0

Letsencrypt not working for domain on Server/IP 1 and for subdomain on Server/IP 2 *using A and AAAA records

So we have 2 servers, 1 live and 1 staging

  • live has multidomain cert for non-www and www using Letsencrypt
  • live is hosted on server 1 with IP 1
  • staging is hosted on staging.* on server server 2 with IP 2
  • Problem: letsencrypt is not letting us generate SSL on server 2 with IP 2

Question: How can we solve the problem where letsencrypt is not letting us generate SSL on server 2 with IP 2?

snh_nl
  • 2,877
  • 6
  • 32
  • 62
  • What exactly "not letting us" means, do you get some error? – Dusan Bajic Feb 22 '21 at 16:03
  • Servfail for subdomain caa. Caa was set for main domain without www. assumed all child subdomains would inherit but this does not seem the case – snh_nl Feb 22 '21 at 16:55
  • CAA was set at the rootdomain following https://letsencrypt.org/docs/caa/ as `domain.com. 14400 IN CAA 0 issue "letsencrypt.org"` when I dig to `domain.com` I get CAA records, when I do the same for `staging.domain.com` I get no results. According to the spec CAA should be obtained from the main domain if not set on the subdomain. Or am I missing something? – snh_nl Feb 22 '21 at 20:17

0 Answers0