acmesh-official / acme.sh

A pure Unix shell script implementing ACME client protocol
https://acme.sh
GNU General Public License v3.0
38.67k stars 4.91k forks source link

Getting "The CSR contains no identifiers" when signing CSR using alias using zerosll #3667

Open komailo opened 3 years ago

komailo commented 3 years ago

Trying to migrate from Lets Encrypt to ZeroSSL but been getting error:

[Fri Aug 20 02:42:54 UTC 2021] Sign failed, finalize code is not 200.
[Fri Aug 20 02:42:54 UTC 2021] {"type":"urn:ietf:params:acme:error:badCSR","status":400,"detail":"The CSR contains no identifiers"}

I am not able to find out what the error means.

Steps to reproduce

acme.sh  \
        --signcsr \
        --csr csf_file.csr \
        --dns  dns_dynu \
        --challenge-alias <removed> \
        --server zerossl

Debug log

[Fri Aug 20 02:37:06 UTC 2021] _selectServer try snames='zerossl.com,zerossl'
[Fri Aug 20 02:37:06 UTC 2021] _selectServer match zerossl
[Fri Aug 20 02:37:06 UTC 2021] Selected server: https://acme.zerossl.com/v2/DV90
[Fri Aug 20 02:37:06 UTC 2021] Lets find script dir.
[Fri Aug 20 02:37:06 UTC 2021] _SCRIPT_='/usr/lib/acmesh/acme.sh'
[Fri Aug 20 02:37:06 UTC 2021] _script='/usr/lib/acmesh/acme.sh'
[Fri Aug 20 02:37:06 UTC 2021] _script_home='/usr/lib/acmesh'
[Fri Aug 20 02:37:06 UTC 2021] Using config home:/srv/acmesh/data
[Fri Aug 20 02:37:06 UTC 2021] LE_WORKING_DIR='/usr/lib/acmesh'
https://github.com/acmesh-official/acme.sh
v3.0.1
[Fri Aug 20 02:37:06 UTC 2021] Using server: zerossl
[Fri Aug 20 02:37:06 UTC 2021] Running cmd: signcsr
[Fri Aug 20 02:37:06 UTC 2021] _csrsubj='<removed>'
[Fri Aug 20 02:37:06 UTC 2021] _csrsubj='<removed>'
[Fri Aug 20 02:37:06 UTC 2021] _dnsAltnames
[Fri Aug 20 02:37:06 UTC 2021] AltNames doesn't contain subject
[Fri Aug 20 02:37:06 UTC 2021] _csrdomainlist
[Fri Aug 20 02:37:06 UTC 2021] _outcsr='Certificate Request:
    Data:
        Version: 1 (0x0)
        Subject: C = CA, ST = ON, L = Ottawa, O = <removed>, OU = SNS, CN = <removed>, emailAddress = <removed>
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                RSA Public-Key: (4096 bit)
                Modulus:
                    00:bd:75:d8:ea:98:4b:8d:d6:4b:a0:98:82:05:c1:
                    c2:11:dc:4c:de:1f:18:48:40:49:b4:38:11:3a:3b:
                    9b:5a:77:ae:28:55:74:da:0a:16:40:45:a5:37:dc:
                    f6:7a:bd:7a:ff:60:4f:ba:e4:14:05:21:b1:5c:13:
                    d2:79:dd:f8:c6:34:1c:71:31:0b:45:b2:9c:57:0a:
                    20:24:c0:f5:42:21:96:a3:67:5a:63:51:d8:17:0f:
                    d9:a4:d0:1d:84:c9:25:12:ba:c2:22:9d:71:4e:72:
                    8d:db:6c:3b:4c:a2:bc:57:25:37:74:3f:43:77:84:
                    3e:6f:52:62:7f:e6:8e:3b:40:24:86:67:a6:7a:f2:
                    e1:ce:7a:0c:44:53:6d:55:05:6f:84:ee:1d:8a:0d:
                    a3:00:67:a3:39:1b:86:6e:5b:ce:c4:f8:f4:61:12:
                    3c:c0:d1:ba:4b:43:05:56:38:e5:03:7a:98:1a:ec:
                    62:9d:d8:77:fc:7f:ff:f2:cc:db:62:1f:05:99:7c:
                    82:cd:12:f0:75:25:7f:85:e6:30:86:56:6e:7b:a6:
                    bf:db:7b:89:8f:a0:86:84:45:11:e0:fe:cb:e5:2a:
                    53:66:65:08:07:63:66:78:fb:17:6a:16:8c:07:09:
                    69:c5:b7:8e:91:b5:36:4d:35:0c:0c:f7:2f:67:a6:
                    49:29:54:45:51:53:c2:35:80:6d:40:b1:94:62:b4:
                    1b:f9:63:f3:3e:03:73:47:94:af:47:f8:66:fb:b8:
                    3f:89:e1:2d:14:17:3c:ce:ec:e5:99:25:52:1a:29:
                    dd:ab:2b:2e:80:e5:16:60:6d:da:c4:e7:c4:2e:f4:
                    79:e3:7a:ec:b9:71:f2:38:41:47:ec:e6:65:fa:d5:
                    3f:3a:9b:fe:77:43:0a:c4:dc:66:3b:a1:00:e6:f4:
                    26:12:fa:d9:bf:d7:d6:16:98:7f:fa:8a:d8:5b:10:
                    ca:f7:ea:e3:c0:94:79:e6:fb:41:ae:78:cc:d2:84:
                    c5:e1:6c:e1:15:65:6d:67:8c:eb:fa:b9:b0:27:94:
                    7a:0d:10:c9:87:78:be:74:ee:04:80:20:0d:61:00:
                    00:73:31:1c:a8:04:65:14:8c:8a:46:e9:83:9c:97:
                    b6:3b:d9:35:d4:0c:ae:d4:c9:36:39:84:8c:f9:e9:
                    da:96:26:08:cd:82:63:18:3a:62:e9:6a:3d:8b:56:
                    4b:0c:d4:85:41:13:03:dd:f9:de:58:52:39:a3:21:
                    3c:da:e8:e6:f5:8f:66:59:4e:ce:71:74:f0:80:ff:
                    f7:bb:cb:1b:55:f7:cd:c0:c9:93:5a:ef:ec:a9:5f:
                    82:e3:7e:78:9b:57:eb:62:73:da:7a:28:c3:1e:8e:
                    b2:db:15
                Exponent: 65537 (0x10001)
        Attributes:
            a0:00
    Signature Algorithm: sha256WithRSAEncryption
         8f:06:7c:06:6b:c2:95:d7:5e:db:cc:d0:4b:2b:3c:16:5b:96:
         d8:e9:61:2d:9e:35:31:c9:8b:f4:99:f7:7e:a0:71:89:16:d6:
         55:9a:f2:76:f3:6b:de:18:5b:c9:c7:6b:80:59:52:14:57:ec:
         56:23:f9:e6:07:fe:7e:8c:dc:e4:64:fd:4e:8e:dc:39:8a:b2:
         16:f5:2e:fe:46:3a:f8:9a:af:92:69:e2:72:e5:55:b6:84:7c:
         9d:cb:19:8d:08:bf:6e:54:a2:6d:6a:c8:e2:ad:65:0f:16:28:
         09:bb:e0:15:5c:12:3e:a4:b3:c9:98:f3:e3:9c:37:a2:78:18:
         7e:2c:fe:ef:66:81:34:78:78:a4:37:08:40:07:7a:f3:e4:c6:
         d6:fe:98:e7:58:a4:88:73:b5:55:ad:cf:fd:7b:df:76:18:76:
         91:9b:dd:2e:b3:a5:50:03:dc:ab:4c:1f:d0:3e:12:d2:80:fb:
         01:a6:b0:ba:d1:57:28:c9:16:c3:0c:be:f7:47:32:51:84:72:
         96:7b:7d:50:e1:c1:2b:1a:74:24:1c:63:49:a5:e9:ec:98:6d:
         4e:75:8a:db:d8:09:46:4c:d5:a7:25:95:ab:e9:ad:1b:1d:1a:
         5b:2d:3f:54:ed:b1:78:14:78:e1:0b:7c:24:42:ee:43:df:37:
         3e:b3:c8:f1:70:a2:6f:9e:1e:25:86:e8:66:75:a0:6f:b4:8a:
         ee:41:47:de:90:83:dd:f0:63:58:fe:a0:c8:93:62:7f:94:bd:
         fc:e8:aa:54:a4:94:fc:37:40:7f:55:bc:af:6e:a6:b3:9a:91:
         03:00:b8:af:67:3b:34:72:27:77:96:40:5d:8f:29:fe:7a:22:
         c2:cc:e4:0d:37:e6:b3:ca:08:b5:c9:65:85:d4:c3:90:b1:ce:
         23:3b:aa:22:a8:0a:fd:83:cb:b6:10:e5:88:c5:b7:a7:a7:ea:
         74:8b:55:ad:31:f5:82:37:b7:62:3c:91:f5:29:73:7a:13:e1:
         58:e5:0b:c8:9d:03:7b:55:1f:2f:f0:50:8d:6d:9b:1a:99:d2:
         0d:50:d0:a0:21:bb:63:37:4c:82:70:ca:33:61:8a:55:59:62:
         11:62:8e:79:ac:1b:09:07:27:c9:b1:d0:cb:ab:4a:f8:d7:eb:
         e1:2a:22:cd:03:e2:ca:c0:23:7c:cf:f5:40:a0:8a:72:c8:ef:
         10:17:16:d0:7c:1f:24:72:df:b8:08:3a:ec:57:49:ee:ed:b0:
         a6:84:69:b4:c1:8d:95:02:98:3f:c4:61:31:dc:94:bd:74:99:
         bc:0b:be:46:a4:36:df:17:0b:30:c1:2f:f4:04:35:7f:89:78:
         6d:6b:93:ea:da:9b:e7:4d'
[Fri Aug 20 02:37:06 UTC 2021] RSA CSR
[Fri Aug 20 02:37:06 UTC 2021] Using config home:/srv/acmesh/data
[Fri Aug 20 02:37:06 UTC 2021] ACME_DIRECTORY='https://acme.zerossl.com/v2/DV90'
[Fri Aug 20 02:37:06 UTC 2021] _ACME_SERVER_HOST='acme.zerossl.com'
[Fri Aug 20 02:37:06 UTC 2021] _ACME_SERVER_PATH='v2/DV90'
[Fri Aug 20 02:37:06 UTC 2021] DOMAIN_PATH='/srv/acmesh/cert-home/<removed>'
[Fri Aug 20 02:37:06 UTC 2021] Copy csr to: /srv/acmesh/cert-home/<removed>/<removed>.csr
[Fri Aug 20 02:37:06 UTC 2021] _main_domain='<removed>'
[Fri Aug 20 02:37:06 UTC 2021] _alt_domains
[Fri Aug 20 02:37:06 UTC 2021] Using config home:/srv/acmesh/data
[Fri Aug 20 02:37:06 UTC 2021] ACME_DIRECTORY='https://acme.zerossl.com/v2/DV90'
[Fri Aug 20 02:37:06 UTC 2021] _ACME_SERVER_HOST='acme.zerossl.com'
[Fri Aug 20 02:37:06 UTC 2021] _ACME_SERVER_PATH='v2/DV90'
[Fri Aug 20 02:37:06 UTC 2021] 'dns_dynu' does not contain 'dns'
[Fri Aug 20 02:37:06 UTC 2021] Using ACME_DIRECTORY: https://acme.zerossl.com/v2/DV90
[Fri Aug 20 02:37:06 UTC 2021] _init api for server: https://acme.zerossl.com/v2/DV90
[Fri Aug 20 02:37:06 UTC 2021] Retrying GET
[Fri Aug 20 02:37:06 UTC 2021] GET
[Fri Aug 20 02:37:07 UTC 2021] url='https://acme.zerossl.com/v2/DV90'
[Fri Aug 20 02:37:07 UTC 2021] timeout=
[Fri Aug 20 02:37:07 UTC 2021] displayError='1'
[Fri Aug 20 02:37:07 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.G6OOwyTz6Q  -g '
[Fri Aug 20 02:37:07 UTC 2021] ret='0'
[Fri Aug 20 02:37:07 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:07 UTC 2021] response='{
  "newNonce": "https://acme.zerossl.com/v2/DV90/newNonce",
  "newAccount": "https://acme.zerossl.com/v2/DV90/newAccount",
  "newOrder": "https://acme.zerossl.com/v2/DV90/newOrder",
  "revokeCert": "https://acme.zerossl.com/v2/DV90/revokeCert",
  "keyChange": "https://acme.zerossl.com/v2/DV90/keyChange",
  "meta": {
    "termsOfService": "https://secure.trust-provider.com/repository/docs/Legacy/20201020_Certificate_Subscriber_Agreement_v_2_4_click.pdf",
    "website": "https://zerossl.com",
    "caaIdentities": ["sectigo.com", "trust-provider.com", "usertrust.com", "comodoca.com", "comodo.com"],
    "externalAccountRequired": true
  }
}'
[Fri Aug 20 02:37:07 UTC 2021] ACME_KEY_CHANGE='https://acme.zerossl.com/v2/DV90/keyChange'
[Fri Aug 20 02:37:07 UTC 2021] ACME_NEW_AUTHZ
[Fri Aug 20 02:37:07 UTC 2021] ACME_NEW_ORDER='https://acme.zerossl.com/v2/DV90/newOrder'
[Fri Aug 20 02:37:07 UTC 2021] ACME_NEW_ACCOUNT='https://acme.zerossl.com/v2/DV90/newAccount'
[Fri Aug 20 02:37:07 UTC 2021] ACME_REVOKE_CERT='https://acme.zerossl.com/v2/DV90/revokeCert'
[Fri Aug 20 02:37:07 UTC 2021] ACME_AGREEMENT='https://secure.trust-provider.com/repository/docs/Legacy/20201020_Certificate_Subscriber_Agreement_v_2_4_click.pdf'
[Fri Aug 20 02:37:07 UTC 2021] ACME_NEW_NONCE='https://acme.zerossl.com/v2/DV90/newNonce'
[Fri Aug 20 02:37:07 UTC 2021] Le_NextRenewTime
[Fri Aug 20 02:37:07 UTC 2021] Using CA: https://acme.zerossl.com/v2/DV90
[Fri Aug 20 02:37:07 UTC 2021] _on_before_issue
[Fri Aug 20 02:37:07 UTC 2021] _chk_main_domain='<removed>'
[Fri Aug 20 02:37:07 UTC 2021] _chk_alt_domains
[Fri Aug 20 02:37:07 UTC 2021] 'dns_dynu' does not contain 'no'
[Fri Aug 20 02:37:07 UTC 2021] Le_LocalAddress
[Fri Aug 20 02:37:07 UTC 2021] d='<removed>'
[Fri Aug 20 02:37:07 UTC 2021] Check for domain='<removed>'
[Fri Aug 20 02:37:08 UTC 2021] _currentRoot='dns_dynu'
[Fri Aug 20 02:37:08 UTC 2021] d
[Fri Aug 20 02:37:08 UTC 2021] 'dns_dynu' does not contain 'apache'
[Fri Aug 20 02:37:08 UTC 2021] _saved_account_key_hash='CLeRODaSy3DMoOfx4qWOG3YCmR6GezhSiA7mBjdhuKA='
[Fri Aug 20 02:37:08 UTC 2021] _saved_account_key_hash is not changed, skip register account.
[Fri Aug 20 02:37:08 UTC 2021] Signing from existing CSR.
[Fri Aug 20 02:37:08 UTC 2021] Getting domain auth token for each domain
[Fri Aug 20 02:37:08 UTC 2021] _is_idn_d='<removed>'
[Fri Aug 20 02:37:08 UTC 2021] _idn_temp
[Fri Aug 20 02:37:08 UTC 2021] d
[Fri Aug 20 02:37:08 UTC 2021] _identifiers='{"type":"dns","value":"<removed>"}'
[Fri Aug 20 02:37:08 UTC 2021] url='https://acme.zerossl.com/v2/DV90/newOrder'
[Fri Aug 20 02:37:08 UTC 2021] payload='{"identifiers": [{"type":"dns","value":"<removed>"}]}'
[Fri Aug 20 02:37:08 UTC 2021] RSA key
[Fri Aug 20 02:37:08 UTC 2021] _URGLY_PRINTF
[Fri Aug 20 02:37:08 UTC 2021] xargs
[Fri Aug 20 02:37:08 UTC 2021] _URGLY_PRINTF
[Fri Aug 20 02:37:08 UTC 2021] xargs
[Fri Aug 20 02:37:08 UTC 2021] Get nonce with HEAD. ACME_NEW_NONCE='https://acme.zerossl.com/v2/DV90/newNonce'
[Fri Aug 20 02:37:08 UTC 2021] Retrying post
[Fri Aug 20 02:37:08 UTC 2021] HEAD
[Fri Aug 20 02:37:08 UTC 2021] _post_url='https://acme.zerossl.com/v2/DV90/newNonce'
[Fri Aug 20 02:37:08 UTC 2021] body
[Fri Aug 20 02:37:08 UTC 2021] _postContentType='application/jose+json'
[Fri Aug 20 02:37:08 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g  -I  '
[Fri Aug 20 02:37:08 UTC 2021] _ret='0'
[Fri Aug 20 02:37:08 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:09 UTC 2021] _headers='HTTP/2 200
server: nginx
date: Fri, 20 Aug 2021 02:37:08 GMT
content-type: application/octet-stream
replay-nonce: 3VExCa2k1NX1uNy3Msb41I4zYMNphJt94KFMda8nKXE
cache-control: max-age=-1
access-control-allow-origin: *
link: <https://acme.zerossl.com/v2/DV90>;rel="index"
strict-transport-security: max-age=15552000
'
[Fri Aug 20 02:37:09 UTC 2021] _CACHED_NONCE='3VExCa2k1NX1uNy3Msb41I4zYMNphJt94KFMda8nKXE'
[Fri Aug 20 02:37:09 UTC 2021] nonce='3VExCa2k1NX1uNy3Msb41I4zYMNphJt94KFMda8nKXE'
[Fri Aug 20 02:37:09 UTC 2021] Retrying post
[Fri Aug 20 02:37:09 UTC 2021] POST
[Fri Aug 20 02:37:09 UTC 2021] _post_url='https://acme.zerossl.com/v2/DV90/newOrder'
[Fri Aug 20 02:37:09 UTC 2021] body='{"protected": "eyJub25jZSI6ICIzVkV4Q2EyazFOWDF1TnkzTXNiNDFJNHpZTU5waEp0OTRLRk1kYThuS1hFIiwgInVybCI6ICJodHRwczovL2FjbWUuemVyb3NzbC5jb20vdjIvRFY5MC9uZXdPcmRlciIsICJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS56ZXJvc3NsLmNvbS92Mi9EVjkwL2FjY291bnQvQm9WMHBoU1JSUEg5TC1HRmtEN3hoZyJ9", "payload": "eyJpZGVudGlmaWVycyI6IFt7InR5cGUiOiJkbnMiLCJ2YWx1ZSI6InRhdXR1bGxpLm90dC5kaWdpbWFjaC5jb20ifV19", "signature": "f2Ds-fiDS9HO7m15L3Mj4JslMzjqbFbLWy6Lh62tA4RMtwF8qNxm0exK4FeQowDRKOx-FWdsYwh1iW5qJi44jEtiTweQHWgvmE1i0UmV6aVARkSKfMwWXMF_TpRazNgEI3w0oK7eL7fafAyJMj44U42aXoel6gy_KmYR130A0Uq6lnyNlyE9VFBKMon09pI1iSAeCxzM_uN26GTcUAfexjZy3aPZVXDKb2fKpYa8r6OMQh71IZfXyxMocVGctceQChj88hJrXZOEJLX6lWZEzNYxUgpaR89_X6DMEphsDcRR85wN6vqi37tGFfidkveh8ipvwMjkLjp0WtLZVu3oBg"}'
[Fri Aug 20 02:37:09 UTC 2021] _postContentType='application/jose+json'
[Fri Aug 20 02:37:09 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:09 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:09 UTC 2021] _ret='0'
[Fri Aug 20 02:37:09 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:09 UTC 2021] responseHeaders='HTTP/2 201
server: nginx
date: Fri, 20 Aug 2021 02:37:09 GMT
content-type: application/json
content-length: 287
status:
replay-nonce: 1-SlJwUvZe3qvgbSdc3EvY2Hyzy6C5Y-XY0YAoXC3wA
cache-control: max-age=0, no-cache, no-store
access-control-allow-origin: *
location: https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg
cache-control: max-age=-1
strict-transport-security: max-age=15552000
'
[Fri Aug 20 02:37:09 UTC 2021] code='201'
[Fri Aug 20 02:37:09 UTC 2021] original='{"status":"pending","expires":"2021-11-18T02:37:09Z","identifiers":[{"type":"dns","value":"<removed>"}],"authorizations":["https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g"],"finalize":"https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg/finalize"}'
[Fri Aug 20 02:37:09 UTC 2021] response='{"status":"pending","expires":"2021-11-18T02:37:09Z","identifiers":[{"type":"dns","value":"<removed>"}],"authorizations":["https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g"],"finalize":"https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg/finalize"}'
[Fri Aug 20 02:37:09 UTC 2021] Le_LinkOrder='https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg'
[Fri Aug 20 02:37:09 UTC 2021] Le_OrderFinalize='https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg/finalize'
[Fri Aug 20 02:37:09 UTC 2021] _authorizations_seg='https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g'
[Fri Aug 20 02:37:09 UTC 2021] _authz_url='https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g'
[Fri Aug 20 02:37:09 UTC 2021] url='https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g'
[Fri Aug 20 02:37:09 UTC 2021] payload
[Fri Aug 20 02:37:09 UTC 2021] Use cached jwk for file: /srv/acmesh/data/ca/acme.zerossl.com/v2/DV90/account.key
[Fri Aug 20 02:37:09 UTC 2021] Use _CACHED_NONCE='1-SlJwUvZe3qvgbSdc3EvY2Hyzy6C5Y-XY0YAoXC3wA'
[Fri Aug 20 02:37:09 UTC 2021] nonce='1-SlJwUvZe3qvgbSdc3EvY2Hyzy6C5Y-XY0YAoXC3wA'
[Fri Aug 20 02:37:09 UTC 2021] Retrying post
[Fri Aug 20 02:37:09 UTC 2021] POST
[Fri Aug 20 02:37:09 UTC 2021] _post_url='https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g'
[Fri Aug 20 02:37:09 UTC 2021] body='{"protected": "eyJub25jZSI6ICIxLVNsSndVdlplM3F2Z2JTZGMzRXZZMkh5enk2QzVZLVhZMFlBb1hDM3dBIiwgInVybCI6ICJodHRwczovL2FjbWUuemVyb3NzbC5jb20vdjIvRFY5MC9hdXRoei83STNqTWMxUGNkOGZjMXJtQy0wYjRnIiwgImFsZyI6ICJSUzI1NiIsICJraWQiOiAiaHR0cHM6Ly9hY21lLnplcm9zc2wuY29tL3YyL0RWOTAvYWNjb3VudC9Cb1YwcGhTUlJQSDlMLUdGa0Q3eGhnIn0", "payload": "", "signature": "wNgQ5BJX_3OR26rwauNCGnguzqui_ftdxUjqst8DSvxonedLWNxsco6I9CsD38oUAwnH_B_7ySmTiIieda1B6tUZhqJDj8ayN8ovNK1qZxrIKHOiMrCCafxFYb4QJTSKk1NGD2AX1AaT-LEVaQEYrqkqHuReizHxFDB15oqQWJBHS62jHCSw2Bny6jSXrsyjgcUD_uPgg_K24_FanvpitglX7DFvbheam2KooiJvsp-RkipZyHL08eijGN7-fYlZwXXdiWK7p5MT1ikCYBh6mW3edzEpT0wKqiZ3H8EchUdsIEoJWGR6iJNDTk1-zmXPg1O7i1vgrL-s65qAonFiXw"}'
[Fri Aug 20 02:37:09 UTC 2021] _postContentType='application/jose+json'
[Fri Aug 20 02:37:09 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:09 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:10 UTC 2021] _ret='0'
[Fri Aug 20 02:37:10 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:10 UTC 2021] responseHeaders='HTTP/2 200
server: nginx
date: Fri, 20 Aug 2021 02:37:10 GMT
content-type: application/json
content-length: 455
replay-nonce: 049qLEobT4fdMy_mQ9ChwqYVHFZHsKzy76vhDVUhTSQ
cache-control: max-age=-1
access-control-allow-origin: *
link: <https://acme.zerossl.com/v2/DV90>;rel="index"
retry-after: 5
strict-transport-security: max-age=15552000
'
[Fri Aug 20 02:37:10 UTC 2021] code='200'
[Fri Aug 20 02:37:10 UTC 2021] original='{"identifier":{"type":"dns","value":"<removed>"},"status":"pending","expires":"2021-09-19T02:37:09Z","challenges":[{"type":"http-01","url":"https://acme.zerossl.com/v2/DV90/chall/xiIH9Fd9kdiyw4M0sq9WVg","status":"pending","token":"p8hwSow_oMVy55_SXzFAjsv7PYSvGjrqH9JK8hD5sUY"},{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}]}'
[Fri Aug 20 02:37:10 UTC 2021] response='{"identifier":{"type":"dns","value":"<removed>"},"status":"pending","expires":"2021-09-19T02:37:09Z","challenges":[{"type":"http-01","url":"https://acme.zerossl.com/v2/DV90/chall/xiIH9Fd9kdiyw4M0sq9WVg","status":"pending","token":"p8hwSow_oMVy55_SXzFAjsv7PYSvGjrqH9JK8hD5sUY"},{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}]}'
[Fri Aug 20 02:37:10 UTC 2021] response='{"identifier":{"type":"dns","value":"<removed>"},"status":"pending","expires":"2021-09-19T02:37:09Z","challenges":[{"type":"http-01","url":"https://acme.zerossl.com/v2/DV90/chall/xiIH9Fd9kdiyw4M0sq9WVg","status":"pending","token":"p8hwSow_oMVy55_SXzFAjsv7PYSvGjrqH9JK8hD5sUY"},{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}]}'
[Fri Aug 20 02:37:10 UTC 2021] _d='<removed>'
[Fri Aug 20 02:37:10 UTC 2021] _authorizations_map='<removed>,{"identifier":{"type":"dns","value":"<removed>"},"status":"pending","expires":"2021-09-19T02:37:09Z","challenges":[{"type":"http-01","url":"https://acme.zerossl.com/v2/DV90/chall/xiIH9Fd9kdiyw4M0sq9WVg","status":"pending","token":"p8hwSow_oMVy55_SXzFAjsv7PYSvGjrqH9JK8hD5sUY"},{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}]}
'
[Fri Aug 20 02:37:10 UTC 2021] d='<removed>'
[Fri Aug 20 02:37:10 UTC 2021] Getting webroot for domain='<removed>'
[Fri Aug 20 02:37:10 UTC 2021] _w='dns_dynu'
[Fri Aug 20 02:37:10 UTC 2021] _currentRoot='dns_dynu'
[Fri Aug 20 02:37:10 UTC 2021] _is_idn_d='<removed>'
[Fri Aug 20 02:37:10 UTC 2021] _idn_temp
[Fri Aug 20 02:37:10 UTC 2021] _candidates='<removed>,{"identifier":{"type":"dns","value":"<removed>"},"status":"pending","expires":"2021-09-19T02:37:09Z","challenges":[{"type":"http-01","url":"https://acme.zerossl.com/v2/DV90/chall/xiIH9Fd9kdiyw4M0sq9WVg","status":"pending","token":"p8hwSow_oMVy55_SXzFAjsv7PYSvGjrqH9JK8hD5sUY"},{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}]}'
[Fri Aug 20 02:37:10 UTC 2021] response='{"identifier":{"type":"dns","value":"<removed>"},"status":"pending","expires":"2021-09-19T02:37:09Z","challenges":[{"type":"http-01","url":"https://acme.zerossl.com/v2/DV90/chall/xiIH9Fd9kdiyw4M0sq9WVg","status":"pending","token":"p8hwSow_oMVy55_SXzFAjsv7PYSvGjrqH9JK8hD5sUY"},{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}]}'
[Fri Aug 20 02:37:10 UTC 2021] entry='"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"pending","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"'
[Fri Aug 20 02:37:10 UTC 2021] token='yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo'
[Fri Aug 20 02:37:10 UTC 2021] uri='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:10 UTC 2021] keyauthorization='yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo.dlxNsPuticWdGsjtbH64zYGnw1YyOyeFEp-lwMi849I'
[Fri Aug 20 02:37:10 UTC 2021] dvlist='<removed>#yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo.dlxNsPuticWdGsjtbH64zYGnw1YyOyeFEp-lwMi849I#https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g#dns-01#dns_dynu'
[Fri Aug 20 02:37:10 UTC 2021] d
[Fri Aug 20 02:37:10 UTC 2021] vlist='<removed>#yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo.dlxNsPuticWdGsjtbH64zYGnw1YyOyeFEp-lwMi849I#https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g#dns-01#dns_dynu,'
[Fri Aug 20 02:37:10 UTC 2021] d='<removed>'
[Fri Aug 20 02:37:10 UTC 2021] _d_alias='ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:10 UTC 2021] txtdomain='_acme-challenge.ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:10 UTC 2021] txt='faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA'
[Fri Aug 20 02:37:10 UTC 2021] d_api='/usr/lib/acmesh/dnsapi/dns_dynu.sh'
[Fri Aug 20 02:37:10 UTC 2021] dns_entry='<removed>,_acme-challenge.<removed>,_acme-challenge.ott01.certmanager.<removed>.com,dns_dynu,faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA,/usr/lib/acmesh/dnsapi/dns_dynu.sh'
[Fri Aug 20 02:37:10 UTC 2021] Found domain api file: /usr/lib/acmesh/dnsapi/dns_dynu.sh
[Fri Aug 20 02:37:10 UTC 2021] Adding txt value: faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA for domain:  _acme-challenge.ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:11 UTC 2021] Getting Dynu token.
[Fri Aug 20 02:37:11 UTC 2021] Retrying GET
[Fri Aug 20 02:37:11 UTC 2021] GET
[Fri Aug 20 02:37:11 UTC 2021] url='https://api.dynu.com/v2/oauth2/token'
[Fri Aug 20 02:37:11 UTC 2021] timeout=
[Fri Aug 20 02:37:11 UTC 2021] displayError='1'
[Fri Aug 20 02:37:11 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:11 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:11 UTC 2021] ret='0'
[Fri Aug 20 02:37:11 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:11 UTC 2021] response='{"access_token":"VQBpAHgAOABZAFEAQQAxAEEARABrAEEATQBRAEEAegBBAEQARQBBAE4AQQBBADUAQQBDADAAQQBZAFEAQQB6AEEARABrAEEAWgBBAEEAdABBAEQAUQBBAFoAZwBBADMAQQBEAGMAQQBMAFEAQQA1AEEARABVAEEATgBnAEEAMABBAEMAMABBAE0AQQBCAGkAQQBHAFkAQQBNAFEAQQAwAEEARABnAEEAWgBRAEIAaABBAEQATQBBAFoAZwBCAGwAQQBHAFUAQQBPAHcAQQAxAEEARgBnAEEAVgBnAEIAagBBAEcAWQBBAE4AUQBCAGoAQQBHAFkAQQBWAGcAQgBVAEEARgBrAEEATgBnAEIAYQBBAEcAUQBBAFcAZwBCAGsAQQBEAFUAQQBNAHcAQgBZAEEARwBjAEEATgBRAEIAWgBBAEcAVQBBAFkAZwBCAFkAQQBEAEkAQQBaAEEAQgBZAEEARABZAEEAVwBBAEEANwBBAEQAZwBBAEwAdwBBAHkAQQBEAEEAQQBMAHcAQQB5AEEARABFAEEASQBBAEEAeABBAEQAQQBBAE8AZwBBAHoAQQBEAGMAQQBPAGcAQQB4AEEARABFAEEASQBBAEIAQgBBAEUAMABBAE8AdwBCAFYAQQBIAE0AQQBaAFEAQgB5AEEAQQB8AHwA","token_type":"bearer","expires_in":28800,"roles":[]}'
[Fri Aug 20 02:37:11 UTC 2021] Detect root zone
[Fri Aug 20 02:37:11 UTC 2021] h='ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:11 UTC 2021] dns/getroot/ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:11 UTC 2021] Getting https://api.dynu.com/v2/dns/getroot/ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:11 UTC 2021] Retrying GET
[Fri Aug 20 02:37:11 UTC 2021] GET
[Fri Aug 20 02:37:11 UTC 2021] url='https://api.dynu.com/v2/dns/getroot/ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:11 UTC 2021] timeout=
[Fri Aug 20 02:37:11 UTC 2021] displayError='1'
[Fri Aug 20 02:37:11 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:11 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:12 UTC 2021] ret='0'
[Fri Aug 20 02:37:12 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:12 UTC 2021] response='{"statusCode":200,"id":100144612,"domainName":"certmanager.<removed>.com","hostname":"ott01.certmanager.<removed>.com","node":"ott01"}'
[Fri Aug 20 02:37:12 UTC 2021] h='certmanager.<removed>.com'
[Fri Aug 20 02:37:12 UTC 2021] dns/getroot/certmanager.<removed>.com
[Fri Aug 20 02:37:12 UTC 2021] Getting https://api.dynu.com/v2/dns/getroot/certmanager.<removed>.com
[Fri Aug 20 02:37:12 UTC 2021] Retrying GET
[Fri Aug 20 02:37:12 UTC 2021] GET
[Fri Aug 20 02:37:12 UTC 2021] url='https://api.dynu.com/v2/dns/getroot/certmanager.<removed>.com'
[Fri Aug 20 02:37:12 UTC 2021] timeout=
[Fri Aug 20 02:37:12 UTC 2021] displayError='1'
[Fri Aug 20 02:37:12 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:12 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:13 UTC 2021] ret='0'
[Fri Aug 20 02:37:13 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:13 UTC 2021] response='{"statusCode":200,"id":100144612,"domainName":"certmanager.<removed>.com","hostname":"certmanager.<removed>.com","node":""}'
[Fri Aug 20 02:37:13 UTC 2021] _node='_acme-challenge.ott01'
[Fri Aug 20 02:37:13 UTC 2021] _domain_name='certmanager.<removed>.com'
[Fri Aug 20 02:37:13 UTC 2021] Creating TXT record.
[Fri Aug 20 02:37:13 UTC 2021] dns/100144612/record
[Fri Aug 20 02:37:13 UTC 2021] data='{"domainId":"100144612","nodeName":"_acme-challenge.ott01","recordType":"TXT","textData":"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA","state":true,"ttl":90}'
[Fri Aug 20 02:37:13 UTC 2021] Retrying post
[Fri Aug 20 02:37:13 UTC 2021] POST
[Fri Aug 20 02:37:13 UTC 2021] _post_url='https://api.dynu.com/v2/dns/100144612/record'
[Fri Aug 20 02:37:13 UTC 2021] body='{"domainId":"100144612","nodeName":"_acme-challenge.ott01","recordType":"TXT","textData":"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA","state":true,"ttl":90}'
[Fri Aug 20 02:37:13 UTC 2021] _postContentType
[Fri Aug 20 02:37:13 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:13 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:14 UTC 2021] _ret='0'
[Fri Aug 20 02:37:14 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:14 UTC 2021] response='{"statusCode":200,"id":7758608,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"_acme-challenge.ott01","hostname":"_acme-challenge.ott01.certmanager.<removed>.com","recordType":"TXT","ttl":90,"state":true,"content":"_acme-challenge.ott01.certmanager.<removed>.com. 90 IN TXT \"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA\"","updatedOn":"2021-08-20T02:37:13.947","textData":"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA"}'
[Fri Aug 20 02:37:14 UTC 2021] The txt record is added: Success.
[Fri Aug 20 02:37:14 UTC 2021] <removed>,_acme-challenge.<removed>,_acme-challenge.ott01.certmanager.<removed>.com,dns_dynu,faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA,/usr/lib/acmesh/dnsapi/dns_dynu.sh

[Fri Aug 20 02:37:14 UTC 2021] Let's check each DNS record now. Sleep 20 seconds first.
[Fri Aug 20 02:37:35 UTC 2021] You can use '--dnssleep' to disable public dns checks.
[Fri Aug 20 02:37:35 UTC 2021] See: https://github.com/acmesh-official/acme.sh/wiki/dnscheck
[Fri Aug 20 02:37:35 UTC 2021] _is_idn_d='_acme-challenge.<removed>'
[Fri Aug 20 02:37:35 UTC 2021] _idn_temp
[Fri Aug 20 02:37:35 UTC 2021] _is_idn_d='_acme-challenge.ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:35 UTC 2021] _idn_temp
[Fri Aug 20 02:37:35 UTC 2021] d='<removed>'
[Fri Aug 20 02:37:35 UTC 2021] txtdomain='_acme-challenge.<removed>'
[Fri Aug 20 02:37:35 UTC 2021] aliasDomain='_acme-challenge.ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:35 UTC 2021] txt='faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA'
[Fri Aug 20 02:37:35 UTC 2021] d_api='/usr/lib/acmesh/dnsapi/dns_dynu.sh'
[Fri Aug 20 02:37:35 UTC 2021] Checking <removed> for _acme-challenge.ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:35 UTC 2021] _c_txtdomain='_acme-challenge.<removed>'
[Fri Aug 20 02:37:35 UTC 2021] _c_aliasdomain='_acme-challenge.ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:35 UTC 2021] _c_txt='faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA'
[Fri Aug 20 02:37:35 UTC 2021] Detect dns server first.
[Fri Aug 20 02:37:35 UTC 2021] Use cloudflare doh server
[Fri Aug 20 02:37:35 UTC 2021] _ns_ep='https://cloudflare-dns.com/dns-query'
[Fri Aug 20 02:37:35 UTC 2021] _ns_domain='_acme-challenge.ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:35 UTC 2021] _ns_type='TXT'
[Fri Aug 20 02:37:35 UTC 2021] Retrying GET
[Fri Aug 20 02:37:36 UTC 2021] GET
[Fri Aug 20 02:37:36 UTC 2021] url='https://cloudflare-dns.com/dns-query?name=_acme-challenge.ott01.certmanager.<removed>.com&type=TXT'
[Fri Aug 20 02:37:36 UTC 2021] timeout=
[Fri Aug 20 02:37:36 UTC 2021] displayError='1'
[Fri Aug 20 02:37:36 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:36 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:36 UTC 2021] ret='0'
[Fri Aug 20 02:37:36 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:36 UTC 2021] response='{"Status":0,"TC":false,"RD":true,"RA":true,"AD":false,"CD":false,"Question":[{"name":"_acme-challenge.ott01.certmanager.<removed>.com","type":16}],"Answer":[{"name":"_acme-challenge.ott01.certmanager.<removed>.com","type":16,"TTL":90,"data":"\"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA\""}]}'
[Fri Aug 20 02:37:36 UTC 2021] _answers='"Answer":[
"name":"_acme-challenge.ott01.certmanager.<removed>.com","type":16,"TTL":90,"data":"\"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA\""
]'
[Fri Aug 20 02:37:36 UTC 2021] Domain <removed> '_acme-challenge.ott01.certmanager.<removed>.com' success.
[Fri Aug 20 02:37:36 UTC 2021] All success, let's return
[Fri Aug 20 02:37:36 UTC 2021] ok, let's start to verify
[Fri Aug 20 02:37:36 UTC 2021] Verifying: <removed>
[Fri Aug 20 02:37:36 UTC 2021] d='<removed>'
[Fri Aug 20 02:37:36 UTC 2021] keyauthorization='yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo.dlxNsPuticWdGsjtbH64zYGnw1YyOyeFEp-lwMi849I'
[Fri Aug 20 02:37:36 UTC 2021] uri='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:36 UTC 2021] _currentRoot='dns_dynu'
[Fri Aug 20 02:37:36 UTC 2021] Trigger domain validation.
[Fri Aug 20 02:37:36 UTC 2021] _t_url='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:36 UTC 2021] _t_key_authz='yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo.dlxNsPuticWdGsjtbH64zYGnw1YyOyeFEp-lwMi849I'
[Fri Aug 20 02:37:36 UTC 2021] _t_vtype='dns-01'
[Fri Aug 20 02:37:36 UTC 2021] url='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:36 UTC 2021] payload='{}'
[Fri Aug 20 02:37:36 UTC 2021] Use cached jwk for file: /srv/acmesh/data/ca/acme.zerossl.com/v2/DV90/account.key
[Fri Aug 20 02:37:36 UTC 2021] Use _CACHED_NONCE='049qLEobT4fdMy_mQ9ChwqYVHFZHsKzy76vhDVUhTSQ'
[Fri Aug 20 02:37:36 UTC 2021] nonce='049qLEobT4fdMy_mQ9ChwqYVHFZHsKzy76vhDVUhTSQ'
[Fri Aug 20 02:37:36 UTC 2021] Retrying post
[Fri Aug 20 02:37:36 UTC 2021] POST
[Fri Aug 20 02:37:36 UTC 2021] _post_url='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:36 UTC 2021] body='{"protected": "eyJub25jZSI6ICIwNDlxTEVvYlQ0ZmRNeV9tUTlDaHdxWVZIRlpIc0t6eTc2dmhEVlVoVFNRIiwgInVybCI6ICJodHRwczovL2FjbWUuemVyb3NzbC5jb20vdjIvRFY5MC9jaGFsbC9OQ3VlVFJIaEZxRFFueGVrSFNXUDRnIiwgImFsZyI6ICJSUzI1NiIsICJraWQiOiAiaHR0cHM6Ly9hY21lLnplcm9zc2wuY29tL3YyL0RWOTAvYWNjb3VudC9Cb1YwcGhTUlJQSDlMLUdGa0Q3eGhnIn0", "payload": "e30", "signature": "XV02IKsAHmT4nwiDwIxM9YQPGWnFOfX8RrQGkoaqA3WZYDK5luSpYEykdmLptEoSMeQZ6gbMgG2QscomWGofuIK47Gp2pcnJnIvTHfTeEcxU8Mpsb4W8k4J9X1CFcZN0qqGosdzMJAvDlRHD7HJgcTN774w8RFFmadrHwRf7IRHv8J_uT0bkvduPiE5Iva0gAS_BtCN3c3BAsbaYDz957tlqEOCI_AuahWCliJLdtbPiB07HwcjZE5mgIxyGJnx03EquAChJAPVPiPQSoT6SX9dLJTty7gIdxamScH0RlbYD9XqPajvFZABASVbKOHT1F2ejM9IiRruA9sQob55-vg"}'
[Fri Aug 20 02:37:36 UTC 2021] _postContentType='application/jose+json'
[Fri Aug 20 02:37:37 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:37 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:37 UTC 2021] _ret='0'
[Fri Aug 20 02:37:37 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:37 UTC 2021] responseHeaders='HTTP/2 200
server: nginx
date: Fri, 20 Aug 2021 02:37:37 GMT
content-type: application/json
content-length: 163
replay-nonce: AghqXHy9k75piyFaEZraBw2fUjf5nyPCh_Y2NE8hcn4
cache-control: max-age=-1
access-control-allow-origin: *
link: <https://acme.zerossl.com/v2/DV90>;rel="index"
link: <https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g>;rel="up"
retry-after: 10
strict-transport-security: max-age=15552000
'
[Fri Aug 20 02:37:37 UTC 2021] code='200'
[Fri Aug 20 02:37:37 UTC 2021] original='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"processing","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:37 UTC 2021] response='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"processing","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:37 UTC 2021] trigger validation code: 200
[Fri Aug 20 02:37:37 UTC 2021] original='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"processing","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:37 UTC 2021] response='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"processing","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:37 UTC 2021] status='processing'
[Fri Aug 20 02:37:37 UTC 2021] Processing, The CA is processing your order, please just wait. (1/30)
[Fri Aug 20 02:37:37 UTC 2021] sleep 2 secs to verify again
[Fri Aug 20 02:37:39 UTC 2021] checking
[Fri Aug 20 02:37:39 UTC 2021] url='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:39 UTC 2021] payload
[Fri Aug 20 02:37:39 UTC 2021] Use cached jwk for file: /srv/acmesh/data/ca/acme.zerossl.com/v2/DV90/account.key
[Fri Aug 20 02:37:39 UTC 2021] Use _CACHED_NONCE='AghqXHy9k75piyFaEZraBw2fUjf5nyPCh_Y2NE8hcn4'
[Fri Aug 20 02:37:39 UTC 2021] nonce='AghqXHy9k75piyFaEZraBw2fUjf5nyPCh_Y2NE8hcn4'
[Fri Aug 20 02:37:39 UTC 2021] Retrying post
[Fri Aug 20 02:37:39 UTC 2021] POST
[Fri Aug 20 02:37:39 UTC 2021] _post_url='https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g'
[Fri Aug 20 02:37:39 UTC 2021] body='{"protected": "eyJub25jZSI6ICJBZ2hxWEh5OWs3NXBpeUZhRVpyYUJ3MmZVamY1bnlQQ2hfWTJORThoY240IiwgInVybCI6ICJodHRwczovL2FjbWUuemVyb3NzbC5jb20vdjIvRFY5MC9jaGFsbC9OQ3VlVFJIaEZxRFFueGVrSFNXUDRnIiwgImFsZyI6ICJSUzI1NiIsICJraWQiOiAiaHR0cHM6Ly9hY21lLnplcm9zc2wuY29tL3YyL0RWOTAvYWNjb3VudC9Cb1YwcGhTUlJQSDlMLUdGa0Q3eGhnIn0", "payload": "", "signature": "xD3fxHZX3fccijmQtvxD3j99A-hzaNsd-hP823Z22T9bV0-MiAWufxv8MqzBTNDkV-bez3rjXf0DCMpIgGmnAZTRI4Kp5nQvaxrtk7cjVmqpZx9p641sioLBwkLmahiVk2S-_R1-yKniTspjYRJIJ1_TEUdaMI2rIa3yzhSEasoBbzHVQ-jkGyd8SzoJ0_1CxkSnTAxTfJBInC-s4G8GqERJu8c4HZQJ1I8dmTnKCi4IRCR3d5Qhkr_BqCrttQ5kYWo4L1ZdeENx2uPiMfFkotnysC6hS-CBXUch-fDlmer3FXrxHTRz8G77lyP6b7_nvlueebF3iUkPA7hkQP2IPg"}'
[Fri Aug 20 02:37:39 UTC 2021] _postContentType='application/jose+json'
[Fri Aug 20 02:37:39 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:39 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:39 UTC 2021] _ret='0'
[Fri Aug 20 02:37:39 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:39 UTC 2021] responseHeaders='HTTP/2 200
server: nginx
date: Fri, 20 Aug 2021 02:37:39 GMT
content-type: application/json
content-length: 193
replay-nonce: LVn-LsRq7fjuczbeknyNvAu-DV7udq_2URLv8xWWEyY
cache-control: max-age=-1
access-control-allow-origin: *
link: <https://acme.zerossl.com/v2/DV90>;rel="index"
link: <https://acme.zerossl.com/v2/DV90/authz/7I3jMc1Pcd8fc1rmC-0b4g>;rel="up"
retry-after: 10
strict-transport-security: max-age=15552000
'
[Fri Aug 20 02:37:39 UTC 2021] code='200'
[Fri Aug 20 02:37:39 UTC 2021] original='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"valid","validated":"2021-08-20T02:37:37Z","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:39 UTC 2021] response='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"valid","validated":"2021-08-20T02:37:37Z","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:39 UTC 2021] original='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"valid","validated":"2021-08-20T02:37:37Z","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:39 UTC 2021] response='{"type":"dns-01","url":"https://acme.zerossl.com/v2/DV90/chall/NCueTRHhFqDQnxekHSWP4g","status":"valid","validated":"2021-08-20T02:37:37Z","token":"yGe708qRv9uLwdJCwgkznTz-8V9onupix775xkoEQJo"}'
[Fri Aug 20 02:37:40 UTC 2021] status='valid'
[Fri Aug 20 02:37:40 UTC 2021] Success
[Fri Aug 20 02:37:40 UTC 2021] pid
[Fri Aug 20 02:37:40 UTC 2021] Skip for removelevel:
[Fri Aug 20 02:37:40 UTC 2021] pid
[Fri Aug 20 02:37:40 UTC 2021] No need to restore nginx, skip.
[Fri Aug 20 02:37:40 UTC 2021] _clearupdns
[Fri Aug 20 02:37:40 UTC 2021] dns_entries='<removed>,_acme-challenge.<removed>,_acme-challenge.ott01.certmanager.<removed>.com,dns_dynu,faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA,/usr/lib/acmesh/dnsapi/dns_dynu.sh
'
[Fri Aug 20 02:37:40 UTC 2021] Removing DNS records.
[Fri Aug 20 02:37:40 UTC 2021] d='<removed>'
[Fri Aug 20 02:37:40 UTC 2021] txtdomain='_acme-challenge.<removed>'
[Fri Aug 20 02:37:40 UTC 2021] aliasDomain='_acme-challenge.ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:40 UTC 2021] _currentRoot='dns_dynu'
[Fri Aug 20 02:37:40 UTC 2021] txt='faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA'
[Fri Aug 20 02:37:40 UTC 2021] d_api='/usr/lib/acmesh/dnsapi/dns_dynu.sh'
[Fri Aug 20 02:37:40 UTC 2021] Removing txt: faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA for domain: _acme-challenge.ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:40 UTC 2021] Getting Dynu token.
[Fri Aug 20 02:37:40 UTC 2021] Retrying GET
[Fri Aug 20 02:37:40 UTC 2021] GET
[Fri Aug 20 02:37:40 UTC 2021] url='https://api.dynu.com/v2/oauth2/token'
[Fri Aug 20 02:37:40 UTC 2021] timeout=
[Fri Aug 20 02:37:40 UTC 2021] displayError='1'
[Fri Aug 20 02:37:40 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:40 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:46 UTC 2021] ret='0'
[Fri Aug 20 02:37:46 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:46 UTC 2021] response='{"access_token":"VQBpAHgAOABZAFEAQQAxAEEARABrAEEATQBRAEEAegBBAEQARQBBAE4AQQBBADUAQQBDADAAQQBZAFEAQQB6AEEARABrAEEAWgBBAEEAdABBAEQAUQBBAFoAZwBBADMAQQBEAGMAQQBMAFEAQQA1AEEARABVAEEATgBnAEEAMABBAEMAMABBAE0AQQBCAGkAQQBHAFkAQQBNAFEAQQAwAEEARABnAEEAWgBRAEIAaABBAEQATQBBAFoAZwBCAGwAQQBHAFUAQQBPAHcAQQAxAEEARgBnAEEAVgBnAEIAagBBAEcAWQBBAE4AUQBCAGoAQQBHAFkAQQBWAGcAQgBVAEEARgBrAEEATgBnAEIAYQBBAEcAUQBBAFcAZwBCAGsAQQBEAFUAQQBNAHcAQgBZAEEARwBjAEEATgBRAEIAWgBBAEcAVQBBAFkAZwBCAFkAQQBEAEkAQQBaAEEAQgBZAEEARABZAEEAVwBBAEEANwBBAEQAZwBBAEwAdwBBAHkAQQBEAEEAQQBMAHcAQQB5AEEARABFAEEASQBBAEEAeABBAEQAQQBBAE8AZwBBAHoAQQBEAGMAQQBPAGcAQQAwAEEARABZAEEASQBBAEIAQgBBAEUAMABBAE8AdwBCAFYAQQBIAE0AQQBaAFEAQgB5AEEAQQB8AHwA","token_type":"bearer","expires_in":28800,"roles":[]}'
[Fri Aug 20 02:37:46 UTC 2021] Detect root zone.
[Fri Aug 20 02:37:46 UTC 2021] h='ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:46 UTC 2021] dns/getroot/ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:46 UTC 2021] Getting https://api.dynu.com/v2/dns/getroot/ott01.certmanager.<removed>.com
[Fri Aug 20 02:37:46 UTC 2021] Retrying GET
[Fri Aug 20 02:37:46 UTC 2021] GET
[Fri Aug 20 02:37:46 UTC 2021] url='https://api.dynu.com/v2/dns/getroot/ott01.certmanager.<removed>.com'
[Fri Aug 20 02:37:46 UTC 2021] timeout=
[Fri Aug 20 02:37:46 UTC 2021] displayError='1'
[Fri Aug 20 02:37:46 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:46 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:47 UTC 2021] ret='0'
[Fri Aug 20 02:37:47 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:47 UTC 2021] response='{"statusCode":200,"id":100144612,"domainName":"certmanager.<removed>.com","hostname":"ott01.certmanager.<removed>.com","node":"ott01"}'
[Fri Aug 20 02:37:47 UTC 2021] h='certmanager.<removed>.com'
[Fri Aug 20 02:37:47 UTC 2021] dns/getroot/certmanager.<removed>.com
[Fri Aug 20 02:37:47 UTC 2021] Getting https://api.dynu.com/v2/dns/getroot/certmanager.<removed>.com
[Fri Aug 20 02:37:47 UTC 2021] Retrying GET
[Fri Aug 20 02:37:47 UTC 2021] GET
[Fri Aug 20 02:37:47 UTC 2021] url='https://api.dynu.com/v2/dns/getroot/certmanager.<removed>.com'
[Fri Aug 20 02:37:47 UTC 2021] timeout=
[Fri Aug 20 02:37:47 UTC 2021] displayError='1'
[Fri Aug 20 02:37:47 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:47 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:48 UTC 2021] ret='0'
[Fri Aug 20 02:37:48 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:48 UTC 2021] response='{"statusCode":200,"id":100144612,"domainName":"certmanager.<removed>.com","hostname":"certmanager.<removed>.com","node":""}'
[Fri Aug 20 02:37:48 UTC 2021] _node='_acme-challenge.ott01'
[Fri Aug 20 02:37:48 UTC 2021] _domain_name='certmanager.<removed>.com'
[Fri Aug 20 02:37:48 UTC 2021] Checking for TXT record.
[Fri Aug 20 02:37:48 UTC 2021] dns/100144612/record
[Fri Aug 20 02:37:48 UTC 2021] Getting https://api.dynu.com/v2/dns/100144612/record
[Fri Aug 20 02:37:48 UTC 2021] Retrying GET
[Fri Aug 20 02:37:48 UTC 2021] GET
[Fri Aug 20 02:37:48 UTC 2021] url='https://api.dynu.com/v2/dns/100144612/record'
[Fri Aug 20 02:37:48 UTC 2021] timeout=
[Fri Aug 20 02:37:48 UTC 2021] displayError='1'
[Fri Aug 20 02:37:48 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:48 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:49 UTC 2021] ret='0'
[Fri Aug 20 02:37:49 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:49 UTC 2021] response='{"statusCode":200,"dnsRecords":[{"id":6246490,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"SOA","ttl":120,"state":true,"content":"certmanager.<removed>.com. 120 IN SOA ns1.dynu.com. administrator.dynu.com. 228 3600 900 604800 300","updatedOn":"2020-04-24T23:53:33","masterName":"ns1.dynu.com","responsibleName":"administrator.dynu.com","refresh":3600,"retry":900,"expire":604800,"negativeTTL":300},{"id":6246491,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"NS","ttl":90,"state":true,"content":"certmanager.<removed>.com. 90 IN NS ns1.dynu.com.","updatedOn":"2020-04-24T23:53:33.197","host":"ns1.dynu.com"},{"id":6246492,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"NS","ttl":90,"state":true,"content":"certmanager.<removed>.com. 90 IN NS ns2.dynu.com.","updatedOn":"2020-04-24T23:53:33.203","host":"ns2.dynu.com"},{"id":6246493,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"NS","ttl":90,"state":true,"content":"certmanager.<removed>.com. 90 IN NS ns3.dynu.com.","updatedOn":"2020-04-24T23:53:33.213","host":"ns3.dynu.com"},{"id":6246494,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"NS","ttl":90,"state":true,"content":"certmanager.<removed>.com. 90 IN NS ns4.dynu.com.","updatedOn":"2020-04-24T23:53:33.22","host":"ns4.dynu.com"},{"id":6246495,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"NS","ttl":90,"state":true,"content":"certmanager.<removed>.com. 90 IN NS ns5.dynu.com.","updatedOn":"2020-04-24T23:53:33.23","host":"ns5.dynu.com"},{"id":6246496,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"","hostname":"certmanager.<removed>.com","recordType":"NS","ttl":90,"state":true,"content":"certmanager.<removed>.com. 90 IN NS ns6.dynu.com.","updatedOn":"2020-04-24T23:53:33.237","host":"ns6.dynu.com"},{"id":7758608,"domainId":100144612,"domainName":"certmanager.<removed>.com","nodeName":"_acme-challenge.ott01","hostname":"_acme-challenge.ott01.certmanager.<removed>.com","recordType":"TXT","ttl":90,"state":true,"content":"_acme-challenge.ott01.certmanager.<removed>.com. 90 IN TXT \"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA\"","updatedOn":"2021-08-20T02:37:13.947","textData":"faILLlLt0cUhEBupDZUyW-DhWeR8Bdr8leCgnpm2_EA"}]}'
[Fri Aug 20 02:37:49 UTC 2021] Removing TXT record.
[Fri Aug 20 02:37:49 UTC 2021] dns/100144612/record/7758608
[Fri Aug 20 02:37:49 UTC 2021] data
[Fri Aug 20 02:37:49 UTC 2021] Retrying post
[Fri Aug 20 02:37:49 UTC 2021] DELETE
[Fri Aug 20 02:37:49 UTC 2021] _post_url='https://api.dynu.com/v2/dns/100144612/record/7758608'
[Fri Aug 20 02:37:49 UTC 2021] body
[Fri Aug 20 02:37:49 UTC 2021] _postContentType
[Fri Aug 20 02:37:49 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:49 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:49 UTC 2021] _ret='0'
[Fri Aug 20 02:37:49 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:49 UTC 2021] response='{"statusCode":200}'
[Fri Aug 20 02:37:50 UTC 2021] Removed: Success
[Fri Aug 20 02:37:50 UTC 2021] Verify finished, start to sign.
[Fri Aug 20 02:37:50 UTC 2021] i='2'
[Fri Aug 20 02:37:50 UTC 2021] j='27'
[Fri Aug 20 02:37:50 UTC 2021] Lets finalize the order.
[Fri Aug 20 02:37:50 UTC 2021] Le_OrderFinalize='https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg/finalize'
[Fri Aug 20 02:37:50 UTC 2021] url='https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg/finalize'
[Fri Aug 20 02:37:50 UTC 2021] payload='{"csr": "MIIE1zCCAr8CAQAwgZExCzAJBgNVBAYTAkNBMQswCQYDVQQIDAJPTjEPMA0GA1UEBwwGT3R0YXdhMREwDwYDVQQKDAhEaWdpbWFjaDEMMAoGA1UECwwDU05TMSIwIAYDVQQDDBl0YXV0dWxsaS5vdHQuZGlnaW1hY2guY29tMR8wHQYJKoZIhvcNAQkBFhBrYW5qZWVAa29tYWlsLmNhMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEAvXXY6phLjdZLoJiCBcHCEdxM3h8YSEBJtDgROjubWneuKFV02goWQEWlN9z2er16_2BPuuQUBSGxXBPSed34xjQccTELRbKcVwogJMD1QiGWo2daY1HYFw_ZpNAdhMklErrCIp1xTnKN22w7TKK8VyU3dD9Dd4Q-b1Jif-aOO0AkhmemevLhznoMRFNtVQVvhO4dig2jAGejORuGblvOxPj0YRI8wNG6S0MFVjjlA3qYGuxindh3_H__8szbYh8FmXyCzRLwdSV_heYwhlZue6a_23uJj6CGhEUR4P7L5SpTZmUIB2NmePsXahaMBwlpxbeOkbU2TTUMDPcvZ6ZJKVRFUVPCNYBtQLGUYrQb-WPzPgNzR5SvR_hm-7g_ieEtFBc8zuzlmSVSGindqysugOUWYG3axOfELvR543rsuXHyOEFH7OZl-tU_Opv-d0MKxNxmO6EA5vQmEvrZv9fWFph_-orYWxDK9-rjwJR55vtBrnjM0oTF4WzhFWVtZ4zr-rmwJ5R6DRDJh3i-dO4EgCANYQAAczEcqARlFIyKRumDnJe2O9k11Ayu1Mk2OYSM-enaliYIzYJjGDpi6Wo9i1ZLDNSFQRMD3fneWFI5oyE82ujm9Y9mWU7OcXTwgP_3u8sbVffNwMmTWu_sqV-C4354m1frYnPaeijDHo6y2xUCAwEAAaAAMA0GCSqGSIb3DQEBCwUAA4ICAQCPBnwGa8KV117bzNBLKzwWW5bY6WEtnjUxyYv0mfd-oHGJFtZVmvJ282veGFvJx2uAWVIUV-xWI_nmB_5-jNzkZP1Ojtw5irIW9S7-Rjr4mq-SaeJy5VW2hHydyxmNCL9uVKJtasjirWUPFigJu-AVXBI-pLPJmPPjnDeieBh-LP7vZoE0eHikNwhAB3rz5MbW_pjnWKSIc7VVrc_9e992GHaRm90us6VQA9yrTB_QPhLSgPsBprC60VcoyRbDDL73RzJRhHKWe31Q4cErGnQkHGNJpensmG1OdYrb2AlGTNWnJZWr6a0bHRpbLT9U7bF4FHjhC3wkQu5D3zc-s8jxcKJvnh4lhuhmdaBvtIruQUfekIPd8GNY_qDIk2J_lL386KpUpJT8N0B_VbyvbqazmpEDALivZzs0cid3lkBdjyn-eiLCzOQNN-azygi1yWWF1MOQsc4jO6oiqAr9g8u2EOWIxbenp-p0i1WtMfWCN7diPJH1KXN6E-FY5QvInQN7VR8v8FCNbZsamdINUNCgIbtjN0yCcMozYYpVWWIRYo55rBsJByfJsdDLq0r41-vhKiLNA-LKwCN8z_VAoIpyyO8QFxbQfB8kct-4CDrsV0nu7bCmhGm0wY2VApg_xGEx3JS9dJm8C75GpDbfFwswwS_0BDV_iXhta5Pq2pvnTQ"}'
[Fri Aug 20 02:37:50 UTC 2021] Use cached jwk for file: /srv/acmesh/data/ca/acme.zerossl.com/v2/DV90/account.key
[Fri Aug 20 02:37:50 UTC 2021] Use _CACHED_NONCE='LVn-LsRq7fjuczbeknyNvAu-DV7udq_2URLv8xWWEyY'
[Fri Aug 20 02:37:50 UTC 2021] nonce='LVn-LsRq7fjuczbeknyNvAu-DV7udq_2URLv8xWWEyY'
[Fri Aug 20 02:37:50 UTC 2021] Retrying post
[Fri Aug 20 02:37:50 UTC 2021] POST
[Fri Aug 20 02:37:50 UTC 2021] _post_url='https://acme.zerossl.com/v2/DV90/order/ebiab_XGTN2spDDMeFfbRg/finalize'
[Fri Aug 20 02:37:50 UTC 2021] body='{"protected": "eyJub25jZSI6ICJMVm4tTHNScTdmanVjemJla255TnZBdS1EVjd1ZHFfMlVSTHY4eFdXRXlZIiwgInVybCI6ICJodHRwczovL2FjbWUuemVyb3NzbC5jb20vdjIvRFY5MC9vcmRlci9lYmlhYl9YR1ROMnNwRERNZUZmYlJnL2ZpbmFsaXplIiwgImFsZyI6ICJSUzI1NiIsICJraWQiOiAiaHR0cHM6Ly9hY21lLnplcm9zc2wuY29tL3YyL0RWOTAvYWNjb3VudC9Cb1YwcGhTUlJQSDlMLUdGa0Q3eGhnIn0", "payload": "eyJjc3IiOiAiTUlJRTF6Q0NBcjhDQVFBd2daRXhDekFKQmdOVkJBWVRBa05CTVFzd0NRWURWUVFJREFKUFRqRVBNQTBHQTFVRUJ3d0dUM1IwWVhkaE1SRXdEd1lEVlFRS0RBaEVhV2RwYldGamFERU1NQW9HQTFVRUN3d0RVMDVUTVNJd0lBWURWUVFEREJsMFlYVjBkV3hzYVM1dmRIUXVaR2xuYVcxaFkyZ3VZMjl0TVI4d0hRWUpLb1pJaHZjTkFRa0JGaEJyWVc1cVpXVkFhMjl0WVdsc0xtTmhNSUlDSWpBTkJna3Foa2lHOXcwQkFRRUZBQU9DQWc4QU1JSUNDZ0tDQWdFQXZYWFk2cGhMamRaTG9KaUNCY0hDRWR4TTNoOFlTRUJKdERnUk9qdWJXbmV1S0ZWMDJnb1dRRVdsTjl6MmVyMTZfMkJQdXVRVUJTR3hYQlBTZWQzNHhqUWNjVEVMUmJLY1Z3b2dKTUQxUWlHV28yZGFZMUhZRndfWnBOQWRoTWtsRXJyQ0lwMXhUbktOMjJ3N1RLSzhWeVUzZEQ5RGQ0US1iMUppZi1hT08wQWtobWVtZXZMaHpub01SRk50VlFWdmhPNGRpZzJqQUdlak9SdUdibHZPeFBqMFlSSTh3Tkc2UzBNRlZqamxBM3FZR3V4aW5kaDNfSF9fOHN6YlloOEZtWHlDelJMd2RTVl9oZVl3aGxadWU2YV8yM3VKajZDR2hFVVI0UDdMNVNwVFptVUlCMk5tZVBzWGFoYU1Cd2xweGJlT2tiVTJUVFVNRFBjdlo2WkpLVlJGVVZQQ05ZQnRRTEdVWXJRYi1XUHpQZ056UjVTdlJfaG0tN2dfaWVFdEZCYzh6dXpsbVNWU0dpbmRxeXN1Z09VV1lHM2F4T2ZFTHZSNTQzcnN1WEh5T0VGSDdPWmwtdFVfT3B2LWQwTUt4TnhtTzZFQTV2UW1FdnJadjlmV0ZwaF8tb3JZV3hESzktcmp3SlI1NXZ0QnJuak0wb1RGNFd6aEZXVnRaNHpyLXJtd0o1UjZEUkRKaDNpLWRPNEVnQ0FOWVFBQWN6RWNxQVJsRkl5S1J1bURuSmUyTzlrMTFBeXUxTWsyT1lTTS1lbmFsaVlJellKakdEcGk2V285aTFaTEROU0ZRUk1EM2ZuZVdGSTVveUU4MnVqbTlZOW1XVTdPY1hUd2dQXzN1OHNiVmZmTndNbVRXdV9zcVYtQzQzNTRtMWZyWW5QYWVpakRIbzZ5MnhVQ0F3RUFBYUFBTUEwR0NTcUdTSWIzRFFFQkN3VUFBNElDQVFDUEJud0dhOEtWMTE3YnpOQkxLendXVzViWTZXRXRualV4eVl2MG1mZC1vSEdKRnRaVm12SjI4MnZlR0Z2SngydUFXVklVVi14V0lfbm1CXzUtak56a1pQMU9qdHc1aXJJVzlTNy1SanI0bXEtU2FlSnk1VlcyaEh5ZHl4bU5DTDl1VktKdGFzamlyV1VQRmlnSnUtQVZYQkktcExQSm1QUGpuRGVpZUJoLUxQN3Zab0UwZUhpa053aEFCM3J6NU1iV19wam5XS1NJYzdWVnJjXzllOTkyR0hhUm05MHVzNlZRQTl5clRCX1FQaExTZ1BzQnByQzYwVmNveVJiRERMNzNSekpSaEhLV2UzMVE0Y0VyR25Ra0hHTkpwZW5zbUcxT2RZcmIyQWxHVE5XbkpaV3I2YTBiSFJwYkxUOVU3YkY0RkhqaEMzd2tRdTVEM3pjLXM4anhjS0p2bmg0bGh1aG1kYUJ2dElydVFVZmVrSVBkOEdOWV9xRElrMkpfbEwzODZLcFVwSlQ4TjBCX1ZieXZicWF6bXBFREFMaXZaenMwY2lkM2xrQmRqeW4tZWlMQ3pPUU5OLWF6eWdpMXlXV0YxTU9Rc2M0ak82b2lxQXI5Zzh1MkVPV0l4YmVucC1wMGkxV3RNZldDTjdkaVBKSDFLWE42RS1GWTVRdkluUU43VlI4djhGQ05iWnNhbWRJTlVOQ2dJYnRqTjB5Q2NNb3pZWXBWV1dJUllvNTVyQnNKQnlmSnNkRExxMHI0MS12aEtpTE5BLUxLd0NOOHpfVkFvSXB5eU84UUZ4YlFmQjhrY3QtNENEcnNWMG51N2JDbWhHbTB3WTJWQXBnX3hHRXgzSlM5ZEptOEM3NUdwRGJmRndzd3dTXzBCRFZfaVhodGE1UHEycHZuVFEifQ", "signature": "grBtj8ilzo2PAvlr2Et4o1u82Xv6rEwalU3a-ljSdIcYw03nLFFIYHoaUT9C4xx2IuzlM5inDo5y1geRebc27hyZW6l9bxH1uEersablkOUv70gQqUC0ofpi2f5vlTPHBCI4UltzsAgFqXrGkR7_o1KNq1kRkbEO0rHi50Cf42xLXcVQLHErkbYEsANjHVL1ZpTY2hM4WyIzgQ6bkboV6nbY4I66z6C5DdQ7bBMal_Yz7PsWT5nIVsWOiy7Hq0y2tdHKZUiQKYxeQJIUuhCcgGCeprUC3PSOhX5b6ttkpMDFeAZwb0XhEJBD12zRHVtb_x_DcSe7ikTkIr6DcUYTlA"}'
[Fri Aug 20 02:37:50 UTC 2021] _postContentType='application/jose+json'
[Fri Aug 20 02:37:50 UTC 2021] Http already initialized.
[Fri Aug 20 02:37:50 UTC 2021] _CURL='curl --silent --dump-header /srv/acmesh/data/http.header  -L  --trace-ascii /tmp/tmp.im2KOlaXqR  -g '
[Fri Aug 20 02:37:50 UTC 2021] _ret='0'
[Fri Aug 20 02:37:50 UTC 2021] _hcode='0'
[Fri Aug 20 02:37:50 UTC 2021] responseHeaders='HTTP/2 400
server: nginx
date: Fri, 20 Aug 2021 02:37:50 GMT
content-type: application/problem+json
content-length: 100
replay-nonce: HkEp_bWnsu8mcJY6EJqIxjNw-u_dW7buNyISsqgRXB0
cache-control: max-age=0, no-cache, no-store
access-control-allow-origin: *
link: <https://acme.zerossl.com/v2/DV90>;rel="index"
cache-control: max-age=-1
'
[Fri Aug 20 02:37:50 UTC 2021] code='400'
[Fri Aug 20 02:37:50 UTC 2021] original='{"type":"urn:ietf:params:acme:error:badCSR","status":400,"detail":"The CSR contains no identifiers"}'
[Fri Aug 20 02:37:50 UTC 2021] response='{"type":"urn:ietf:params:acme:error:badCSR","status":400,"detail":"The CSR contains no identifiers"}'
[Fri Aug 20 02:37:50 UTC 2021] Sign failed, finalize code is not 200.
[Fri Aug 20 02:37:50 UTC 2021] {"type":"urn:ietf:params:acme:error:badCSR","status":400,"detail":"The CSR contains no identifiers"}
[Fri Aug 20 02:37:50 UTC 2021] _on_issue_err
[Fri Aug 20 02:37:50 UTC 2021] Please check log file for more details: /srv/acmesh/data/acme.sh.log
[Fri Aug 20 02:37:50 UTC 2021] _chk_vlist
[Fri Aug 20 02:37:50 UTC 2021] Diagnosis versions:
openssl:openssl
OpenSSL 1.1.1f  31 Mar 2020
apache:
apache doesn't exist.
nginx:
nginx doesn't exist.
socat:
socat by Gerhard Rieger and contributors - see www.dest-unreach.org
socat version 1.7.3.3 on Oct 26 2019 17:42:04
   running on Linux version #2 SMP Wed Jul 21 17:45:32 PDT 2021, release 5.4.17-2102.203.6.el8uek.x86_64, machine x86_64
features:
  #define WITH_STDIO 1
  #define WITH_FDNUM 1
  #define WITH_FILE 1
  #define WITH_CREAT 1
  #define WITH_GOPEN 1
  #define WITH_TERMIOS 1
  #define WITH_PIPE 1
  #define WITH_UNIX 1
  #define WITH_ABSTRACT_UNIXSOCKET 1
  #define WITH_IP4 1
  #define WITH_IP6 1
  #define WITH_RAWIP 1
  #define WITH_GENERICSOCKET 1
  #define WITH_INTERFACE 1
  #define WITH_TCP 1
  #define WITH_UDP 1
  #define WITH_SCTP 1
  #define WITH_LISTEN 1
  #define WITH_SOCKS4 1
  #define WITH_SOCKS4A 1
  #define WITH_PROXY 1
  #define WITH_SYSTEM 1
  #define WITH_EXEC 1
  #undef WITH_READLINE
  #define WITH_TUN 1
  #define WITH_PTY 1
  #define WITH_OPENSSL 1
  #undef WITH_FIPS
  #define WITH_LIBWRAP 1
  #define WITH_SYCLS 1
  #define WITH_FILAN 1
  #define WITH_RETRY 1
  #define WITH_MSGLEVEL 0 /*debug*/
Neilpang commented 3 years ago

Is this CSR working with letsencrypt ? It seems your CSR doesn't contain SubjectAltNames ?

komailo commented 3 years ago

Yes the CSR works with letsencrypt. I have been trying to migrate to zerossl but this error is what's blocking me.

I'll look into specifying SubjectAltName and see if it fixes it.