使用acme.sh v3.0.6签发证书时遇DNS验证循环及验证失败问题求助
acme.sh 签发证书无限循环及验证失败问题排查与解决
问题描述
我使用acme.sh v3.0.6执行以下命令签发EC-256证书:
export Namesilo_Key=812bb423232b951sdfwg3423 acme.sh --issue -d reddwarf.life -d www.reddwarf.life --nginx --debug --dns dns_namesilo -k ec-256
执行过程中acme.sh进入无限循环,反复提示Not valid yet, let's wait 10 seconds and check next one.,后续出现致命错误reddwarf.life:Verify error:"error":{,相关日志如下:
[Sat Apr 8 15:23:44 BST 2023] You can use '--dnssleep' to disable public dns checks. [Sat Apr 8 15:23:44 BST 2023] See: https://github.com/acmesh-official/acme.sh/wiki/dnscheck [Sat Apr 8 15:23:44 BST 2023] Checking www.reddwarf.life for _acme-challenge.www.reddwarf.life [Sat Apr 8 15:23:44 BST 2023] Already success, continue next one. [Sat Apr 8 15:23:44 BST 2023] Checking reddwarf.life for _acme-challenge.reddwarf.life [Sat Apr 8 15:23:44 BST 2023] Domain reddwarf.life '_acme-challenge.reddwarf.life' success. [Sat Apr 8 15:23:44 BST 2023] All success, let's return [Sat Apr 8 15:23:44 BST 2023] Verifying: reddwarf.life [Sat Apr 8 15:23:44 BST 2023] Nginx mode for domain:reddwarf.life [Sat Apr 8 15:23:45 BST 2023] Found conf file: /etc/nginx/conf.d/reddwarf.life-80.conf [Sat Apr 8 15:23:45 BST 2023] Backup /etc/nginx/conf.d/reddwarf.life-80.conf to /root/.acme.sh/reddwarf.life_ecc/backup/reddwarf.life.nginx.conf [Sat Apr 8 15:23:45 BST 2023] Check the nginx conf before setting up. [Sat Apr 8 15:23:45 BST 2023] OK, Set up nginx config file [Sat Apr 8 15:23:45 BST 2023] nginx conf is done, let's check it again. [Sat Apr 8 15:23:45 BST 2023] Reload nginx [Sat Apr 8 15:23:47 BST 2023] The replay Nonce is not valid, let's get a new one, Sleeping 1 seconds. [Sat Apr 8 15:23:50 BST 2023] Processing, The CA is processing your order, please just wait. (1/30) [Sat Apr 8 15:23:54 BST 2023] reddwarf.life:Verify error:"error":{ [Sat Apr 8 15:23:54 BST 2023] Restoring from /root/.acme.sh/reddwarf.life_ecc/backup/reddwarf.life.nginx.conf to /etc/nginx/conf.d/reddwarf.life-80.conf [Sat Apr 8 15:23:54 BST 2023] Reload nginx [Sat Apr 8 15:23:54 BST 2023] Removing DNS records. [Sat Apr 8 15:23:54 BST 2023] Removing txt: FRtaMsJ7H4INjCc8FlPaI7z8o6ICo9rW5H-tq2h0puk for domain: _acme-challenge.www.reddwarf.life [Sat Apr 8 15:23:56 BST 2023] Successfully retrieved the record id for ACME challenge. [Sat Apr 8 15:23:57 BST 2023] Successfully removed the TXT record. [Sat Apr 8 15:23:57 BST 2023] Removed: Success [Sat Apr 8 15:23:57 BST 2023] Removing txt: fVQzFJukChDfZn9roxCxHoNKGGBqLj2GNfHisRiLWQQ for domain: _acme-challenge.reddwarf.life [Sat Apr 8 15:23:59 BST 2023] Successfully retrieved the record id for ACME challenge. [Sat Apr 8 15:24:00 BST 2023] Successfully removed the TXT record. [Sat Apr 8 15:24:00 BST 2023] Removed: Success [Sat Apr 8 15:24:00 BST 2023] Please add '--debug' or '--log' to check more details. [Sat Apr 8 15:24:00 BST 2023] See: https://github.com/acmesh-official/acme.sh/wiki/How-to-debug-acme.sh
问题根源
- 验证模式冲突:同时指定
--nginx(HTTP验证)和--dns dns_namesilo(DNS验证),两种验证逻辑互相干扰,导致流程异常。 - DNS同步延迟:Namesilo的DNS解析生效通常需要10-30分钟,默认等待时间不足以让全球DNS节点同步完成,引发前期无限循环。
- 错误信息截断:日志中验证错误信息不完整,大概率是HTTP验证时临时nginx配置无法被CA服务器正常访问,或DNS记录在CA节点未生效。
解决方法
方案一:纯DNS验证(推荐)
放弃HTTP验证,仅使用DNS模式,避免冲突:
export Namesilo_Key=812bb423232b951sdfwg3423 acme.sh --issue -d reddwarf.life -d www.reddwarf.life --dns dns_namesilo --dnssleep 300 -k ec-256
--dnssleep 300:强制等待5分钟再检查DNS,给足Namesilo同步时间;若仍失败,可延长至600(10分钟)。
方案二:纯HTTP验证(nginx模式)
删除DNS相关参数,仅用nginx模式,确保80端口正常对外开放:
acme.sh --issue -d reddwarf.life -d www.reddwarf.life --nginx -k ec-256
- 检查nginx配置,确保两个域名的80站点能正常访问;
- 确认服务器防火墙/安全组放行80端口,CA服务器可正常访问你的站点。
额外排查点
- 手动验证DNS记录:执行命令后,用
dig _acme-challenge.reddwarf.life TXT和dig _acme-challenge.www.reddwarf.life TXT检查记录是否存在,直到全球多个节点都能查询到再继续。 - 更新acme.sh:升级到最新版本修复已知bug:
acme.sh --upgrade
- 获取完整错误日志:添加
--log /var/log/acme.log参数,查看完整验证错误信息,定位具体原因。
内容的提问来源于stack exchange,提问作者Dolphin
相关产品推荐
相关产品推荐

