-
-
Notifications
You must be signed in to change notification settings - Fork 3.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
IPv6 doesn't work #180
Comments
BTW, if your hoster does not support IPv6 directly, but you have root access to the (virtual) machine, you can easily set up IPv6 via a tunnel: https://tunnelbroker.net/ |
John Gilmore asked that we test for support for IPv6-only hosts once Boulder is interoperable (i.e., a host which only has an AAAA record and not an A record). (I think that's potentially a further case from the one reported here.) I believe John is interested in the ability to get a cert on a web server that has no IPv4 service at all, or at the very least no associated A record that can be used to make an inbound TCP connection over IPv4. |
+1 - I'm running many machines w/ ipv6 only. |
+1 - Also running many IPv6-only hosts |
I have only ipv6 working resolve but somehow I was able to get an cert. I dont know how I did it, is there any record of what I did anywhere? |
+1 - I also have some IPv6-only hosts. Some hosting providers are also now proving lower-cost offerings for IPv6-only. |
+1 - many, many IPv6-only hosts and no letsencrypt. |
Blocked by: letsencrypt/boulder#593 |
Here IPv6 only webservers, can't validate the DNS thus no certificate. |
I have a number of IPv6-only environments that LetsEncrypt would allow me to deploy much-needed security to. Unfortunately this issue is preventing authentication for certs to be generated. Please add IPv6-only support! |
I run a dual-stack NATed IPv4 and IPv6 network so the only global IPs are available on IPv6, currently without IPv6 support I can't create certificates :( |
+1 I run many services on IPv6 only, because IPv4 address pools are depleted. |
+1 Kind of odd for a service like this to support legacy IP only ;) |
Indeed, letsencrypt fails to handle IPv6. Example here:
Of course, there is only an AAAA record for this domain; no A record:
|
Hey folks, the Let's Encrypt project is aware of this. We're currently hamstrung on the server-side because our network and DC provider doesn't give us a way to do IPv6 out to folks. We'll definitely be posting to the community site when we get IPv6 and its on our want list! Thanks for your interest! I'm going to close this up since its not a client bug, and lock it since we're already getting +1 spam. |
$ sudo ./venv/bin/letsencrypt -e -d myname.nsupdate.info -t
INFO:root:Generating key: /etc/apache2/ssl/key-letsencrypt_17.pem
INFO:root:Performing the following challenges:
INFO:root: DVSNI challenge for name myname.nsupdate.info.
INFO:root:Ready for verification...
INFO:root:Waiting for 3 seconds...
CRITICAL:root:Expected message (authorization) not received
CRITICAL:root:Failed Authorization procedure - cleaning up challenges
INFO:root:Cleaning up challenges for myname.nsupdate.info
tw@tux:~/w/lets-encrypt-preview$ host myname.nsupdate.info
myname.nsupdate.info has IPv6 address 2002:xxxx:xxxx:xxxx:xxxx:xxff:fexx:xxxx (only v6 in DNS!)
tw@tux:~/w/lets-encrypt-preview$ host letsencrypt-demo.org
letsencrypt-demo.org has address 54.183.196.250 (only v4 in DNS!)
note: myname.nsupdate.info has v4 and v6 connectivity.
So, not sure what's going wrong, but I think it would be good if you added a AAAA record for the ACME server (and also v6 connectivity in case it is not yet there).
Same thing worked if I put an A record into DNS.
The text was updated successfully, but these errors were encountered: