acmesh-official / acme.sh

A pure Unix shell script implementing ACME client protocol
https://acme.sh
GNU General Public License v3.0
38.26k stars 4.89k forks source link

acme.sh --issue --server google \ #4704

Open hfhoshii opened 1 year ago

hfhoshii commented 1 year ago

root@glowing-unicorn-2:~/.acme.sh# acme.sh --issue --debug --server google -d ban.hoshii.nl --dns dns_googledomains [Mon 17 Jul 2023 11:36:36 AM EDT] Selected server: https://dv.acme-v02.api.pki.goog/directory [Mon 17 Jul 2023 11:36:36 AM EDT] Lets find script dir. [Mon 17 Jul 2023 11:36:36 AM EDT] SCRIPT='/root/.acme.sh/acme.sh' [Mon 17 Jul 2023 11:36:36 AM EDT] _script='/root/.acme.sh/acme.sh' [Mon 17 Jul 2023 11:36:36 AM EDT] _script_home='/root/.acme.sh' [Mon 17 Jul 2023 11:36:36 AM EDT] Using config home:/root/.acme.sh https://github.com/acmesh-official/acme.sh v3.0.6 [Mon 17 Jul 2023 11:36:36 AM EDT] Using server: https://dv.acme-v02.api.pki.goog/directory [Mon 17 Jul 2023 11:36:36 AM EDT] Running cmd: issue [Mon 17 Jul 2023 11:36:36 AM EDT] _main_domain='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:36 AM EDT] _alt_domains='no' [Mon 17 Jul 2023 11:36:36 AM EDT] Using config home:/root/.acme.sh [Mon 17 Jul 2023 11:36:36 AM EDT] ACME_DIRECTORY='https://dv.acme-v02.api.pki.goog/directory' [Mon 17 Jul 2023 11:36:36 AM EDT] DOMAIN_PATH='/root/.acme.sh/ban.hoshii.nl_ecc' [Mon 17 Jul 2023 11:36:36 AM EDT] Le_NextRenewTime [Mon 17 Jul 2023 11:36:36 AM EDT] Using ACME_DIRECTORY: https://dv.acme-v02.api.pki.goog/directory [Mon 17 Jul 2023 11:36:36 AM EDT] _init api for server: https://dv.acme-v02.api.pki.goog/directory [Mon 17 Jul 2023 11:36:36 AM EDT] GET [Mon 17 Jul 2023 11:36:36 AM EDT] url='https://dv.acme-v02.api.pki.goog/directory' [Mon 17 Jul 2023 11:36:36 AM EDT] timeout= [Mon 17 Jul 2023 11:36:36 AM EDT] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g ' [Mon 17 Jul 2023 11:36:37 AM EDT] ret='0' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_KEY_CHANGE='https://dv.acme-v02.api.pki.goog/key-change' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_NEW_AUTHZ='https://dv.acme-v02.api.pki.goog/new-authz' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_NEW_ORDER='https://dv.acme-v02.api.pki.goog/new-order' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_NEW_ACCOUNT='https://dv.acme-v02.api.pki.goog/new-account' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_REVOKE_CERT='https://dv.acme-v02.api.pki.goog/revoke-cert' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_AGREEMENT='https://pki.goog/GTS-SA.pdf' [Mon 17 Jul 2023 11:36:37 AM EDT] ACME_NEW_NONCE='https://dv.acme-v02.api.pki.goog/new-nonce' [Mon 17 Jul 2023 11:36:37 AM EDT] Using CA: https://dv.acme-v02.api.pki.goog/directory [Mon 17 Jul 2023 11:36:37 AM EDT] _on_before_issue [Mon 17 Jul 2023 11:36:37 AM EDT] _chk_main_domain='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:37 AM EDT] _chk_alt_domains [Mon 17 Jul 2023 11:36:37 AM EDT] Le_LocalAddress [Mon 17 Jul 2023 11:36:37 AM EDT] d='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:37 AM EDT] Check for domain='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:37 AM EDT] _currentRoot='dns_googledomains' [Mon 17 Jul 2023 11:36:37 AM EDT] d [Mon 17 Jul 2023 11:36:37 AM EDT] _saved_account_key_hash is not changed, skip register account. [Mon 17 Jul 2023 11:36:37 AM EDT] Read key length:ec-256 [Mon 17 Jul 2023 11:36:37 AM EDT] _createcsr [Mon 17 Jul 2023 11:36:37 AM EDT] Single domain='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:37 AM EDT] Getting domain auth token for each domain [Mon 17 Jul 2023 11:36:37 AM EDT] d [Mon 17 Jul 2023 11:36:37 AM EDT] url='https://dv.acme-v02.api.pki.goog/new-order' [Mon 17 Jul 2023 11:36:37 AM EDT] payload='{"identifiers": [{"type":"dns","value":"ban.hoshii.nl"}]}' [Mon 17 Jul 2023 11:36:37 AM EDT] EC key [Mon 17 Jul 2023 11:36:37 AM EDT] HEAD [Mon 17 Jul 2023 11:36:37 AM EDT] _post_url='https://dv.acme-v02.api.pki.goog/new-nonce' [Mon 17 Jul 2023 11:36:37 AM EDT] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g -I ' [Mon 17 Jul 2023 11:36:37 AM EDT] _ret='0' [Mon 17 Jul 2023 11:36:38 AM EDT] POST [Mon 17 Jul 2023 11:36:38 AM EDT] _post_url='https://dv.acme-v02.api.pki.goog/new-order' [Mon 17 Jul 2023 11:36:38 AM EDT] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g ' [Mon 17 Jul 2023 11:36:38 AM EDT] _ret='0' [Mon 17 Jul 2023 11:36:38 AM EDT] code='201' [Mon 17 Jul 2023 11:36:38 AM EDT] Le_LinkOrder='https://dv.acme-v02.api.pki.goog/order/46EcOO6SLOJ3zuRKxMcFpg' [Mon 17 Jul 2023 11:36:38 AM EDT] Le_OrderFinalize='https://dv.acme-v02.api.pki.goog/order/46EcOO6SLOJ3zuRKxMcFpg/finalize' [Mon 17 Jul 2023 11:36:38 AM EDT] url='https://dv.acme-v02.api.pki.goog/authz/OicQ3q66EUK3b3shRADKug' [Mon 17 Jul 2023 11:36:38 AM EDT] payload [Mon 17 Jul 2023 11:36:38 AM EDT] POST [Mon 17 Jul 2023 11:36:38 AM EDT] _post_url='https://dv.acme-v02.api.pki.goog/authz/OicQ3q66EUK3b3shRADKug' [Mon 17 Jul 2023 11:36:38 AM EDT] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g ' [Mon 17 Jul 2023 11:36:39 AM EDT] _ret='0' [Mon 17 Jul 2023 11:36:39 AM EDT] code='200' [Mon 17 Jul 2023 11:36:39 AM EDT] d='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:39 AM EDT] Getting webroot for domain='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:39 AM EDT] _w='dns_googledomains' [Mon 17 Jul 2023 11:36:39 AM EDT] _currentRoot='dns_googledomains' [Mon 17 Jul 2023 11:36:39 AM EDT] entry='"type":"dns-01","url":"https://dv.acme-v02.api.pki.goog/challenge/wLVU4okQK-7D75niKN4QJw","status":"pending","token":"KQyYN1INHvYpy2bDrgeu_8lWf8f6dCbqouAnF_IUltMItSaCJ4ZbxNee_APs5fal"' [Mon 17 Jul 2023 11:36:39 AM EDT] token='KQyYN1INHvYpy2bDrgeu_8lWf8f6dCbqouAnF_IUltMItSaCJ4ZbxNee_APs5fal' [Mon 17 Jul 2023 11:36:39 AM EDT] uri='https://dv.acme-v02.api.pki.goog/challenge/wLVU4okQK-7D75niKN4QJw' [Mon 17 Jul 2023 11:36:39 AM EDT] keyauthorization='KQyYN1INHvYpy2bDrgeu_8lWf8f6dCbqouAnF_IUltMItSaCJ4ZbxNee_APs5fal.-lo145aOJMVMb4nZaQo1IZhQPfKzGA-Da3dTHNKkI50' [Mon 17 Jul 2023 11:36:39 AM EDT] dvlist='ban.hoshii.nl#KQyYN1INHvYpy2bDrgeu_8lWf8f6dCbqouAnF_IUltMItSaCJ4ZbxNee_APs5fal.-lo145aOJMVMb4nZaQo1IZhQPfKzGA-Da3dTHNKkI50#https://dv.acme-v02.api.pki.goog/challenge/wLVU4okQK-7D75niKN4QJw#dns-01#dns_googledomains' [Mon 17 Jul 2023 11:36:39 AM EDT] d [Mon 17 Jul 2023 11:36:39 AM EDT] vlist='ban.hoshii.nl#KQyYN1INHvYpy2bDrgeu_8lWf8f6dCbqouAnF_IUltMItSaCJ4ZbxNee_APs5fal.-lo145aOJMVMb4nZaQo1IZhQPfKzGA-Da3dTHNKkI50#https://dv.acme-v02.api.pki.goog/challenge/wLVU4okQK-7D75niKN4QJw#dns-01#dns_googledomains,' [Mon 17 Jul 2023 11:36:39 AM EDT] d='ban.hoshii.nl' [Mon 17 Jul 2023 11:36:39 AM EDT] _d_alias [Mon 17 Jul 2023 11:36:39 AM EDT] txtdomain='_acme-challenge.ban.hoshii.nl' [Mon 17 Jul 2023 11:36:39 AM EDT] txt='i9bqvAafX4gRvG16yc7ZqBdjhz5IXOpIIjsVrFJbi_s' [Mon 17 Jul 2023 11:36:39 AM EDT] d_api='/root/.acme.sh/dnsapi/dns_googledomains.sh' [Mon 17 Jul 2023 11:36:39 AM EDT] Found domain api file: /root/.acme.sh/dnsapi/dns_googledomains.sh [Mon 17 Jul 2023 11:36:39 AM EDT] Adding txt value: i9bqvAafX4gRvG16yc7ZqBdjhz5IXOpIIjsVrFJbi_s for domain: _acme-challenge.ban.hoshii.nl [Mon 17 Jul 2023 11:36:39 AM EDT] Invoking Google Domains ACME DNS API. [Mon 17 Jul 2023 11:36:39 AM EDT] GOOGLEDOMAINS_ACCESS_TOKEN='NHpFZE1sU2tnTFVXeEg0UlBfdWRoUQ==' [Mon 17 Jul 2023 11:36:39 AM EDT] GOOGLEDOMAINS_ZONE='google-domains-zone' [Mon 17 Jul 2023 11:36:39 AM EDT] GET [Mon 17 Jul 2023 11:36:39 AM EDT] url='https://acmedns.googleapis.com/v1/acmeChallengeSets/google-domains-zone' [Mon 17 Jul 2023 11:36:39 AM EDT] timeout= [Mon 17 Jul 2023 11:36:39 AM EDT] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g ' [Mon 17 Jul 2023 11:36:39 AM EDT] ret='0' [Mon 17 Jul 2023 11:36:39 AM EDT] response='{ "error": { "code": 400, "message": "Request contains an invalid argument.", "status": "INVALID_ARGUMENT" } }' [Mon 17 Jul 2023 11:36:39 AM EDT] Could not find a Google Domains-managed zone containing the requested domain. [Mon 17 Jul 2023 11:36:39 AM EDT] Error add txt for domain:_acme-challenge.ban.hoshii.nl [Mon 17 Jul 2023 11:36:39 AM EDT] _on_issue_err [Mon 17 Jul 2023 11:36:39 AM EDT] Please add '--debug' or '--log' to check more details. [Mon 17 Jul 2023 11:36:39 AM EDT] See: https://github.com/acmesh-official/acme.sh/wiki/How-to-debug-acme.sh [Mon 17 Jul 2023 11:36:39 AM EDT] url='https://dv.acme-v02.api.pki.goog/challenge/wLVU4okQK-7D75niKN4QJw' [Mon 17 Jul 2023 11:36:39 AM EDT] payload='{}' [Mon 17 Jul 2023 11:36:39 AM EDT] POST [Mon 17 Jul 2023 11:36:39 AM EDT] _post_url='https://dv.acme-v02.api.pki.goog/challenge/wLVU4okQK-7D75niKN4QJw' [Mon 17 Jul 2023 11:36:39 AM EDT] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g ' [Mon 17 Jul 2023 11:36:40 AM EDT] _ret='0' [Mon 17 Jul 2023 11:36:40 AM EDT] code='200' [Mon 17 Jul 2023 11:36:40 AM EDT] Diagnosis versions: openssl:openssl OpenSSL 1.1.1n 15 Mar 2022 apache: apache doesn't exist. nginx: nginx doesn't exist. socat: socat by Gerhard Rieger and contributors - see www.dest-unreach.org socat version 1.7.3.2 on Nov 19 2017 13:56:10 running on Linux version #1 SMP Debian 4.19.37-5+deb10u2 (2019-08-08), release 4.19.0-5-amd64, machine x86_64 features:

define WITH_STDIO 1

define WITH_FDNUM 1

define WITH_FILE 1

define WITH_CREAT 1

define WITH_GOPEN 1

define WITH_TERMIOS 1

define WITH_PIPE 1

define WITH_UNIX 1

define WITH_ABSTRACT_UNIXSOCKET 1

define WITH_IP4 1

define WITH_IP6 1

define WITH_RAWIP 1

define WITH_GENERICSOCKET 1

define WITH_INTERFACE 1

define WITH_TCP 1

define WITH_UDP 1

define WITH_SCTP 1

define WITH_LISTEN 1

define WITH_SOCKS4 1

define WITH_SOCKS4A 1

define WITH_PROXY 1

define WITH_SYSTEM 1

define WITH_EXEC 1

undef WITH_READLINE

define WITH_TUN 1

define WITH_PTY 1

define WITH_OPENSSL 1

undef WITH_FIPS

define WITH_LIBWRAP 1

define WITH_SYCLS 1

define WITH_FILAN 1

define WITH_RETRY 1

define WITH_MSGLEVEL 0 /debug/

[Mon 17 Jul 2023 11:36:40 AM EDT] pid [Mon 17 Jul 2023 11:36:40 AM EDT] No need to restore nginx, skip. [Mon 17 Jul 2023 11:36:40 AM EDT] _clearupdns [Mon 17 Jul 2023 11:36:40 AM EDT] dns_entries [Mon 17 Jul 2023 11:36:40 AM EDT] skip dns.

github-actions[bot] commented 1 year ago

Please upgrade to the latest code and try again first. Maybe it's already fixed. acme.sh --upgrade If it's still not working, please provide the log with --debug 2, otherwise, nobody can help you.