为子域名cloud.maxime-mazet.fr申请Let's Encrypt SSL证书时遇DNS NXDOMAIN错误
Let’s work through this step by step—your main domain’s SSL worked, so the issue is specifically tied to the subdomain’s DNS or setup. Here’s how to troubleshoot and resolve the NXDOMAIN error you’re seeing:
1. Verify DNS Record Propagation & Correctness
The error NXDOMAIN looking up A for cloud.maxime-mazet.fr means the Let’s Encrypt servers can’t find an A record for your subdomain. Even if you added it in OVH’s panel, DNS changes take time to propagate across the internet.
- Check the record locally first: Run these commands on your server to confirm the DNS resolves correctly:
Look for a line showing your server’s public IP address. If it returns "NXDOMAIN" here too, the record hasn’t been set up properly or hasn’t propagated yet.dig cloud.maxime-mazet.fr A nslookup cloud.maxime-mazet.fr - Wait for DNS propagation: OVH’s default TTL (time-to-live) for records is often 1-2 hours. If you just added the A record, give it some time to roll out. You can also test from a different network (like your phone’s cellular data) to bypass local/ISP DNS caching.
- Double-check your OVH panel entry: Ensure your A record is configured exactly as:
- Record type:
A - Hostname:
cloud(notwww.cloudor any variation) - Target/Value: Your server’s public IP address (not an internal private IP like 192.168.x.x)
- Record type:
2. Validate Webroot & Web Server Configuration
Once DNS is resolving correctly, make sure your web server is set up to serve files from the webroot path you provided:
- Confirm the webroot path exists: Run
ls -ld /var/www/sub-domain/maxime-mazet.fr/owncloudto ensure the directory is present and has the correct permissions (your web server user likewww-datashould have read access). - Test the ACME challenge path: Create a test file in the challenge directory:
Then try accessingmkdir -p /var/www/sub-domain/maxime-mazet.fr/owncloud/.well-known/acme-challenge echo "test-content" > /var/www/sub-domain/maxime-mazet.fr/owncloud/.well-known/acme-challenge/test-filehttp://cloud.maxime-mazet.fr/.well-known/acme-challenge/test-filefrom a browser. If you can see "test-content", the webroot is working correctly. If not, check your web server (Apache/Nginx) configuration for the subdomain—make sure it’s pointing to the right directory and there are no rewrite rules blocking access to.well-known.
3. Check Firewall & Network Access
Let’s Encrypt needs to reach your server on port 80 for the http-01 challenge:
- Verify server firewall rules: If you’re using
ufw, runufw statusto confirm port 80 is allowed. Foriptables, check withiptables -L -n | grep 80. - Check cloud provider security groups: If your server is on a cloud platform (like OVH Cloud), ensure the inbound security group allows traffic on port 80 from all sources (0.0.0.0/0).
4. Re-Run the Certbot Command
Once you’ve confirmed DNS propagation, webroot access, and firewall settings, re-run your Certbot command:
certbot certonly --webroot -w /var/www/sub-domain/maxime-mazet.fr/owncloud/ -d cloud.maxime-mazet.fr
If you still run into issues, add the --debug flag to get more detailed logs from Let’s Encrypt.
内容的提问来源于stack exchange,提问作者user9202590

