Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Letsencrypt renewal error due to Gandi DNS failing to be set using either API Token or PAT

Letsencrypt renewal error due to Gandi DNS failing to be set using either API Token or PAT

Scheduled Pinned Locked Moved Unsolved Support
gandidns
6 Posts 3 Posters 34 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ruihildtR Offline
    ruihildtR Offline
    ruihildt
    wrote last edited by ruihildt
    #1

    Since I installed 9.1, I noticed 2 apps I used based on domains from Gandi were not restarting due to letsencrypt provisioning issues. Basically Cloudron can't connect to Gandi either using the legacy API token or the new PAT.

    Here's the error:

    Gandi DNS error [403] {"object": "HTTPForbidden", "cause": "Forbidden", "code": 403, "message": "Access was denied to this resource."} BoxError: Gandi DNS error [403] {"object": "HTTPForbidden", "cause": "Forbidden", "code": 403, "message": "Access was denied to this resource."}

    This also happens when I manually try to change those values directly in the Domains interface. (I tried the Gandi CURL example with the same token, so this is clearly not an error with the token)

    What can I do to fix this. I already have a customer complaining their website is down, and I seemingly can't do anything to fix this, since it's letsencrypt related.

    1 Reply Last reply
    1
    • ruihildtR ruihildt referenced this topic
    • ruihildtR Offline
      ruihildtR Offline
      ruihildt
      wrote last edited by
      #2

      Now I'm starting to wonder when these other gandi domains are going to rotate their letsencrypt certificates and error out as well. 🥶

      1 Reply Last reply
      1
      • nebulonN Away
        nebulonN Away
        nebulon
        Staff
        wrote last edited by nebulon
        #3

        We have to debug this, for a start you can switch that domain over to manual and fixup the A record manually to point to the server's ip

        ruihildtR 1 Reply Last reply
        1
        • nebulonN nebulon

          We have to debug this, for a start you can switch that domain over to manual and fixup the A record manually to point to the server's ip

          ruihildtR Offline
          ruihildtR Offline
          ruihildt
          wrote last edited by
          #4

          @nebulon Ah right, since the domain was already pointing to the server, it immediately worked after retrying ththe failing task.

          1 Reply Last reply
          1
          • nebulonN Away
            nebulonN Away
            nebulon
            Staff
            wrote last edited by
            #5

            Since the token works in your CURL example, can you run that from the server itself to see if there might be some IP block/allowlist issue?

            1 Reply Last reply
            1
            • J Online
              J Online
              joseph
              Staff
              wrote last edited by
              #6

              Does the token have read/write access to the domain? How did you create the token in Gandi?

              1 Reply Last reply
              1

              Hello! It looks like you're interested in this conversation, but you don't have an account yet.

              Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

              With your input, this post could be even better 💗

              Register Login
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • Bookmarks
              • Search