Any body else having renewal error with acme certificate ?
diag sys acme status-full "xxxx.xxxxxx.ca"
{ "name": "xxxx.xxxxxx.ca", "finished": false, "notified": false, "next-run": "Thu, 05 Aug 2021 15:19:58 GMT", "last-run": "Thu, 05 Aug 2021 14:37:16 GMT", "errors": 554, "last": { "status": 22, "status-description": "Invalid argument", "problem": "urn:ietf:params:acme:error:malformed", "detail": "No order for ID xxxxxxxxxxxx" },
Is dns working? It sounds like the acme client might have issues. You can maybe trying to restart it and see what happens . FWIW I have no issues.
promete01:~ ken$ openssl s_client -connect 192.168.1.99:443 | openssl x509 -noout -datesdepth=3 O = Digital Signature Trust Co., CN = DST Root CA X3verify return:1depth=2 C = US, O = Internet Security Research Group, CN = ISRG Root X1verify return:1depth=1 C = US, O = Let's Encrypt, CN = R3verify return:1depth=0 CN = blahblah.socpuppets.comverify return:1notBefore=Jul 26 09:58:12 2021 GMTnotAfter=Oct 24 09:58:10 2021 GMT Ken Felix
PCNSE
NSE
StrongSwan
Yes DNS is working fine in fact the error jumped just now the previous one renewal was successfully done.
Just do the diag cmd if this happens again. I bet it might have some hidden issues of running the acme-client and protocol and DNS has be working. Are you using fortinet DNS or some other DNS servers?
Ken Felix
PCNSE
NSE
StrongSwan
Hi Ken, thks again for answer, we use Windows Srv 2019 Std as DNS server. As mentioned before it was working fine the second 100F that has almost same config just diff CN is working fine too, the renew on that one was successfully done last 18082021 in or second firewall.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.