We have a VPS running CPanel 110.0.2 on Apache. We use Let's Encrypt with AutoSSL. DNS is done by another server at another provider.
It's been working fine for a few years. As of a couple of months ago, we started getting error messages related to SSL certificate renewal. The error is "DNS DCV: No local authority: “*.example.com”. The error is only occurring on the wildcard entry. The entries for example.com and www.example.com are working fine and renew as expected. (Mail is not handled by this web server).
After checking in SSL/TLS Status, I see that I can exclude certain entries from the AutoSSL process. This would work for us as we don't need wildcard domain coverage for this domain. However, there is no option to EXCLUDE the wild card entry. I can exclude any other entry in the list, but not the wildcard. There's no checkbox.
Another solution that would work for us would be to make the certificate issuance for the wildcard work. Let's Encrypt says it will, but it fails with the above error. I've tried running it manually but it still fails.
Ideas? Some way to manually remove the wildcard entry from the AutoSSL list? Some way to get it to properly renew?
It's been working fine for a few years. As of a couple of months ago, we started getting error messages related to SSL certificate renewal. The error is "DNS DCV: No local authority: “*.example.com”. The error is only occurring on the wildcard entry. The entries for example.com and www.example.com are working fine and renew as expected. (Mail is not handled by this web server).
After checking in SSL/TLS Status, I see that I can exclude certain entries from the AutoSSL process. This would work for us as we don't need wildcard domain coverage for this domain. However, there is no option to EXCLUDE the wild card entry. I can exclude any other entry in the list, but not the wildcard. There's no checkbox.
Another solution that would work for us would be to make the certificate issuance for the wildcard work. Let's Encrypt says it will, but it fails with the above error. I've tried running it manually but it still fails.
Ideas? Some way to manually remove the wildcard entry from the AutoSSL list? Some way to get it to properly renew?
Last edited by a moderator: