mirror of
https://github.com/acme-dns/acme-dns.git
synced 2026-04-27 12:55:48 +03:00
[GH-ISSUE #353] TXT record returns two values - doesn't seem that should be possible #196
Labels
No labels
Documentation
Documentation
bug
enhancement
feature request
feature request
help wanted
pull-request
question
security
security
testing
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/acme-dns#196
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @bbct on GitHub (May 31, 2024).
Original GitHub issue: https://github.com/acme-dns/acme-dns/issues/353
My renewal was failing, the value returned for my TXT record didn't match.
I used nslookup to see what the value is.
Somehow I've managed to get 2 values stored for the same TXT record:
Non-authoritative answer:
90103513-A497-46F6-944e-32CDf9D25794.My.domain.COM text =
90103513-A497-46F6-944e-32CDf9D25794.My.domain.COM text =
The second one is the correct one, the first one must be older? Should two TXT records even exist like this?
Question 1: any idea how I managed to do this?
Question 2: how do I delete the TXT records to start from scratch?
Disclosure - As I am testing this out first, I may have registered this same domain a second time under different credentials, perhaps that is why it is returning two values?.
Perhaps I should just start with a fresh db, and start over? I've registered only a couple domains. If I need to start over, what's the best way?
Thank you for any help you can provide.
@bbct commented on GitHub (May 31, 2024):
FYI - using Sqlite3, I queried the txt table, there were two rows for each Subdomain. I deleted the oldest for each pair, and it seems to be working now.
Still not sure how I got two TXT records for each subdomain...
@aduzsardi commented on GitHub (May 31, 2024):
afaik , that's the desired behaivor (having 2 txt records) for wildcard certificates
@bbct commented on GitHub (May 31, 2024):
Interesting, aduzsardi. It wasn't actually a wildcard cert I requested, though. Just a single domain.
@joohoi commented on GitHub (May 31, 2024):
Yeah, this is true. An usecase where the CA requires two different tokens
in the same subdomain is a wildcard certificate and the apex domain in the
same certificate.
That said, the CA will respect a correct validation token in any of the the
records. Additional ones do not matter.
On Fri 31. May 2024 at 18.52, bbct @.***> wrote: