• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Acme DNS-NSupdate / RFC 2136 issue

Scheduled Pinned Locked Moved ACME
53 Posts 5 Posters 6.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dansgul
    last edited by Aug 6, 2019, 1:12 AM

    Hi,
    Many thnkas for the feedback.

    In the GUI, I have set the Zone section to the correct zone (cnet.sgul.ac.uk)

    acme.PNG

    On the shell on pfSense

    [2.4.4-RELEASE][admin@pfSense.localdomain]/tmp/acme/testing: nsupdate -v -k /tmp/acme/testing/login.cnet.sgul.ac.uknsupdate_acme-challenge.login.cnet.sgul.ac.uk.key
    > server 194.82.51.2
    > zone cnet.sgul.ac.uk
    > update add fiddy.cnet.sgul.ac.uk 3600 a 10.10.10.50
    > update add fiddy.cnet.sgul.ac.uk 3600 txt fiddy text
    > send
    > quit
    > 
    
    [2.4.4-RELEASE][admin@pfSense.localdomain]/tmp/acme/testing: dig fiddy.cnet.sgul.ac.uk txt @194.82.51.2
    
    ; <<>> DiG 9.12.2-P1 <<>> fiddy.cnet.sgul.ac.uk txt @194.82.51.2
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 56306
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
    
    ;; OPT PSEUDOSECTION:
    ; EDNS: version: 0, flags:; udp: 1452
    ;; QUESTION SECTION:
    ;fiddy.cnet.sgul.ac.uk.         IN      TXT
    
    ;; ANSWER SECTION:
    fiddy.cnet.sgul.ac.uk.  3484    IN      TXT     "fiddy" "text"
    
    ;; Query time: 4 msec
    ;; SERVER: 194.82.51.2#53(194.82.51.2)
    ;; WHEN: Tue Aug 06 00:07:39 UTC 2019
    ;; MSG SIZE  rcvd: 73
    
    

    Interestingly, If I omit the "-v" from nsupdate it fails

    [2.4.4-RELEASE][admin@pfSense.localdomain]/tmp/acme/testing: nsupdate -k /tmp/acme/testing/login.cnet.sgul.ac.uknsupdate_acme-challenge.login.cnet.sgul.ac.uk.key
    > server 194.82.51.2
    > zone cnet.sgul.ac.uk
    > update add fiddy1.cnet.sgul.ac.uk 3600 a 10.10.10.51
    > send
    ; TSIG error with server: expected a TSIG or SIG(0)
    update failed: SERVFAIL
    > quit
    
    
    1 Reply Last reply Reply Quote 0
    • D
      dansgul @dansgul
      last edited by Aug 6, 2019, 2:07 PM

      @dansgul

      More info on this

      It appears accountconf.conf contains an NULL NSUPDATE_ZONE (and is overwritten by dns_nsupdate.sh)

      ACME_DIRECTORY='https://acme-v01.api.letsencrypt.org/directory'
      ACCOUNT_EMAIL=xxxxxxxx'
      LOG_FILE='/tmp/acme/testing/acme_issuecert.log'
      LOG_LEVEL='3'
      NSUPDATE_SERVER='login.cnet.sgul.ac.uk'
      NSUPDATE_SERVER_PORT=''
      NSUPDATE_KEY='/tmp/acme/testing/login.cnet.sgul.ac.uknsupdate_acme-challenge.login.cnet.sgul.ac.uk.key'
      NSUPDATE_ZONE=''
      

      If I set THISNSUPDATE_ZONE at the top of /usr/local/pkg/acme/dnsapi/dns_nsupdate.sh it can issue a cert

      G 1 Reply Last reply Aug 6, 2019, 2:59 PM Reply Quote 0
      • G
        Gertjan @dansgul
        last edited by Gertjan Aug 6, 2019, 2:59 PM Aug 6, 2019, 2:59 PM

        @dansgul said in Acme DNS-NSupdate / RFC 2136 issue:

        THISNSUPDATE_ZONE

        I've looked for this one before.
        It's used before its initialized, so that explains :

        @dansgul said in Acme DNS-NSupdate / RFC 2136 issue:

        It appears accountconf.conf contains an NULL NSUPDATE_ZONE (and is overwritten by dns_nsupdate.s

        very well.

        Better yet : can't find "THISNSUPDATE_ZONE" here https://github.com/Neilpang/acme.sh/blob/master/dnsapi/dns_nsupdate.sh

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • J
          jimp Rebel Alliance Developer Netgate
          last edited by Aug 6, 2019, 3:43 PM

          Are you on the latest version of the ACME package? There was a bug with that a while back IIRC.

          The THISNSUPDATE_<x> stuff is just in pfSense. The stock files from acme.sh don't easily support multiple RFC2136 entries on a single cert the way pfSense uses them.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          G 1 Reply Last reply Aug 6, 2019, 3:51 PM Reply Quote 0
          • G
            Gertjan @jimp
            last edited by Aug 6, 2019, 3:51 PM

            @jimp said in Acme DNS-NSupdate / RFC 2136 issue:

            Are you on the latest version of the ACME package? There was a bug with that a while back IIRC.

            1b14debe-a30c-4b9b-8f70-330f7b8cb40a-image.png

            The THISNSUPDATE_<x> stuff is just in pfSense. The stock files from acme.sh don't easily support multiple RFC2136 entries on a single cert the way pfSense uses them.

            Ah, ok.
            Have a look at this "THISNSUPDATE_ZONE" in dnsapi/dns_nsupdate.sh - shouldnt it be init (= read) before used and written ?

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 0
            • J
              jimp Rebel Alliance Developer Netgate
              last edited by Aug 6, 2019, 3:52 PM

              Yeah, I thought it was but I'm not seeing it now, either. I'll look into it.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 1
              • J
                jimp Rebel Alliance Developer Netgate
                last edited by Aug 6, 2019, 8:48 PM

                I just pushed a new version of ACME that should fix this. Give it a try when it shows up for you (0.6)

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 1
                • G
                  Gertjan
                  last edited by Aug 7, 2019, 3:07 PM

                  Saw it.
                  Tested !
                  Worked !

                  👍

                  No "help me" PM's please. Use the forum, the community will thank you.
                  Edit : and where are the logs ??

                  1 Reply Last reply Reply Quote 0
                  • D
                    dansgul
                    last edited by Aug 7, 2019, 4:28 PM

                    Hi there, this still isn't working for me; I've upgraded to 0.6
                    I still see "NSUPDATE_ZONE" as empty and the issue fails. (I know our DNS server needs to have the zone sent for this to work)

                    [Wed Aug  7 17:23:39 BST 2019] d='login.cnet.sgul.ac.uk'
                    [Wed Aug  7 17:23:39 BST 2019] _d_alias
                    [Wed Aug  7 17:23:39 BST 2019] txtdomain='_acme-challenge.login.cnet.sgul.ac.uk'
                    [Wed Aug  7 17:23:39 BST 2019] base64 single line.
                    [Wed Aug  7 17:23:39 BST 2019] txt='_WaKP7V9YAEUOHv0Y6MJWEhq7KPImm7n8t6WcSwPqZE'
                    [Wed Aug  7 17:23:39 BST 2019] d_api='/usr/local/pkg/acme/dnsapi/dns_nsupdate.sh'
                    [Wed Aug  7 17:23:39 BST 2019] dns_entry='login.cnet.sgul.ac.uk,_acme-challenge.login.cnet.sgul.ac.uk,,dns_nsupdate,_WaKP7V9YAEUOHv0Y6MJWEhq7KPImm7n8t6WcSwPqZE,/usr/local/pkg/acme/dnsapi/dns_nsupdate.sh'
                    [Wed Aug  7 17:23:39 BST 2019] Found domain api file: /usr/local/pkg/acme/dnsapi/dns_nsupdate.sh
                    [Wed Aug  7 17:23:39 BST 2019] dns_nsupdate_add exists=0
                    [Wed Aug  7 17:23:39 BST 2019] Adding txt value: _WaKP7V9YAEUOHv0Y6MJWEhq7KPImm7n8t6WcSwPqZE for domain:  _acme-challenge.login.cnet.sgul.ac.uk
                    [Wed Aug  7 17:23:39 BST 2019] APP
                    [Wed Aug  7 17:23:39 BST 2019] 5:NSUPDATE_SERVER='ns1.sgul.ac.uk'
                    [Wed Aug  7 17:23:39 BST 2019] APP
                    [Wed Aug  7 17:23:39 BST 2019] 6:NSUPDATE_SERVER_PORT=''
                    [Wed Aug  7 17:23:39 BST 2019] APP
                    [Wed Aug  7 17:23:39 BST 2019] 7:NSUPDATE_KEY='/tmp/acme/testing/login.cnet.sgul.ac.uknsupdate_acme-challenge.login.cnet.sgul.ac.uk.key'
                    [Wed Aug  7 17:23:39 BST 2019] APP
                    [Wed Aug  7 17:23:39 BST 2019] 8:NSUPDATE_ZONE=''
                    [Wed Aug  7 17:23:39 BST 2019] adding _acme-challenge.login.cnet.sgul.ac.uk. 60 in txt "_WaKP7V9YAEUOHv0Y6MJWEhq7KPImm7n8t6WcSwPqZE"
                    [Wed Aug  7 17:23:39 BST 2019] error updating domain
                    [Wed Aug  7 17:23:39 BST 2019] Error add txt for domain:_acme-challenge.login.cnet.sgul.ac.uk
                    [Wed Aug  7 17:23:39 BST 2019] _on_issue_err
                    
                    
                    1 Reply Last reply Reply Quote 0
                    • J
                      jimp Rebel Alliance Developer Netgate
                      last edited by Aug 7, 2019, 6:19 PM

                      OK, I missed a couple bits. I just pushed ACME pkg v 0.6.2 which should work now. I didn't test it completely but I did confirm at least that the zone makes it into the account config and logs where it was missing before.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • D
                        dansgul
                        last edited by Aug 8, 2019, 8:22 AM

                        Working now after upgrade to 0.6.2

                        Many thanks jimp!

                        1 Reply Last reply Reply Quote 1
                        • N NollipfSense referenced this topic on Feb 16, 2022, 3:51 AM
                        • N NollipfSense referenced this topic on Feb 17, 2022, 1:35 AM
                        • N NollipfSense referenced this topic on Feb 18, 2022, 7:53 PM
                        • V
                          VioletDragon
                          last edited by Aug 31, 2024, 5:48 PM

                          The problem is still present in the latest version. 0.8_1.

                          Failures on expected a TSIG or SIG(0) even though it's implemented.

                          Regards

                          G 1 Reply Last reply Sep 1, 2024, 11:07 AM Reply Quote 0
                          • G
                            Gertjan @VioletDragon
                            last edited by Sep 1, 2024, 11:07 AM

                            @VioletDragon

                            Humm. I'm using 'nsupdate' = DNS-NSupdate / RFC 2136.
                            Works just fine.

                            nsupdate didn't change for years.

                            No "help me" PM's please. Use the forum, the community will thank you.
                            Edit : and where are the logs ??

                            V 2 Replies Last reply Sep 1, 2024, 11:09 AM Reply Quote 0
                            • V
                              VioletDragon @Gertjan
                              last edited by Sep 1, 2024, 11:09 AM

                              @Gertjan are you using BIND9?

                              G 1 Reply Last reply Sep 1, 2024, 11:15 AM Reply Quote 0
                              • V
                                VioletDragon @Gertjan
                                last edited by Sep 1, 2024, 11:10 AM

                                @Gertjan are you using BIND9?

                                G 1 Reply Last reply Sep 1, 2024, 11:25 AM Reply Quote 0
                                • G
                                  Gertjan @VioletDragon
                                  last edited by Sep 1, 2024, 11:15 AM

                                  @VioletDragon said in Acme DNS-NSupdate / RFC 2136 issue:

                                  @Gertjan are you using BIND9?

                                  Yes.

                                  No "help me" PM's please. Use the forum, the community will thank you.
                                  Edit : and where are the logs ??

                                  V 1 Reply Last reply Sep 1, 2024, 11:16 AM Reply Quote 0
                                  • V
                                    VioletDragon @Gertjan
                                    last edited by Sep 1, 2024, 11:16 AM

                                    @Gertjan could you post your config?

                                    1 Reply Last reply Reply Quote 0
                                    • G
                                      Gertjan @VioletDragon
                                      last edited by Sep 1, 2024, 11:25 AM

                                      @VioletDragon said in Acme DNS-NSupdate / RFC 2136 issue:

                                      @Gertjan are you using BIND9?

                                      Yes.
                                      Debian 11.10... no .11 just right now.

                                      f006a373-d89b-4123-8d18-b632508f9d56-image.png

                                      I can't re test my acme renewal, as I'm in the grace period : a renewal will work and no DNS checks will be done.

                                      But : I'm also using RFC2136 for my pfSense WAN side host name = DynDNS.

                                      Logs on server = bind9 side :

                                      01-Sep-2024 13:21:27.416 update-security: client @0x7f4884148ed0 82.127.99.108#59810/key update: signer "update" approved
                                      01-Sep-2024 13:21:27.416 update: client @0x7f4884148ed0 82.127.26.108#59810/key update: updating zone 'bhf.tld/IN': deleting rrset at 'home.bhf.tld' A
                                      01-Sep-2024 13:21:27.416 update: client @0x7f4884148ed0 82.127.26.108#59810/key update: updating zone 'bhf.tld/IN': adding an RR at 'home.bhf.tld' A 82.135.26.118
                                      01-Sep-2024 13:21:27.416 update: client @0x7f4884148ed0 82.127.26.108#59810/key update: updating zone 'bhf.tld/IN': deleting rrset at 'home.bhf.tld' AAAA
                                      01-Sep-2024 13:21:27.416 update: client @0x7f4884148ed0 82.127.26.108#59810/key update: updating zone 'bhf.tld/IN': adding an RR at 'home.bhf.tld' AAAA 2a01:cb19:beef:dead:92ec:77ff:fe29:392a
                                      

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      V 2 Replies Last reply Sep 1, 2024, 11:28 AM Reply Quote 0
                                      • V
                                        VioletDragon @Gertjan
                                        last edited by Sep 1, 2024, 11:28 AM

                                        @Gertjan how did you set it up? As I got it working with Certbot but not Acme.

                                        1 Reply Last reply Reply Quote 0
                                        • V
                                          VioletDragon @Gertjan
                                          last edited by Sep 1, 2024, 3:16 PM

                                          @Gertjan Problem seems to be with the acme.sh package, works fine with Certbot with the HMAC key but Acme seems to be ignoring the Key whether you put the key in or not.

                                          Error that keeps showing dns_request_getresponse: expected a TSIG or SIG(0)

                                          same happens with acme.sh on a fresh install of BSD so i think the package is broken.

                                          G 1 Reply Last reply Sep 1, 2024, 4:30 PM Reply Quote 0
                                          22 out of 53
                                          • First post
                                            22/53
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received