Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Looping on DNS check

    Scheduled Pinned Locked Moved ACME
    2 Posts 2 Posters 155 Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      Nodiaque
      last edited by Nodiaque

      Hello,

      I just tried to manually start a renewal and on the gui, it simply timeout. Looking at the log, it seems to loop on a check at cloud-flare while I use duckdns:

      [Sat Jul 18 19:02:37 EDT 2026] Not valid yet, let's wait for 10 seconds then check the next one.
      [Sat Jul 18 19:02:37 EDT 2026] _p_txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:37 EDT 2026] Purging Cloudflare TXT record for domain _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:37 EDT 2026] POST
      [Sat Jul 18 19:02:37 EDT 2026] _post_url='https://cloudflare-dns.com/api/v1/purge?domain=_acme-challenge.###.duckdns.org&type=TXT'
      [Sat Jul 18 19:02:37 EDT 2026] body
      [Sat Jul 18 19:02:37 EDT 2026] _postContentType
      [Sat Jul 18 19:02:37 EDT 2026] Http already initialized.
      [Sat Jul 18 19:02:37 EDT 2026] _CURL='curl --silent --dump-header /tmp/acme/###.duckdns.org/http.header  -L  -g '
      [Sat Jul 18 19:02:37 EDT 2026] _ret='0'
      [Sat Jul 18 19:02:37 EDT 2026] response='{"msg":"purge request queued. Please wait a few seconds and verify the request was successful"}'
      [Sat Jul 18 19:02:40 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:40 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:40 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:40 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:40 EDT 2026] d='###.duckdns.org'
      [Sat Jul 18 19:02:40 EDT 2026] txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:40 EDT 2026] aliasDomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:40 EDT 2026] txt='######'
      [Sat Jul 18 19:02:40 EDT 2026] d_api='/usr/local/pkg/acme/dnsapi/dns_duckdns.sh'
      [Sat Jul 18 19:02:40 EDT 2026] Checking ###.duckdns.org for _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:40 EDT 2026] Already succeeded, continuing.
      [Sat Jul 18 19:02:40 EDT 2026] Let's wait for 10 seconds and check again.
      [Sat Jul 18 19:02:47 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:47 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:47 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:47 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:47 EDT 2026] d='###.duckdns.org'
      [Sat Jul 18 19:02:47 EDT 2026] txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:47 EDT 2026] aliasDomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:47 EDT 2026] txt='######'
      [Sat Jul 18 19:02:47 EDT 2026] d_api='/usr/local/pkg/acme/dnsapi/dns_duckdns.sh'
      [Sat Jul 18 19:02:47 EDT 2026] Checking ###.duckdns.org for _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:47 EDT 2026] Already succeeded, continuing.
      [Sat Jul 18 19:02:47 EDT 2026] Let's wait for 10 seconds and check again.
      [Sat Jul 18 19:02:50 EDT 2026] You can use '--dnssleep' to disable public dns checks.
      [Sat Jul 18 19:02:50 EDT 2026] See: https://github.com/acmesh-official/acme.sh/wiki/dnscheck
      [Sat Jul 18 19:02:50 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:50 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:50 EDT 2026] d='###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] aliasDomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] txt='########'
      [Sat Jul 18 19:02:50 EDT 2026] d_api='/usr/local/pkg/acme/dnsapi/dns_duckdns.sh'
      [Sat Jul 18 19:02:50 EDT 2026] Checking ###.duckdns.org for _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:50 EDT 2026] _c_txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] _c_aliasdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] _c_txt='########'
      [Sat Jul 18 19:02:50 EDT 2026] _ns_ep='https://cloudflare-dns.com/dns-query'
      [Sat Jul 18 19:02:50 EDT 2026] _ns_domain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:50 EDT 2026] _ns_type='TXT'
      [Sat Jul 18 19:02:50 EDT 2026] GET
      [Sat Jul 18 19:02:50 EDT 2026] url='https://cloudflare-dns.com/dns-query?name=_acme-challenge.###.duckdns.org&type=TXT'
      [Sat Jul 18 19:02:50 EDT 2026] timeout=
      [Sat Jul 18 19:02:50 EDT 2026] Http already initialized.
      [Sat Jul 18 19:02:50 EDT 2026] _CURL='curl --silent --dump-header /tmp/acme/###.duckdns.org/http.header  -L  -g '
      [Sat Jul 18 19:02:51 EDT 2026] ret='0'
      [Sat Jul 18 19:02:51 EDT 2026] response='{"Status":0,"TC":false,"RD":true,"RA":true,"AD":false,"CD":false,"Question":[{"name":"_acme-challenge.###.duckdns.org","type":16}],"Answer":[{"name":"_acme-challenge.###.duckdns.org","type":16,"TTL":60,"data":"\"######\""}]}'
      [Sat Jul 18 19:02:51 EDT 2026] _answers='"Answer":[
      "name":"_acme-challenge.###.duckdns.org","type":16,"TTL":60,"data":"\"######\""
      ]'
      [Sat Jul 18 19:02:51 EDT 2026] Not valid yet, let's wait for 10 seconds then check the next one.
      [Sat Jul 18 19:02:51 EDT 2026] _p_txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:51 EDT 2026] Purging Cloudflare TXT record for domain _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:51 EDT 2026] POST
      [Sat Jul 18 19:02:51 EDT 2026] _post_url='https://cloudflare-dns.com/api/v1/purge?domain=_acme-challenge.###.duckdns.org&type=TXT'
      [Sat Jul 18 19:02:51 EDT 2026] body
      [Sat Jul 18 19:02:51 EDT 2026] _postContentType
      [Sat Jul 18 19:02:51 EDT 2026] Http already initialized.
      [Sat Jul 18 19:02:51 EDT 2026] _CURL='curl --silent --dump-header /tmp/acme/###.duckdns.org/http.header  -L  -g '
      [Sat Jul 18 19:02:51 EDT 2026] _ret='0'
      [Sat Jul 18 19:02:51 EDT 2026] response='{"msg":"purge request queued. Please wait a few seconds and verify the request was successful"}'
      [Sat Jul 18 19:02:57 EDT 2026] You can use '--dnssleep' to disable public dns checks.
      [Sat Jul 18 19:02:57 EDT 2026] See: https://github.com/acmesh-official/acme.sh/wiki/dnscheck
      [Sat Jul 18 19:02:57 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:57 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] _idn_temp
      [Sat Jul 18 19:02:57 EDT 2026] d='###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] aliasDomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] txt='########'
      [Sat Jul 18 19:02:57 EDT 2026] d_api='/usr/local/pkg/acme/dnsapi/dns_duckdns.sh'
      [Sat Jul 18 19:02:57 EDT 2026] Checking ###.duckdns.org for _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:57 EDT 2026] _c_txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] _c_aliasdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] _c_txt='########'
      [Sat Jul 18 19:02:57 EDT 2026] _ns_ep='https://cloudflare-dns.com/dns-query'
      [Sat Jul 18 19:02:57 EDT 2026] _ns_domain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:57 EDT 2026] _ns_type='TXT'
      [Sat Jul 18 19:02:57 EDT 2026] GET
      [Sat Jul 18 19:02:57 EDT 2026] url='https://cloudflare-dns.com/dns-query?name=_acme-challenge.###.duckdns.org&type=TXT'
      [Sat Jul 18 19:02:57 EDT 2026] timeout=
      [Sat Jul 18 19:02:57 EDT 2026] Http already initialized.
      [Sat Jul 18 19:02:57 EDT 2026] _CURL='curl --silent --dump-header /tmp/acme/###.duckdns.org/http.header  -L  -g '
      [Sat Jul 18 19:02:57 EDT 2026] ret='0'
      [Sat Jul 18 19:02:57 EDT 2026] response='{"Status":0,"TC":false,"RD":true,"RA":true,"AD":false,"CD":false,"Question":[{"name":"_acme-challenge.###.duckdns.org","type":16}],"Answer":[{"name":"_acme-challenge.###.duckdns.org","type":16,"TTL":60,"data":"\"######\""}]}'
      [Sat Jul 18 19:02:57 EDT 2026] _answers='"Answer":[
      "name":"_acme-challenge.###.duckdns.org","type":16,"TTL":60,"data":"\"######\""
      ]'
      [Sat Jul 18 19:02:58 EDT 2026] Not valid yet, let's wait for 10 seconds then check the next one.
      [Sat Jul 18 19:02:58 EDT 2026] _p_txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:02:58 EDT 2026] Purging Cloudflare TXT record for domain _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:02:58 EDT 2026] POST
      [Sat Jul 18 19:02:58 EDT 2026] _post_url='https://cloudflare-dns.com/api/v1/purge?domain=_acme-challenge.###.duckdns.org&type=TXT'
      [Sat Jul 18 19:02:58 EDT 2026] body
      [Sat Jul 18 19:02:58 EDT 2026] _postContentType
      [Sat Jul 18 19:02:58 EDT 2026] Http already initialized.
      [Sat Jul 18 19:02:58 EDT 2026] _CURL='curl --silent --dump-header /tmp/acme/###.duckdns.org/http.header  -L  -g '
      [Sat Jul 18 19:02:58 EDT 2026] _ret='0'
      [Sat Jul 18 19:02:58 EDT 2026] response='{"msg":"purge request queued. Please wait a few seconds and verify the request was successful"}'
      [Sat Jul 18 19:03:01 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:03:01 EDT 2026] _idn_temp
      [Sat Jul 18 19:03:01 EDT 2026] _is_idn_d='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:03:01 EDT 2026] _idn_temp
      [Sat Jul 18 19:03:01 EDT 2026] d='###.duckdns.org'
      [Sat Jul 18 19:03:01 EDT 2026] txtdomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:03:01 EDT 2026] aliasDomain='_acme-challenge.###.duckdns.org'
      [Sat Jul 18 19:03:01 EDT 2026] txt='######'
      [Sat Jul 18 19:03:01 EDT 2026] d_api='/usr/local/pkg/acme/dnsapi/dns_duckdns.sh'
      [Sat Jul 18 19:03:01 EDT 2026] Checking ###.duckdns.org for _acme-challenge.###.duckdns.org
      [Sat Jul 18 19:03:01 EDT 2026] Already succeeded, continuing.
      [Sat Jul 18 19:03:01 EDT 2026] Let's wait for 10 seconds and check again.
      

      It used to work fine, I don't get why it's not working currently

      edit: What's weird is I have another certificate request using the same duckdns account but another dns name and this one work no problem

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Offline
        Gertjan @Nodiaque
        last edited by

        @Nodiaque

        As said here :

        fde87c33-9005-431d-88cc-e81e13a84dbe-image.png

        when you set DNS Sleep to nothing, or '0', acme.sh will poll every 10 seconds the TXT records using a pre determined (cloudflare or another oine, hard coded into acme.sh?) if these TXT records are set to the correct 'challenge' values.
        If they aren't not correct yet, it will reloop.
        Not indefinitely, it will do so 20x max, if I recall, and then it times out.
        I do remember : wasn't there a counter in the acme.sh log ??

        The thing is : acme.sh updates the TXT challenge records on the DNS domain master server.
        Then, the DNS master will signal the DNS slave(s) that that is a zone update available.
        The salve(s) will contact back the DNS domain master 'whenever it sees fit' to execute the update/zone sync.
        There is not rule that says : the salve will update/sync with the master with xxxx seconds.
        That's why "DNS Sleep" has to be determined by 'test and trail'.
        20 x 10 seconds = 200 seconds max is the max delay when using "DNS Sleep = 0".
        And there is another condition : DNS needs to work. Not the ordinary DNS, but the DoH or DoT one, as acme.sh uses one of these to do secure DNS challenge testing.
        ( I had these blocked with pfBlockerng, so DNS Sleep set to zero never worked for me, took me a long time to find this out, that it was of my own doing)
        In the past, when I used 'public' domain name servers (like duckdns) it would take even more time then that, and had to set DNS Sleep to 600 = 10 minutes. After all, these DNS servers have millions of domain name (zones) to sync all the time, so they tend to be a bit 'overworked'.

        No "help me" PM's please. Use the forum, the community will thank you.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.
        Privacy Policy · Cookie Policy