I am having an issue implementing CAA records. The domains in question lycaonsec.netlify.app. i want to limit the CAA to Lets encrypt however if i do this then netlify is unable to renew SSL certificates.
If I remove the record it renews the certificate.
This is the record am i missing something does Netlify need to be added?
I cannot comment on the CAA record, however I can see
lycaonsec.com isn’t configured per the Configure external DNS for a custom domain documentation. The secord record here (
220.127.116.11) will cause issues here. Only the A record pointing to
18.104.22.168 should exist.
% dig lycaonsec.com
lycaonsec.com. 3600 IN A 22.214.171.124
lycaonsec.com. 3600 IN A 126.96.36.199
Having a non-Netlify IP address like this will cause issues with provision/renewal of SSL certificates.
For CAA, your
iodef property is correct.
issuewild will be ignored when processing a TLS certificate request which is not a wildcard domain. In that case, it will fall to your
issue property which prohibit any CA from issuing TLS cert for your domain.
So, Let’s Encrypt will be able to issue a certificate for
*.subdomain.lycaonsec.com but nothing else. It won’t be able to issue a cert for
I personally have been running my domain with only
0 issue "letsencrypt.org" and the
iodef property and it would work just fine.
@coelmay Thanks for this
Im a little confused by your comment as the subdomain www record is configured as a CNAME per the document you liked to that is correct
The Apex domain is a ANAME but will return as A but this is also correct if I’m missing something please let me know
lycaonsec is the primary domain not www
My apologies @lycaon-security, your setup is correct—my information was not
Going back to your original post, if you add the CAA record, SSL certificate generation stops working. I suspect @luke might best know what the issue here.
I’m not sure what the status of this thread is. You appear to have
0 issue "letsencrypt.org" as your CAA record and you also seem to have got the SSL. Is this resolved or do you need something specific?