[GH-ISSUE #1149] 使用华为云DNS解析acme: error presenting token: huaweicloud: zone "httpsauto #774

Closed
opened 2026-03-03 01:05:55 +03:00 by kerem · 1 comment
Owner

Originally created by @wzqiang1332 on GitHub (Jan 7, 2026).
Original GitHub issue: https://github.com/certimate-go/certimate/issues/1149

Release Version / 软件版本

v0.4.13

Description / 问题描述

使用华为云DNS解析,如果已经存在_acme-challenge.xxx.xxx.com这条记录时,执行报下面这个错误

[2026-01-07 17:31:07]
Found CNAME entry for "_acme-challenge.xxx.xxx.com.": "b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com."
[2026-01-07 17:31:08]
[xxx.xxx.com] acme: Cleaning DNS-01 challenge
[2026-01-07 17:31:08]
Found CNAME entry for "_acme-challenge.xxx.xxx.com.": "b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com."
[2026-01-07 17:31:08]
[xxx.xxx.com] acme: cleaning up failed: huaweicloud: unknown record ID for 'b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com.' 'Hf_bxR2LgbfgVxuMGxLKChaBBNCUP8y_KIHAXvD_KO4'
[2026-01-07 17:31:08]
Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz/2942091316/639164578076
[2026-01-07 17:31:09]
could not obtain certificate
[2026-01-07 17:31:09]
failed to obtain certificate: error: one or more domains had a problem: [xxx.xxx.com] [xxx.xxx.com] acme: error presenting token: huaweicloud: zone "httpsauto.com." not found

如果删掉这条记录,执行流程会创建一条记录,但是走到验证那里走不下去了,错误如下:

[2026-01-07 17:25:06]
[xxx.xxx.com] acme: use dns-01 solver
[2026-01-07 17:25:06]
[xxx.xxx.com] acme: Preparing to solve DNS-01
[2026-01-07 17:25:08]
[xxx.xxx.com] acme: Trying to solve DNS-01
[2026-01-07 17:25:08]
Found CNAME entry for "_acme-challenge.xxx.xxx.com.": "b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com."
[2026-01-07 17:25:08]
[xxx.xxx.com] acme: Checking DNS record propagation. [nameservers=192.168.21.2:53,223.5.5.5:53]
[2026-01-07 17:25:10]
Wait for propagation [timeout: 1m0s, interval: 2s]
[2026-01-07 17:25:11]
[xxx.xxx.com] acme: Waiting for DNS record propagation.
[2026-01-07 17:25:13]
……
[2026-01-07 17:26:11]
[xxx.xxx.com] acme: Cleaning DNS-01 challenge
[2026-01-07 17:26:13]
Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz/2942091316/639162568166
[2026-01-07 17:26:13]
could not obtain certificate
[2026-01-07 17:26:13]
failed to obtain certificate: error: one or more domains had a problem: [xxx.xxx.com] propagation: time limit exceeded: last error: authoritative nameservers: NS f1g1ns2.dnspod.net.:53 did not return the expected TXT record [fqdn: b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com., value: OSbnDaRnrPzKMeCKqcpjFQ5_aDtPFoGxc-aIVIuN4CA]:

求大佬指点,感谢

Miscellaneous / 其他

No response

Originally created by @wzqiang1332 on GitHub (Jan 7, 2026). Original GitHub issue: https://github.com/certimate-go/certimate/issues/1149 ### Release Version / 软件版本 v0.4.13 ### Description / 问题描述 使用华为云DNS解析,如果已经存在_acme-challenge.xxx.xxx.com这条记录时,执行报下面这个错误 ``` [2026-01-07 17:31:07] Found CNAME entry for "_acme-challenge.xxx.xxx.com.": "b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com." [2026-01-07 17:31:08] [xxx.xxx.com] acme: Cleaning DNS-01 challenge [2026-01-07 17:31:08] Found CNAME entry for "_acme-challenge.xxx.xxx.com.": "b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com." [2026-01-07 17:31:08] [xxx.xxx.com] acme: cleaning up failed: huaweicloud: unknown record ID for 'b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com.' 'Hf_bxR2LgbfgVxuMGxLKChaBBNCUP8y_KIHAXvD_KO4' [2026-01-07 17:31:08] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz/2942091316/639164578076 [2026-01-07 17:31:09] could not obtain certificate [2026-01-07 17:31:09] failed to obtain certificate: error: one or more domains had a problem: [xxx.xxx.com] [xxx.xxx.com] acme: error presenting token: huaweicloud: zone "httpsauto.com." not found ``` 如果删掉这条记录,执行流程会创建一条记录,但是走到验证那里走不下去了,错误如下: ``` [2026-01-07 17:25:06] [xxx.xxx.com] acme: use dns-01 solver [2026-01-07 17:25:06] [xxx.xxx.com] acme: Preparing to solve DNS-01 [2026-01-07 17:25:08] [xxx.xxx.com] acme: Trying to solve DNS-01 [2026-01-07 17:25:08] Found CNAME entry for "_acme-challenge.xxx.xxx.com.": "b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com." [2026-01-07 17:25:08] [xxx.xxx.com] acme: Checking DNS record propagation. [nameservers=192.168.21.2:53,223.5.5.5:53] [2026-01-07 17:25:10] Wait for propagation [timeout: 1m0s, interval: 2s] [2026-01-07 17:25:11] [xxx.xxx.com] acme: Waiting for DNS record propagation. [2026-01-07 17:25:13] …… [2026-01-07 17:26:11] [xxx.xxx.com] acme: Cleaning DNS-01 challenge [2026-01-07 17:26:13] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz/2942091316/639162568166 [2026-01-07 17:26:13] could not obtain certificate [2026-01-07 17:26:13] failed to obtain certificate: error: one or more domains had a problem: [xxx.xxx.com] propagation: time limit exceeded: last error: authoritative nameservers: NS f1g1ns2.dnspod.net.:53 did not return the expected TXT record [fqdn: b298nuxjf48i3a2vlxwk.dcv2.httpsauto.com., value: OSbnDaRnrPzKMeCKqcpjFQ5_aDtPFoGxc-aIVIuN4CA]: ``` 求大佬指点,感谢 ### Miscellaneous / 其他 _No response_
kerem closed this issue 2026-03-03 01:05:55 +03:00
Author
Owner

@wzqiang1332 commented on GitHub (Jan 7, 2026):

找到解决方案了,根据官网的常见问题,勾选阻止“阻止 CNAME 跟随”后可以了

<!-- gh-comment-id:3718143190 --> @wzqiang1332 commented on GitHub (Jan 7, 2026): 找到解决方案了,根据官网的常见问题,勾选阻止“阻止 CNAME 跟随”后可以了
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/certimate#774
No description provided.