Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Feature Requests
  3. Failed LE Certs due to DNS config change

Failed LE Certs due to DNS config change

Scheduled Pinned Locked Moved Feature Requests
8 Posts 3 Posters 1.3k Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • robiR Offline
      robiR Offline
      robi
      wrote on last edited by
      #1

      I have a few domains that generate these failures now because they expired and the registrar re-pointed their DNS away from Cloudron.

      If there was a check to validate DNS before the error and notification is generated, the message would be much more useful and the constant retries could be stopped until DNS is back.

      Stop getting certs until then.

      Step up in intelligence.

      Conscious tech

      nebulonN 1 Reply Last reply
      1
      • robiR robi

        I have a few domains that generate these failures now because they expired and the registrar re-pointed their DNS away from Cloudron.

        If there was a check to validate DNS before the error and notification is generated, the message would be much more useful and the constant retries could be stopped until DNS is back.

        Stop getting certs until then.

        Step up in intelligence.

        nebulonN Offline
        nebulonN Offline
        nebulon
        Staff
        wrote on last edited by
        #2

        @robi the next release will be less noisy about temporarily failing cert renewals. It will only raise warnings if it is actually timely urgent. So I guess your case would also be covered since by the time the cert expires your DNS records would be fine again.

        robiR 1 Reply Last reply
        1
        • nebulonN nebulon

          @robi the next release will be less noisy about temporarily failing cert renewals. It will only raise warnings if it is actually timely urgent. So I guess your case would also be covered since by the time the cert expires your DNS records would be fine again.

          robiR Offline
          robiR Offline
          robi
          wrote on last edited by
          #3

          @nebulon No, as some of these domains we don't control. If they choose not to renew, they should go into a different state.

          Unconfigured perhaps.

          Conscious tech

          nebulonN 1 Reply Last reply
          1
          • robiR robi

            @nebulon No, as some of these domains we don't control. If they choose not to renew, they should go into a different state.

            Unconfigured perhaps.

            nebulonN Offline
            nebulonN Offline
            nebulon
            Staff
            wrote on last edited by
            #4

            @robi not sure I understand, so you are saying those are domains added to the Cloudron but with wildcard or manual DNS backend and thus the renewal fails because the records don't point to the Cloudron anymore? If this is the case, why have them on the Cloudron in the first place and probably more importantly why are there apps installed using them, which is why a renewal of certs would be triggered.

            robiR 1 Reply Last reply
            0
            • nebulonN nebulon

              @robi not sure I understand, so you are saying those are domains added to the Cloudron but with wildcard or manual DNS backend and thus the renewal fails because the records don't point to the Cloudron anymore? If this is the case, why have them on the Cloudron in the first place and probably more importantly why are there apps installed using them, which is why a renewal of certs would be triggered.

              robiR Offline
              robiR Offline
              robi
              wrote on last edited by
              #5

              @nebulon No.

              Customer wants domain hosted for any reason, let's say WP. At some point they either point the domain someplace else, or it expires and the registrar repoints to it's own DNS servers which point to parking servers.

              There's no "heads up" or customer contact that this has happened, just errors on our side.

              This could be more graceful.

              Conscious tech

              d19dotcaD 1 Reply Last reply
              0
              • robiR robi

                @nebulon No.

                Customer wants domain hosted for any reason, let's say WP. At some point they either point the domain someplace else, or it expires and the registrar repoints to it's own DNS servers which point to parking servers.

                There's no "heads up" or customer contact that this has happened, just errors on our side.

                This could be more graceful.

                d19dotcaD Offline
                d19dotcaD Offline
                d19dotca
                wrote on last edited by
                #6

                @robi So in other words, you're wanting Cloudron to essentially notify you if it notices that registered domain names used on the Cloudron instance are pointed away from the server? In other words, a period check (like once a day or something) that notifies admins?

                --
                Dustin Dauncey
                www.d19.ca

                nebulonN 1 Reply Last reply
                0
                • d19dotcaD d19dotca

                  @robi So in other words, you're wanting Cloudron to essentially notify you if it notices that registered domain names used on the Cloudron instance are pointed away from the server? In other words, a period check (like once a day or something) that notifies admins?

                  nebulonN Offline
                  nebulonN Offline
                  nebulon
                  Staff
                  wrote on last edited by
                  #7

                  @d19dotca as I understand it, I also think this is not so much related to the cert renewal, but the failure to do so is just the symptom.

                  1 Reply Last reply
                  2
                  • robiR Offline
                    robiR Offline
                    robi
                    wrote on last edited by
                    #8

                    Right, if Cloudron is no longer in control of a domain, switch that domain to manual or No-OP so all the other expected things don't keep failing.

                    Conscious tech

                    1 Reply Last reply
                    0
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search