root@acmesh01:/home/acmeadmin# acme.sh --set-default-ca --server https://acmeserver01.acmelab.sec.internal/directory --issue --dns dns_acmedns -d acmesh01dup.acmelab.sec.internal -d '*.acmesh01dup.acmelab.sec.internal' -k 2048 --force [Thu Apr 11 16:49:29 UTC 2024] Using CA: https://acmeserver01.acmelab.sec.internal/directory [Thu Apr 11 16:49:29 UTC 2024] Multi domain='DNS:acmesh01dup.acmelab.sec.internal,DNS:*.acmesh01dup.acmelab.sec.internal' [Thu Apr 11 16:49:31 UTC 2024] Getting webroot for domain='acmesh01dup.acmelab.sec.internal' [Thu Apr 11 16:49:31 UTC 2024] Getting webroot for domain='*.acmesh01dup.acmelab.sec.internal' [Thu Apr 11 16:49:31 UTC 2024] Adding txt value: 2vZiwaeVGTXH5dlqlNp7zxfsTOZa2NpJHeicHr9TpXo for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:49:31 UTC 2024] Using acme-dns [Thu Apr 11 16:49:31 UTC 2024] The txt record is added: Success. [Thu Apr 11 16:49:31 UTC 2024] Adding txt value: FuQs3wYkePoNrE3pk1r8Tr02aIJYwGeiR5lK9P4jGPA for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:49:31 UTC 2024] Using acme-dns [Thu Apr 11 16:49:32 UTC 2024] The txt record is added: Success. [Thu Apr 11 16:49:32 UTC 2024] Let's check each DNS record now. Sleep 20 seconds first. [Thu Apr 11 16:49:35 UTC 2024] Verifying: acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:49:36 UTC 2024] Success [Thu Apr 11 16:49:36 UTC 2024] Verifying: *.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:49:36 UTC 2024] Success [Thu Apr 11 16:49:36 UTC 2024] Removing DNS records. [Thu Apr 11 16:49:36 UTC 2024] Removing txt: 2vZiwaeVGTXH5dlqlNp7zxfsTOZa2NpJHeicHr9TpXo for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:49:36 UTC 2024] Using acme-dns [Thu Apr 11 16:49:36 UTC 2024] Removed: Success [Thu Apr 11 16:49:36 UTC 2024] Removing txt: FuQs3wYkePoNrE3pk1r8Tr02aIJYwGeiR5lK9P4jGPA for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:49:36 UTC 2024] Using acme-dns [Thu Apr 11 16:49:36 UTC 2024] Removed: Success [Thu Apr 11 16:49:36 UTC 2024] Verify finished, start to sign. [Thu Apr 11 16:49:36 UTC 2024] Lets finalize the order. [Thu Apr 11 16:49:36 UTC 2024] Le_OrderFinalize='https://acmeserver01.acmelab.sec.internal/acme/order/ufRSmkY6lb24/finalize' [Thu Apr 11 16:49:42 UTC 2024] Order status is processing, lets sleep and retry. [Thu Apr 11 16:49:42 UTC 2024] Retry after: 15 [Thu Apr 11 16:49:58 UTC 2024] Polling order status: https://acmeserver01.acmelab.sec.internal/acme/order/ufRSmkY6lb24 [Thu Apr 11 16:49:58 UTC 2024] Sign error, wrong status [Thu Apr 11 16:49:58 UTC 2024] {"status":"invalid", "expires":"2024-04-12T16:49:30Z", "identifiers":[{"type":"dns", "value":"acmesh01dup.acmelab.sec.internal"}, {"type":"dns", "value":"*.acmesh01dup.acmelab.sec.internal"}], "authorizations":["https://acmeserver01.acmelab.sec.internal/acme/authz/Z3QaBQbgJlc1", "https://acmeserver01.acmelab.sec.internal/acme/authz/qhrJEzeidrDt"], "finalize":"https://acmeserver01.acmelab.sec.internal/acme/order/ufRSmkY6lb24/finalize"} [Thu Apr 11 16:49:58 UTC 2024] Please add '--debug' or '--log' to check more details. [Thu Apr 11 16:49:58 UTC 2024] See: https://github.com/acmesh-official/acme.sh/wiki/How-to-debug-acme.sh root@acmesh01:/home/acmeadmin# acme.sh --set-default-ca --server https://acmeserver01.acmelab.sec.internal/directory --issue --dns dns_acmedns -d acmesh01dup.acmelab.sec.internal -d '*.acmesh01dup.acmelab.sec.internal' -k 2048 --force [Thu Apr 11 16:50:00 UTC 2024] Using CA: https://acmeserver01.acmelab.sec.internal/directory [Thu Apr 11 16:50:00 UTC 2024] Multi domain='DNS:acmesh01dup.acmelab.sec.internal,DNS:*.acmesh01dup.acmelab.sec.internal' [Thu Apr 11 16:50:02 UTC 2024] Getting webroot for domain='acmesh01dup.acmelab.sec.internal' [Thu Apr 11 16:50:02 UTC 2024] Getting webroot for domain='*.acmesh01dup.acmelab.sec.internal' [Thu Apr 11 16:50:02 UTC 2024] Adding txt value: f4AksR2FoBGkvxoiHj68IP7b1hrj4hFR-Bb2-ljOF3w for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:50:02 UTC 2024] Using acme-dns [Thu Apr 11 16:50:03 UTC 2024] The txt record is added: Success. [Thu Apr 11 16:50:03 UTC 2024] Adding txt value: OhS7OS5q8nboRq59Aev836RcyIPOKF5seUuJrUfdOo0 for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:50:03 UTC 2024] Using acme-dns [Thu Apr 11 16:50:03 UTC 2024] The txt record is added: Success. [Thu Apr 11 16:50:03 UTC 2024] Let's check each DNS record now. Sleep 20 seconds first. [Thu Apr 11 16:50:06 UTC 2024] Verifying: acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:50:07 UTC 2024] Success [Thu Apr 11 16:50:07 UTC 2024] Verifying: *.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:50:08 UTC 2024] Success [Thu Apr 11 16:50:08 UTC 2024] Removing DNS records. [Thu Apr 11 16:50:08 UTC 2024] Removing txt: f4AksR2FoBGkvxoiHj68IP7b1hrj4hFR-Bb2-ljOF3w for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:50:08 UTC 2024] Using acme-dns [Thu Apr 11 16:50:08 UTC 2024] Removed: Success [Thu Apr 11 16:50:08 UTC 2024] Removing txt: OhS7OS5q8nboRq59Aev836RcyIPOKF5seUuJrUfdOo0 for domain: _acme-challenge.acmesh01dup.acmelab.sec.internal [Thu Apr 11 16:50:08 UTC 2024] Using acme-dns [Thu Apr 11 16:50:08 UTC 2024] Removed: Success [Thu Apr 11 16:50:08 UTC 2024] Verify finished, start to sign. [Thu Apr 11 16:50:08 UTC 2024] Lets finalize the order. [Thu Apr 11 16:50:08 UTC 2024] Le_OrderFinalize='https://acmeserver01.acmelab.sec.internal/acme/order/mKMkQf9fcebG/finalize' [Thu Apr 11 16:50:08 UTC 2024] Downloading cert. [Thu Apr 11 16:50:08 UTC 2024] Le_LinkCert='https://acmeserver01.acmelab.sec.internal/acme/cert/xVPClDepQi5t' [Thu Apr 11 16:50:09 UTC 2024] Cert success. -----BEGIN CERTIFICATE----- MIIFTTCCBDWgAwIBAgITagAAADnGTW1gl4kKsgAAAAAAOTANBgkqhkiG9w0BAQsF ADCBnDETMBEGCgmSJomT8ixkARkWA2NvbTETMBEGCgmSJomT8ixkARkWA3NlczEY MBYGCgmSJomT8ixkARkWCGludGVybmFsMRMwEQYKCZImiZPyLGQBGRYDc2VjMRcw FQYKCZImiZPyLGQBGRYHYWNtZWxhYjEoMCYGA1UEAxMfQUNNRVRFU1QtU0VTSW50 ZXJuYWxJc3N1aW5nQ0EwMTAeFw0yNDA0MTExNjQwMDhaFw0yNjA0MTExNjQwMDha MDMxMTAvBgNVBAMTKGFjbWVzaDAxZHVwLmFjbWVsYWIuc2VjLmludGVybmFsLnNl cy5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCUQryWMRnHCZwL zT3+hgx2RbYusUMbyKtWLW9c/SDjoYkLU8lu01Qj6SSfacfAaH5Ux8f7oREx2eeG 7Z8dZWalIBMdxlwd1QitHRzzSK3pcD34ZBH0Ug+mCv5KQeY8rcfHS8o7Hcof9gbG DAUiuj3nTKIDk0B4sYIAfewGYeMi/xFsL5m032RQ3Z2sJC6TSng3YDyA+HC7krUG FEoXaFjaX8/+V1+vfdXq7INmHZSiExqBV7jkJYnP3s4gh7yoxK6bYawAgq3Lf9o6 CDijez9v+f+okWaGtT69UP6mCiG5NG+CqAcIQkWShhP/vxweF1mP+iYa2EpfAV12 /md1pu7tAgMBAAGjggHuMIIB6jATBgNVHSUEDDAKBggrBgEFBQcDATBfBgNVHREE WDBWgihhY21lc2gwMWR1cC5hY21lbGFiLnNlYy5pbnRlcm5hbC5zZXMuY29tgioq LmFjbWVzaDAxZHVwLmFjbWVsYWIuc2VjLmludGVybmFsLnNlcy5jb20wHQYDVR0O me29RmpNhKU1MFwGA1UdHwRVMFMwUaBPoE2GS2h0dHA6Ly9wa2kuYWNtZWxhYi5z ZWMuaW50ZXJuYWwuc2VzLmNvbS9BQ01FVEVTVC1TRVNJbnRlcm5hbElzc3VpbmdD QTAxLmNybDBnBggrBgEFBQcBAQRbMFkwVwYIKwYBBQUHMAKGS2h0dHA6Ly9wa2ku YWNtZWxhYi5zZWMuaW50ZXJuYWwuc2VzLmNvbS9BQ01FVEVTVC1TRVNJbnRlcm5h bElzc3VpbmdDQTAxLmNydDAOBgNVHQ8BAf8EBAMCBaAwPgYJKwYBBAGCNxUHBDEw LwYnKwYBBAGCNxUIh6SWJ4GD/U6HhYM0g/3JJIHI8kOBCoOJ+x+C36ZtAgFkAgED MBsGCSsGAQQBgjcVCgQOMAwwCgYIKwYBBQUHAwEwDQYJKoZIhvcNAQELBQADggEB AFm+MmcKzDWoOh1IuTv9SItHdRNjdWwa55NNPQSJYBRtclzFs4cTGuXh6m4k3DOE 2pGETkO+vuoZhhfzolIU+BNpPAXFnD6ujO4Xpek/ZoAHkcmTK1lHPpsFMaCM9Ali AmHDm7FMDcT3Iz4qa46ZQi2e2IP4AM4KaRqm5MSOHn1aDRIj4VbhS64s7EnNGczc lCppaU/6sH6tpbf8ekR3D8gMz0nYwuEeoU65e+1TVn5rsS/lc2k39QbIei37ku4/ a2/rnYFbHffoXQes85DdjGgOL2uS77BHxWoBBkULWOnnov9RhWJOEgOwoc0Q3aBl Vw0lpJMBBsQzs6X1fqSgDs0= -----END CERTIFICATE----- [Thu Apr 11 16:50:09 UTC 2024] Your cert is in: /root/.acme.sh/acmesh01dup.acmelab.sec.internal/acmesh01dup.acmelab.sec.internal.cer [Thu Apr 11 16:50:09 UTC 2024] Your cert key is in: /root/.acme.sh/acmesh01dup.acmelab.sec.internal/acmesh01dup.acmelab.sec.internal.key [Thu Apr 11 16:50:09 UTC 2024] The intermediate CA cert is in: /root/.acme.sh/acmesh01dup.acmelab.sec.internal/ca.cer [Thu Apr 11 16:50:09 UTC 2024] And the full chain certs is there: /root/.acme.sh/acmesh01dup.acmelab.sec.internal/fullchain.cer root@acmesh01:/home/acmeadmin# root@acmesh01:/home/acmeadmin# root@acmesh01:/home/acmeadmin# root@acmesh01:/home/acmeadmin#