Skip to content

Waiting for DNS-01 challenge propagation: dial tcp [IP]:53: i/o timeout #13

@nhat-tong

Description

@nhat-tong

Hi,

I want to use DNS01 challenge for wildcard certificate. I have configured my OVH credentials with the right permissions but when calling OVH I have this error:

Status:
Presented: true
Processing: true
Reason: Waiting for DNS-01 challenge propagation: dial tcp 10.10.2.3:53: i/o timeout
State: pending

I don't understand what it means, especially this ip (10.10.2.3). I don't have any pod within cluster with this ip.

By the way, a record type TXT named "_acme-challenge.XXX.com" have been created in dns zone on OVH side.
I could confirm that the webhook client was able to talk to OVH with the right permissions.

@baarde: do you have any thoughts concerning this error ?

Thanks in advance,

Cluster: OpenShift 4
Cert Manager version: 1.6.0
Acme server (staging). https://acme-staging-v02.api.letsencrypt.org/directory
Webhook OVH version: 0.3.0

------------------------------------------------------ Webhook Client Logs ------------------------------------------------
I1102 11:05:30.778796 1 trace.go:205] Trace[477362888]: "Create" url:/apis/XXX/v1alpha1/ovh,user-agent:controller/v0.0.0 (linux/amd64) kubernetes/$Format/leader-election,audit-id:39a76cfa-73a4-4c10-970a-2b6ac6961091,client:10.64.84.31,accept:application/json, /,protocol:HTTP/2.0 (02-Nov-2021 11:05:30.023) (total time: 754ms):
Trace[477362888]: ---"Object stored in database" 754ms (11:05:30.778)
Trace[477362888]: [754.909453ms] [754.909453ms] END

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions