Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!

AutoSSL errors, not renewing certificate

Discussion in 'General Discussion' started by Volt55, May 30, 2018.

  1. Volt55

    Volt55 Member

    Joined:
    Feb 20, 2017
    Messages:
    8
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    UK
    cPanel Access Level:
    Root Administrator
    I have multiple Wordpress websites that are failing AutoSSL. Note that I am forcing SSL at Cloudflare.
    Code:
     6:47:07 PM Checking “example.com” …
     6:47:07 PM ERROR TLS Status: Defective
     ERROR Certificate expiry: 5/17/18, 12:00 AM UTC (13.74 days ago)
     ERROR Defect: OPENSSL_VERIFY: The certificate chain failed OpenSSL’s verification (0:10:CERT_HAS_EXPIRED).
     Redirection #1 (example.com): http://example.com/.well-known/pki-validation/00CAA51FED8AE75FC682E11F15104C22.txt → https://example.com/.well-known/pki-validation/00CAA51FED8AE75FC682E11F15104C22.txt
     WARN Local DCV error (example.com): “cPanel (powered by Comodo)” forbids DCV HTTP redirections.
     Redirection #1 (www.example.com): http://www.example.com/.well-known/pki-validation/64BA9F73A3A773EE10167625B24F8322.txt → https://www.example.com/.well-known/pki-validation/64BA9F73A3A773EE10167625B24F8322.txt
     WARN Local DCV error (www.example.com): “cPanel (powered by Comodo)” forbids DCV HTTP redirections.
     WARN Local DCV error (mail.example.com): “mail.example.com” does not resolve to any IPv4 addresses on the internet.
     WARN Local DCV error (webmail.example.com): “webmail.example.com” does not resolve to any IPv4 addresses on the internet.
     WARN Local DCV error (webmail.example.com): “webmail.example.com” does not resolve to any IPv4 addresses on the internet.
     6:47:08 PM WARN Local DCV error (cpanel.example.com): “cpanel.example.com” does not resolve to any IPv4 addresses on the internet.
     WARN Local DCV error (cpanel.example.com): “cpanel.example.com” does not resolve to any IPv4 addresses on the internet.
     6:47:12 PM WARN Local DCV error (webdisk.example.com): “webdisk.example.com” does not resolve to any IPv4 addresses on the internet.
     WARN Local DCV error (webdisk.example.com): “webdisk.example.com” does not resolve to any IPv4 addresses on the internet.
     ERROR Impediment: TOTAL_DCV_FAILURE: Every domain failed DCV.
    
    Here is the standard Wordpress redirect which I have added the currently recommended cPanel lines to:
    Code:
    # BEGIN WordPress
    <IfModule mod_rewrite.c>
    RewriteEngine On
    RewriteBase /
    RewriteRule ^index\.php$ - [L]
    RewriteCond %{REQUEST_FILENAME} !-f
    RewriteCond %{REQUEST_FILENAME} !-d
    RewriteCond %{REQUEST_URI} !^/[0-9]+\..+\.cpaneldcv$
    RewriteCond %{REQUEST_URI} !^/\.well-known/cpanel-dcv/[0-9a-zA-Z_-]+$
    RewriteCond %{REQUEST_URI} !^/[A-F0-9]{32}\.txt$
    RewriteCond %{REQUEST_URI} !^/\.well-known/pki-validation/[A-F0-9]{32}\.txt(?:\ Comodo\ DCV)?$
    RewriteRule . /index.php [L]
    </IfModule>
    
    There are also a few 301 redirects in there like this:

    Redirect 301 /product-information/ example.com'

    I'm not sure how to pass the AutoSSL update request through to the domain if I'm forcing SSL via Cloudflare. Really need some help on this, I have tried many variants of code but I can't see what the auto-inserted domain validation code is doing and whether it needs modifying somehow.

    Thanks in advance!
     
    #1 Volt55, May 30, 2018
    Last edited by a moderator: Jun 21, 2018 at 4:12 AM
  2. cPanelLauren

    cPanelLauren Forums Analyst
    Staff Member

    Joined:
    Nov 14, 2017
    Messages:
    1,424
    Likes Received:
    98
    Trophy Points:
    103
    Location:
    Houston
    cPanel Access Level:
    DataCenter Provider
    HI @Volt55


    AutoSSL will not work with a forced redirection to https at CloudFlare. The DCV check needs to be able to complete over http. If you login to your CloudFlare dashboard and modify the forced redirection temporarily are you able to complete the DCV check? Furthermore you may be able to add an exception at Cloudflare for the dcv check using their "Page Rules" settings.
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
Loading...

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice