AutoSSL is very slow and missing certificates

sunmacet

Active Member
Jan 24, 2009
26
8
53
cPanel Access Level
Root Administrator
We have been receiving complaints from our customers on multiple servers that certificates with AutoSSL has not been renewed. When we run the AutoSSL manually for the user the certificate will be renewed.

In one of the affected server we have run autossl manually in command line and it has been running now over two days!

We have checked resolving and it is fast. Also the resolvers are the same as for servers that has not been affected.

The autossl command seems to be very slow at each "AutoSSL will attempt a DNS-based DCV for ..."

Only clue so far is these error messages in output of the autossl:

[1637931458] libunbound[2391132:0] error: event_add failed. in cpsl.
[1637931458] libunbound[2391132:0] error: could not event_del on close

Any help would be greatly appreciated!
 

sunmacet

Active Member
Jan 24, 2009
26
8
53
cPanel Access Level
Root Administrator
There is not much. Of course there is errors for the domains that are expired or do not point to our server but they are not relevant.

These are produces when run in command line:

[1637951124] libunbound[2391132:0] error: event_add failed. in cpsl.
[1637951124] libunbound[2391132:0] error: could not event_del on close
[1637951126] libunbound[2391132:0] error: event_add failed. in cpsl.
[1637951126] libunbound[2391132:0] error: could not event_del on close


This user was missing certificate after one night and only this was in the log of the previous AutoSSL run:

10:06:24 PM Analyzing “XXX”’s domains …
10:06:24 PM Analyzing “XXX” (website) …
10:06:24 PM ERROR TLS Status: Defective
ERROR Certificate expiry: 11/25/21, 12:00 AM UTC (0.12 days from now)
ERROR Defect: ALMOST_EXPIRED: The certificate will expire very soon.
10:06:24 PM Attempting to ensure the existence of necessary CAA records …
10:06:25 PM No CAA records were created.
10:06:25 PM Verifying 1 domains’ management status …
Verifying “cPanel (powered by Sectigo)”’s authorization on 1 domains via DNS CAA records …
10:06:25 PM “XXX” is managed.
CA authorized: “XXX”
All of this user’s 1 domains are managed.
“cPanel (powered by Sectigo)” is authorized to issue certificates for 1 of this user’s 1 domains.
10:06:25 PM Performing HTTP DCV (Domain Control Validation) on 1 domains …
10:06:26 PM Local HTTP DCV OK: XXX
10:06:26 PM No local DNS DCV is necessary.

And there was no other log entries for the user.
 

sunmacet

Active Member
Jan 24, 2009
26
8
53
cPanel Access Level
Root Administrator
Yes I can confirm that this seemed to be the case.

When we ran AutoSSL per user as explained in the article the AutoSSL finished in under 3 hours without problems.

With normal run it took over 2 days and was interrupted before finishing.
 
  • Like
Reactions: cPanelAnthony