kY2se0m2o5fh7FItKVbxfg9v59OvFYTmCk\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"gUns9KMH_MagwIt6FHwIiR_QdKBdHKmHBHtiitprNSw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"hd0gWVgstrIHF0OpHehXKiyFyJq2WL27crDd5OIy0gE\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"hsdbEZZhzqMYPu2fhfI-FoXfawoPaWtq45lbwguB7ic\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"jhneUbU5TBW6LM5eEQGwKMCdLFBrbFyBv4yKcS5vr6U\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"jpisa4DF8w04gMsWe97DZP0T-mxd5gxV-wC1p0LIpiQ\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"k7yeaE14RmZyp0XwxbNcwzeGBaBo6PORp_uC3tsWr1A\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"kRjbv6r9kowu3mY7gfetp0Ue0mbQ-yUbABHO34znUyg\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"kngjUasIiP-r0hCkDAmAy_3xqQFRe13PjFpJsLoTI4Q\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"l-TcjlV-JRUNup-8mpOnY7nCX_SvEcmx2_r15r9eioA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"l3wxuJQhwQgR2CbIp_-GDXtSX31GAIwM35r3kDtatmI\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"m2MBzczFAAwFgxYc2So0-3KIA4WaKCWNhcOlkXL0Shg\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"no_k_aS9NWYaqiMRsCXciX7aSxdilC0GHXf2Fsw7kSM\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"oEhZSDpwIM6_cT1K2AnNaYdnVC6eHVB4792JUC_pEyI\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"p9ZT2lPs74rmFKUELLwxW22bkoOWEIEqaJGvROayarw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"qViJi1dwrMZuPjExTjvvyFVV4lZHvZIr48vjowk-mrw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"rC1ytA1W96fPAPb2CJXd4iAUmoiaf4N1eShdmq-2XTk\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"rEr_AJEgqS8pbtnXAjybVyNBpe_oS123OCHEoemtnvA\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"rjk8s6WxmS5Vf7rrRGC2PeqMm9wg8ZVJj8CLzYHdrS4\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"se4RvMui4eElqeHuNBo7zwuzUZBarcJDq1KT2mPCf1s\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"tbaZAXyl-40kM9mvgYimYU1GjkB8jXT_dgDNDQqq1ps\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"trDxOhdcFS2uHUfeW6ikccsGNdd8-nUl4Fq3DixOu8E\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"uIHw2E30Cu-98XgiZNxetdDk8yARV9kNmbD9k7pETJU\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"uQ-F-sWzXC_5PRAn1LxBMThh5VBsdjax9XwYvY3SPjw\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"vPb3h0nUl-nTB1H3Mh7WnE0lSnre3jkHzA5uFNozTmY\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"wQw8BFKXR6hRWQBbACe6MnCS2qKt-PdN0g-e1_9q6KU\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"x7qGlPDcehoI3WdR3g4NFmEJVafvUPTy_1VDJLXnJI8\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"xBaMcOxdP0-ELmrmNGiZnq12evgb22NL-i-OJZYnkyM\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"yGXOBdXdyrKCS0XH7LHHnh_Mf2nTyibfFzVlU2XOqAc\""},{"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"zg--ov8k6TUFiFIBIERWkJqqC57IeEw0MRl6D2zKLdw\""}]}'
[Fri Jun 21 07:31:50 UTC 2019] _answers='"Answer":[
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"0_Pxz1tXoQB78iCnk3lnMxwF_wIPLE30lW5yMFVn_zw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"0y9o5Q6Kc6_D8PHq9UXwh8nw3y8qAuFvzOe5QtM_lMU\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"1r4KLIpErZfVLqaSMA9K7AeAIXtW6BWIJXmXUxSzTrc\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"2rMef8a6MiS5Kruynfol3CIgYUfxQ_HC6cL1NwBhoXc\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"3LeKnPEp8pCLJJllrsktLBkul9ubfdMILhzNaVQwStI\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"3TQe5xdL8ywhidmjDPDKuZt-jXUpeI44oqGskTVqD9E\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"5EO8SM_nru0tN3iexCUdjaxLRacgWjtF-hHEx3CycIA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"5hqg0hb-QumffSRl5U6qSjWImJY14DCdPGxvPb3rt64\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"6JMNgCM-fSEw0BCkwxLy2WXSrb1IFEopdzrQ4mra28Q\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"6Y3X5-NlfNzaDOFARrafMggm5PZkleyhTKNLsgyBagM\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"6kf-9RqI1XuuT6cVEYbcCPpgxiGMfYCT3u5PcYXHwRg\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"7QoZz-e-KUqI7NhkHlf3xxAJu10MQH2-Elq125EXRow\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"8czPRvikgexiHtqHtWMrB5L4VOJNxrMOvFHVI5RunMQ\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"A627WoiHnWeVSBGjEffK11nUIUaKKqLquu9v_KjnBdo\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"AoAEZDbVhixJVD9iKDMsLEySVI7HMjVmRlkML6EJwJA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"B4_PVOZqcW3mGD6LgYXQs9CjcY37EAAo6bfV9Aa4yhU\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"C67aLjzAgQjGwD8iqHZx4qjcjHUeDqAPbrLvLM0OZIw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"CiNLXkxV4kqMHQUb6aPjAvMTCiyt6Llpn2AKxjF4Izw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"DisJTB-ysloQ6H7zMeKao2bNpjN80vVY8iZBM_yr5mc\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Dw18Zx-lqtE4dWiM-85PMs8En_U7q3XRbiZsWhtYHUY\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"E8pzc_Is1z2KkfXp__jb1DvTv67d_3wzzK7gRdpfN7Y\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"FlHlvU70EsW4lIhM0Ox0jG4lPHr2KuynbOTfeL78UFQ\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Fm-yVFPU_-deHwr9iW0NLyLwKdJVFVq9Qu0wbhgB9aU\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"G8E28Sd8lBzZyyBhCH6_gO2OzDQAxluuG7W9m176m0M\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"GvTCt4IjnVfE7OweztTvGpEWLnE1GR25VIkZwFD2W6A\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"GzB4UXoWqMatGfbCZndpMrd8J2qUu4AYTsOA6OmG-Q4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"IQjza_mdIpvlS2x55e7qoi_anC-cahGxQ_mU7mhqYUI\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"LoH1CUOuh4dtoZjGeGucYRE-YPL3weIC_JciAkLY6DM\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"NbYOSaL-HWlP3oyDR6bRcT1bBiFaBo5GW5VA3INQBe4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Ogu1FVmS9IztpG1DU6aDcYXCQVy72Hv-H_F83tfznPA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"QJryN0WpXcLc6qyDmwT1rxlHwp8PZsgzlSS_9FwC5W4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"UjWWnV8GBGbVZ9uHj4gEuvoWvFZNGNB3kHe0Gun3vg4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"V9INLMHfAuwKHeTLYyL00X4vl5FuiVKvKvwYj69E6k0\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"VeQjKClCbXpb2cc4UNIYChYYh5FDCRrCbKjkNYJ2b4M\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"XYpv_5ps5zHiqJODMaW6aPQO3lSmDKFtqvsE379rREA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"YYjljhv2FXNjLNv7YT8vIb14ANohGBXpj4Lm5fR-T5M\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"Zs6UWn8atnR3c-DUZCIrqPLmzrDlzoIMIbTGdsutPi4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"ahCYKsB3Fkd0iI6GGnhTvXZBkvUJ8fL2cHVz8E52xyA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"bw3E3L44VUk4DMFD7sj34txwvipo-7IOYTJgWH7RQK4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"d1M0ZVWNEdbuXArv3NLFnABVGGQrxxTF7hAd4B2gb7s\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"d1nWzNU1BFln9xMlqFG-OtaEbllsKwz-Wfc3oadb2Sw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"dsQFJwkQ1nirSMOR1Lp0TaRq1tvxalCxQjEcLRcfs00\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"eM1MhCrat-eOGK81QzM6XBc8i7Yos9ewFqlXHDuFK-M\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"erje-17QbQ6a-ahO_5Fmyz9be-rkQeibNlzpfzeZ0X8\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"ft84cEc64kY2se0m2o5fh7FItKVbxfg9v59OvFYTmCk\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"gUns9KMH_MagwIt6FHwIiR_QdKBdHKmHBHtiitprNSw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"hd0gWVgstrIHF0OpHehXKiyFyJq2WL27crDd5OIy0gE\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"hsdbEZZhzqMYPu2fhfI-FoXfawoPaWtq45lbwguB7ic\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"jhneUbU5TBW6LM5eEQGwKMCdLFBrbFyBv4yKcS5vr6U\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"jpisa4DF8w04gMsWe97DZP0T-mxd5gxV-wC1p0LIpiQ\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"k7yeaE14RmZyp0XwxbNcwzeGBaBo6PORp_uC3tsWr1A\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"kRjbv6r9kowu3mY7gfetp0Ue0mbQ-yUbABHO34znUyg\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"kngjUasIiP-r0hCkDAmAy_3xqQFRe13PjFpJsLoTI4Q\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"l-TcjlV-JRUNup-8mpOnY7nCX_SvEcmx2_r15r9eioA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"l3wxuJQhwQgR2CbIp_-GDXtSX31GAIwM35r3kDtatmI\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"m2MBzczFAAwFgxYc2So0-3KIA4WaKCWNhcOlkXL0Shg\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"no_k_aS9NWYaqiMRsCXciX7aSxdilC0GHXf2Fsw7kSM\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"oEhZSDpwIM6_cT1K2AnNaYdnVC6eHVB4792JUC_pEyI\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"p9ZT2lPs74rmFKUELLwxW22bkoOWEIEqaJGvROayarw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"qViJi1dwrMZuPjExTjvvyFVV4lZHvZIr48vjowk-mrw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"rC1ytA1W96fPAPb2CJXd4iAUmoiaf4N1eShdmq-2XTk\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"rEr_AJEgqS8pbtnXAjybVyNBpe_oS123OCHEoemtnvA\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"rjk8s6WxmS5Vf7rrRGC2PeqMm9wg8ZVJj8CLzYHdrS4\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"se4RvMui4eElqeHuNBo7zwuzUZBarcJDq1KT2mPCf1s\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"tbaZAXyl-40kM9mvgYimYU1GjkB8jXT_dgDNDQqq1ps\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"trDxOhdcFS2uHUfeW6ikccsGNdd8-nUl4Fq3DixOu8E\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"uIHw2E30Cu-98XgiZNxetdDk8yARV9kNmbD9k7pETJU\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"uQ-F-sWzXC_5PRAn1LxBMThh5VBsdjax9XwYvY3SPjw\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"vPb3h0nUl-nTB1H3Mh7WnE0lSnre3jkHzA5uFNozTmY\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"wQw8BFKXR6hRWQBbACe6MnCS2qKt-PdN0g-e1_9q6KU\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"x7qGlPDcehoI3WdR3g4NFmEJVafvUPTy_1VDJLXnJI8\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"xBaMcOxdP0-ELmrmNGiZnq12evgb22NL-i-OJZYnkyM\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"yGXOBdXdyrKCS0XH7LHHnh_Mf2nTyibfFzVlU2XOqAc\""
,
"name": "_acme-challenge.diytronic.ru.", "type": 16, "TTL": 360, "data": "\"zg--ov8k6TUFiFIBIERWkJqqC57IeEw0MRl6D2zKLdw\""
]'
[Fri Jun 21 07:31:50 UTC 2019] Not valid yet, let's wait 10 seconds and check next one.
Снимок экрана 2019-06-21 в 10 50 52
RingoAl commented 5 years ago

Hello. I have the same problem, but it seems that it is Yandex DNS error. Records are present in web interface of PDD, but are missing on DNS server. dig TXT _acme-challenge.domain.name @dns.yandex.ru returns no TXT records. I've created an issue in PDD support, but at this moment they recommend to move domain to Connect which doesn't have DNS API.

RingoAl commented 5 years ago

Hello. Yandex support told me, that Yandex.Connect now support adding and deleting DNS records via same PDD API, so you can simply migrate your domain to Connect. I've tried this on my domain and it worked.

tumarov commented 5 years ago

According to acme.sh.log, after I use the command acme.sh --issue --dns dns_yandex -d <mydomain> the script creates a new TXT record and tries to check the access to it (during 20 minutes max). It uses https://cloudflare-dns.com/dns-query service for checking. When cloudflare-dns tells OK (I got OK), the script make a POST request to https://acme-v02.api.letsencrypt.org/acme/challenge. I suppose, acme-v02.api.letsencrypt.org make one more TXT record access checking. And it fails. It seems to me, at this moment, not all dns servers know about our new TXT record. That is why, certificate issuing fails. As a result I cannot use DNS auto mode :(

WhiteAls commented 5 years ago

I have a much more interesting results. It can't find domain at all. But wildcard version of the same domain passess all checks fine

[Wed Sep 18 16:04:41 MSK 2019] d='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] Getting webroot for domain='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _w='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _currentRoot='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _is_idn_d='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _idn_temp
[Wed Sep 18 16:04:41 MSK 2019] response='{"identifier":{"type":"dns","value":"bgiik.ru"},"status":"valid","expires":"2019-10-24T00:16:39Z","challenges":[{"type":"dns-01","status":"valid","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51","token":"1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0","validationRecord":[{"hostname":"bgiik.ru"}]}],"wildcard": true}'
[Wed Sep 18 16:04:41 MSK 2019] base64 single line.
[Wed Sep 18 16:04:41 MSK 2019] entry='"type":"dns-01","status":"valid","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51","token":"1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0","validationRecord":[{"hostname":"bgiik.ru"'
[Wed Sep 18 16:04:41 MSK 2019] token='1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0'
[Wed Sep 18 16:04:41 MSK 2019] uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51'
[Wed Sep 18 16:04:41 MSK 2019] keyauthorization='1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo'
[Wed Sep 18 16:04:41 MSK 2019] *.bgiik.ru is already verified.
[Wed Sep 18 16:04:41 MSK 2019] keyauthorization='verified_ok'
[Wed Sep 18 16:04:41 MSK 2019] dvlist='*.bgiik.ru#verified_ok#https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51#dns-01#dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] d='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] Getting webroot for domain='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _w='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _currentRoot='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _is_idn_d='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _idn_temp
[Wed Sep 18 16:04:41 MSK 2019] response='{"identifier":{"type":"dns","value":"bgiik.ru"},"status":"pending","expires":"2019-09-25T13:04:21Z","challenges":[{"type":"http-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/taJIJ1","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU"},{"type":"dns-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU"},{"type":"tls-alpn-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/p-uXv1","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU"}]}'
[Wed Sep 18 16:04:41 MSK 2019] entry='"type":"dns-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YYQ","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfG1"'
[Wed Sep 18 16:04:41 MSK 2019] token='1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU'
[Wed Sep 18 16:04:41 MSK 2019] uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1'
[Wed Sep 18 16:04:41 MSK 2019] keyauthorization='1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo'
[Wed Sep 18 16:04:41 MSK 2019] dvlist='bgiik.ru#1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo#https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1#dns-01#dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] d
[Wed Sep 18 16:04:41 MSK 2019] vlist='*.bgiik.ru#verified_ok#https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51#dns-01#dns_yandex,bgiik.ru#1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo#https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1#dns-01#dns_yandex,'
[Wed Sep 18 16:04:41 MSK 2019] d='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] *.bgiik.ru is already verified, skip dns-01.
[Wed Sep 18 16:04:41 MSK 2019] d='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _d_alias
[Wed Sep 18 16:04:41 MSK 2019] txtdomain='_acme-challenge.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] base64 single line.
[Wed Sep 18 16:04:41 MSK 2019] txt='1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k'
[Wed Sep 18 16:04:41 MSK 2019] d_api='/usr/local/pkg/acme/dnsapi/dns_yandex.sh'
[Wed Sep 18 16:04:41 MSK 2019] dns_entry='bgiik.ru,_acme-challenge.bgiik.ru,,dns_yandex,1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k,/usr/local/pkg/acme/dnsapi/dns_yandex.sh'
[Wed Sep 18 16:04:41 MSK 2019] Found domain api file: /usr/local/pkg/acme/dnsapi/dns_yandex.sh
[Wed Sep 18 16:04:41 MSK 2019] dns_yandex_add exists=0
[Wed Sep 18 16:04:41 MSK 2019] Adding txt value: 1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k for domain:  _acme-challenge.bgiik.ru
[Wed Sep 18 16:04:41 MSK 2019] Calling: dns_yandex_add() '_acme-challenge.bgiik.ru' '1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k'
[Wed Sep 18 16:04:41 MSK 2019] APP
[Wed Sep 18 16:04:41 MSK 2019] 5:PDD_Token='YDLA72DGQV3WHFATOLNUIVDRNGRQ24RSCZ3ZDHK2LFR2Y5FUSGV1Q'
[Wed Sep 18 16:04:41 MSK 2019] GET
[Wed Sep 18 16:04:41 MSK 2019] url='https://pddimp.yandex.ru/api2/admin/domain/domains?page=1&on_page=20'
[Wed Sep 18 16:04:41 MSK 2019] timeout=
[Wed Sep 18 16:04:41 MSK 2019] Http already initialized.
[Wed Sep 18 16:04:41 MSK 2019] _CURL='curl -L --silent --dump-header /tmp/acme/bgiikru//http.header  -g '
[Wed Sep 18 16:04:49 MSK 2019] ret='0'
[Wed Sep 18 16:04:49 MSK 2019] res1='{"total": 1, "domains":[{"from_registrar":"no", "dkim-ready":"yes", "emails-max-count": 2147483647, "aliases":["bgiki.ru", "xn--90aepak.xn--p1ai"], "logo_enabled":"no", "master_admin": false, "workspace":"yes", "show-simple-check":"no", "ws_technical":"no", "show-ready-soon":"no", "emails-count": 181, "stage":"added", "status":"added", "nsdelegated":"yes", "name":"bgiik.ru"}], "on_page": 20, "success":"ok", "page": 1, "found": 1}'
[Wed Sep 18 16:04:49 MSK 2019] found:  results on page
[Wed Sep 18 16:04:49 MSK 2019] last page: 1
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain bgiik.ru
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain ru
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] No suitable domain found in your account 
unixzen commented 5 years ago

I have a much more interesting results. It can't find domain at all. But wildcard version of the same domain passess all checks fine

[Wed Sep 18 16:04:41 MSK 2019] d='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] Getting webroot for domain='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _w='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _currentRoot='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _is_idn_d='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _idn_temp
[Wed Sep 18 16:04:41 MSK 2019] response='{"identifier":{"type":"dns","value":"bgiik.ru"},"status":"valid","expires":"2019-10-24T00:16:39Z","challenges":[{"type":"dns-01","status":"valid","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51","token":"1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0","validationRecord":[{"hostname":"bgiik.ru"}]}],"wildcard": true}'
[Wed Sep 18 16:04:41 MSK 2019] base64 single line.
[Wed Sep 18 16:04:41 MSK 2019] entry='"type":"dns-01","status":"valid","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51","token":"1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0","validationRecord":[{"hostname":"bgiik.ru"'
[Wed Sep 18 16:04:41 MSK 2019] token='1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0'
[Wed Sep 18 16:04:41 MSK 2019] uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51'
[Wed Sep 18 16:04:41 MSK 2019] keyauthorization='1zy0FilfwYQU95XUklU2IpQ08LPOTRzvbLcn8x22GO0.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo'
[Wed Sep 18 16:04:41 MSK 2019] *.bgiik.ru is already verified.
[Wed Sep 18 16:04:41 MSK 2019] keyauthorization='verified_ok'
[Wed Sep 18 16:04:41 MSK 2019] dvlist='*.bgiik.ru#verified_ok#https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51#dns-01#dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] d='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] Getting webroot for domain='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _w='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _currentRoot='dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] _is_idn_d='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _idn_temp
[Wed Sep 18 16:04:41 MSK 2019] response='{"identifier":{"type":"dns","value":"bgiik.ru"},"status":"pending","expires":"2019-09-25T13:04:21Z","challenges":[{"type":"http-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/taJIJ1","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU"},{"type":"dns-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU"},{"type":"tls-alpn-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/p-uXv1","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU"}]}'
[Wed Sep 18 16:04:41 MSK 2019] entry='"type":"dns-01","status":"pending","url":"https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YYQ","token":"1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfG1"'
[Wed Sep 18 16:04:41 MSK 2019] token='1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU'
[Wed Sep 18 16:04:41 MSK 2019] uri='https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1'
[Wed Sep 18 16:04:41 MSK 2019] keyauthorization='1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo'
[Wed Sep 18 16:04:41 MSK 2019] dvlist='bgiik.ru#1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo#https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1#dns-01#dns_yandex'
[Wed Sep 18 16:04:41 MSK 2019] d
[Wed Sep 18 16:04:41 MSK 2019] vlist='*.bgiik.ru#verified_ok#https://acme-v02.api.letsencrypt.org/acme/chall-v3/374453631/MP8o51#dns-01#dns_yandex,bgiik.ru#1pLuytU_sO5twz7U_1CT_IFQCFHbbuep29tHTIGGfGU.PUbaPtbUJ8XvqNHXS82cxKgQ81hphefNRGlLTpw69Oo#https://acme-v02.api.letsencrypt.org/acme/chall-v3/397069427/l-6YY1#dns-01#dns_yandex,'
[Wed Sep 18 16:04:41 MSK 2019] d='*.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] *.bgiik.ru is already verified, skip dns-01.
[Wed Sep 18 16:04:41 MSK 2019] d='bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] _d_alias
[Wed Sep 18 16:04:41 MSK 2019] txtdomain='_acme-challenge.bgiik.ru'
[Wed Sep 18 16:04:41 MSK 2019] base64 single line.
[Wed Sep 18 16:04:41 MSK 2019] txt='1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k'
[Wed Sep 18 16:04:41 MSK 2019] d_api='/usr/local/pkg/acme/dnsapi/dns_yandex.sh'
[Wed Sep 18 16:04:41 MSK 2019] dns_entry='bgiik.ru,_acme-challenge.bgiik.ru,,dns_yandex,1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k,/usr/local/pkg/acme/dnsapi/dns_yandex.sh'
[Wed Sep 18 16:04:41 MSK 2019] Found domain api file: /usr/local/pkg/acme/dnsapi/dns_yandex.sh
[Wed Sep 18 16:04:41 MSK 2019] dns_yandex_add exists=0
[Wed Sep 18 16:04:41 MSK 2019] Adding txt value: 1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k for domain:  _acme-challenge.bgiik.ru
[Wed Sep 18 16:04:41 MSK 2019] Calling: dns_yandex_add() '_acme-challenge.bgiik.ru' '1JFQRYUueu76XfcAMhaGprIAQKQTnJ6y1mHwHfqHn1k'
[Wed Sep 18 16:04:41 MSK 2019] APP
[Wed Sep 18 16:04:41 MSK 2019] 5:PDD_Token='YDLA72DGQV3WHFATOLNUIVDRNGRQ24RSCZ3ZDHK2LFR2Y5FUSGV1Q'
[Wed Sep 18 16:04:41 MSK 2019] GET
[Wed Sep 18 16:04:41 MSK 2019] url='https://pddimp.yandex.ru/api2/admin/domain/domains?page=1&on_page=20'
[Wed Sep 18 16:04:41 MSK 2019] timeout=
[Wed Sep 18 16:04:41 MSK 2019] Http already initialized.
[Wed Sep 18 16:04:41 MSK 2019] _CURL='curl -L --silent --dump-header /tmp/acme/bgiikru//http.header  -g '
[Wed Sep 18 16:04:49 MSK 2019] ret='0'
[Wed Sep 18 16:04:49 MSK 2019] res1='{"total": 1, "domains":[{"from_registrar":"no", "dkim-ready":"yes", "emails-max-count": 2147483647, "aliases":["bgiki.ru", "xn--90aepak.xn--p1ai"], "logo_enabled":"no", "master_admin": false, "workspace":"yes", "show-simple-check":"no", "ws_technical":"no", "show-ready-soon":"no", "emails-count": 181, "stage":"added", "status":"added", "nsdelegated":"yes", "name":"bgiik.ru"}], "on_page": 20, "success":"ok", "page": 1, "found": 1}'
[Wed Sep 18 16:04:49 MSK 2019] found:  results on page
[Wed Sep 18 16:04:49 MSK 2019] last page: 1
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain bgiik.ru
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain ru
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] finding zone for domain 
[Wed Sep 18 16:04:49 MSK 2019] No suitable domain found in your account 

I had the same problem.

1F33LR41N commented 4 years ago

Had the same problem as last two guys, No suitable domain found in your account. Do someone have any ideas how to fix it ?

WhiteAls commented 4 years ago

Had the same problem as last two guys, No suitable domain found in your account. Do someone have any ideas how to fix it ?

remove alias domains or use DNS manual mode

1F33LR41N commented 4 years ago

As I know, YandexDNS has no support of aliases for domains, so, I have no configured aliases...

WhiteAls commented 4 years ago

seems it was (unintentionaly? 😅) fixed in #2690 i'm using acme.sh package in pfsense and replacing dns_yandex.sh with the newer version fixed the problem (but you still need a longer DNS-Sleep, 20 minutes in my case 😨)

RingoAl commented 4 years ago

I've moved from Yandex DNS due to its inconsistency. dig can show that the record was added successfully, but acme.sh fails.