Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Letsencrypt renewal error due to Gandi DNS failing to be set using either API Token or PAT

Letsencrypt renewal error due to Gandi DNS failing to be set using either API Token or PAT

Scheduled Pinned Locked Moved Solved Support
gandidns
11 Posts 5 Posters 512 Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ruihildtR Offline
    ruihildtR Offline
    ruihildt
    wrote last edited by
    #2

    Now I'm starting to wonder when these other gandi domains are going to rotate their letsencrypt certificates and error out as well. 🥶

    1 Reply Last reply
    1
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote last edited by nebulon
      #3

      We have to debug this, for a start you can switch that domain over to manual and fixup the A record manually to point to the server's ip

      ruihildtR 1 Reply Last reply
      1
      • nebulonN nebulon

        We have to debug this, for a start you can switch that domain over to manual and fixup the A record manually to point to the server's ip

        ruihildtR Offline
        ruihildtR Offline
        ruihildt
        wrote last edited by
        #4

        @nebulon Ah right, since the domain was already pointing to the server, it immediately worked after retrying ththe failing task.

        1 Reply Last reply
        1
        • nebulonN Offline
          nebulonN Offline
          nebulon
          Staff
          wrote last edited by
          #5

          Since the token works in your CURL example, can you run that from the server itself to see if there might be some IP block/allowlist issue?

          ruihildtR 1 Reply Last reply
          1
          • J Offline
            J Offline
            joseph
            Staff
            wrote last edited by
            #6

            Does the token have read/write access to the domain? How did you create the token in Gandi?

            1 Reply Last reply
            1
            • nebulonN nebulon

              Since the token works in your CURL example, can you run that from the server itself to see if there might be some IP block/allowlist issue?

              ruihildtR Offline
              ruihildtR Offline
              ruihildt
              wrote last edited by
              #7

              @nebulon I can.

              But now I have created a token which can theoretically update all domains.

              But I'm starting to think it's Gandi who changed their permission model and actually, while maybe I can access through the UI to many domain where I've been added as a technical contact, it's possible that somehow that permissions still need to be added manually elsewhere.

              I'll contact Gandi support next week.

              1 Reply Last reply
              1
              • jdaviescoatesJ Online
                jdaviescoatesJ Online
                jdaviescoates
                wrote last edited by
                #8

                I'm interested to know what you discover because I use Gandi too...

                I use Cloudron with Gandi & Hetzner

                1 Reply Last reply
                1
                • J joseph has marked this topic as solved
                • S Offline
                  S Offline
                  SebGG
                  wrote last edited by SebGG
                  #9

                  Hi, today i had the same issue. Cloudron 9.1.5

                  What was the solution?

                  Benachrichtigungen
                  Domain ...... is not configured properly
                  vor 4 Stunden

                  Access denied: Gandi DNS error [403] {"object": "HTTPForbidden", "cause": "Forbidden", "code": 403, "message": "Access was denied to this resource."}

                  1 Reply Last reply
                  0
                  • J Offline
                    J Offline
                    joseph
                    Staff
                    wrote last edited by
                    #10

                    Have you tested if the token works? Check with curl and one of the API calls at https://api.gandi.net/docs/authentication/

                    1 Reply Last reply
                    0
                    • S Offline
                      S Offline
                      SebGG
                      wrote last edited by SebGG
                      #11

                      Got it, yes it was the token, i made a New one (PAT) and it seems that it works
                      Thanks

                      1 Reply Last reply
                      1

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search