Author Topic: CWP7 AutoSSL (letsencrypt) for hostname failed.  (Read 2145 times)

0 Members and 1 Guest are viewing this topic.

Offline
*
CWP7 AutoSSL (letsencrypt) for hostname failed.
« on: May 07, 2021, 05:01:26 PM »
Hello,
I've decided to install CWP7 today on an OpenVZ I'm renting.
The OpenVZ IP is static 185.53.129.160 and it is set in the vps control panel to srv.madbeka.win

First thing I did after installing is settings the nameservers as followed:
on ns1.madbeka.win.db
ns1.madbeka.win.   NS   86400   ns1.madbeka.win.   
ns1.madbeka.win.   NS   86400   ns2.madbeka.win.   
ns1.madbeka.win.   A   14400   185.53.129.160

on ns2.madbeka.win.db
ns2.madbeka.win.   NS   86400   ns1.madbeka.win.   
ns2.madbeka.win.   NS   86400   ns2.madbeka.win.   
ns2.madbeka.win.   A   14400   185.53.129.160

After that I set up a new DNS Zone - srv.madbeka.win.db and set it as followed:
srv.madbeka.win.   NS   86400   ns1.madbeka.win.   
srv.madbeka.win.   NS   86400   ns2.madbeka.win.   
srv.madbeka.win.   MX   0   srv.madbeka.win.
srv.madbeka.win.   A      185.53.129.160   
localhost.srv.madbeka.win.   A      127.0.0.1
_dmarc   TXT   14400   v=DMARC1; p=reject; pct=100; adkim=r; aspf=s   
@   TXT   14400   v=spf1 a mx ~all

Then I went to "Change Hostname" tab and verified that:
Your Hostname is: srv.madbeka.win and it resolves to IP: 185.53.129.160 [Check Black List] [Check CWP SSL] [Check WebServers SSL] rDNS/PTR = srv.madbeka.win SUCCESS [Check SenderBase]   

Under New Hostname i have srv.madbeka.win

The thing is that after I click on "Change Hostname" it doesn't generate an AUTOSSL certificate.
tail -f /root/.acme.sh/acme.sh.log showed me this error:

[Fri May  7 18:36:00 CEST 2021] POST
[Fri May  7 18:36:00 CEST 2021] _post_url='https://acme-v02.api.letsencrypt.org/acme/finalize/122704566/9545281925'
[Fri May  7 18:36:00 CEST 2021] _CURL='curl --silent --dump-header /root/.acme.sh/http.header  -L  -g '
[Fri May  7 18:36:01 CEST 2021] _ret='0'
[Fri May  7 18:36:01 CEST 2021] code='403'
[Fri May  7 18:36:01 CEST 2021] Sign failed, finalize code is not 200.
[Fri May  7 18:36:01 CEST 2021] {
  "type": "urn:ietf:params:acme:error:orderNotReady",
  "detail": "Order's status (\"invalid\") is not acceptable for finalization",
  "status": 403
}
[Fri May  7 18:36:01 CEST 2021] _on_issue_err
[Fri May  7 18:36:01 CEST 2021] Please check log file for more details: /root/.acme.sh/acme.sh.log

Any ideas what is wrong with it?
« Last Edit: May 07, 2021, 05:07:39 PM by mhu »