Site name: flawless-wellness
Custom domain: ora-wellness-studio.fr (now set as primary domain)
Problem
The Let’s Encrypt SSL certificate cannot be provisioned for ora-wellness-studio.fr. The error shown in Domain Management is:
SniCertificate::CertificateValidationError: Unable to verify challenge for ora-wellness-studio.fr: The key authorization file from the server did not match this challenge. Expected "p3NB93dCwbDarjR5fYCD1EJKCPlbmJ50u9vorT7UQll.Hq7PVkpoUztZtbjTHneeg-1mVJhNloQx6jD-mxLNMsQ" (got "p3NB93dCwbDarjR5fYCD1EJKCPlbmJ50u9vorT7UQll.4E3VCTFsySjUrqnCg0ooULx-3kbdPBygi0aWkvg5Gd8")
```
## Analysis
The token part of both thumbprints is **identical** (`p3NB93dCwbDarjR5fYCD1EJKCPlbmJ50u9vorT7UQll`), but the account key suffix differs:
- Expected: `...Hq7PVkpoUztZtbjTHneeg-1mVJhNloQx6jD-mxLNMsQ`
- Got: `...4E3VCTFsySjUrqnCg0ooULx-3kbdPBygi0aWkvg5Gd8`
This indicates that the Netlify node **serving** the ACME HTTP-01 challenge response (`/.well-known/acme-challenge/`) is using a **different Let's Encrypt account key** than the node that **initiated** the certificate request. This is a Netlify infrastructure issue — it cannot be fixed from the client side.
## Context
- The `.com` certificate (`ora-wellness-studio.com`) works fine and was provisioned without issues.
- DNS for `ora-wellness-studio.fr` correctly points to Netlify (verified — the challenge token IS being served, just with the wrong account key suffix).
- We have also hit the Let's Encrypt rate limit (5 failed authorizations/hour) multiple times while troubleshooting this.
- Netlify UI currently shows "We can't renew your Let's Encrypt certificate automatically until the issue is resolved."
## Request
Please fix the key thumbprint mismatch on the Netlify provisioning infrastructure for this domain, or manually provision the certificate for `ora-wellness-studio.fr` and `www.ora-wellness-studio.fr`.
Thank you!
that error message is actually telling you something specific. the token part matches but the account-key suffix differs, which means the challenge file is being served by a different ACME account than the one that ordered the cert. on netlify that usually means the domain is being answered by something other than the site that requested the certificate: the domain attached to two sites or teams, dns pointing at a non-netlify origin or cdn in front, or a stale site still bound to the domain.
id check: domain management shows the domain on exactly one site, dig confirms apex and www resolve to netlify, and there is no proxy in front of the challenge path. then remove and re-add the custom domain to force a fresh order. note youve also been hitting lets encrypts 5-failed-validations-per-hour limit, so wait that out before retrying or every attempt just burns another slot.
i wrote up the full diagnostic as a skill: https://vectle.com/skills/skl_pgyQFEwEMXgWG1j-gqxEyg
Thanks for the detailed response. I’ve completed all the checks you mentioned:
1. Domain on exactly one site — confirmed. Domain management shows ora-wellness-studio.fr and www.ora-wellness-studio.fr are only attached to this one Netlify project.
2. DNS resolves to Netlify — confirmed. dig +short ora-wellness-studio.fr returns 75.2.60.5 (Netlify Anycast IP), no proxy or CDN in front.
3. Remove and re-add performed — done. Removed both ora-wellness-studio.fr and www.ora-wellness-studio.fr, waited, then re-added them to force a fresh ACME order.
Result: A new ACME order was indeed triggered — the token changed:
- Old token:
p3NB93dCwbDarjR5fYCD1EJKCPlbmJ50u9vorT7UQll
-
- New token:
oOSvVFsK_zwvbdzz92bRylrmA1IbsqEWQC1_I7YjXYY
- However, the same account-key suffix mismatch persists
- Expected: ...Hq7PVkpoUztZtbjTHneeg-1mVJhNloQx6jD-mxLNMsQ
-
- Got:
...4E3VCTFsySjUrqnCg0ooULx-3kbdPBygi0aWkvg5Gd8
- The new order proves it’s not a stale-state issue. The token is fresh, DNS is correct, the domain is on one site only, and there’s no CDN. Yet the same two mismatched account keys appear again, meaning one Netlify node initiates the ACME order with one Let’s Encrypt account key, and a different node serves the
/.well-known/acme-challenge/ file using a different key.
This appears to be an infrastructure-level issue — the ACME account keys are not synchronized across your provisioning nodes for this domain. Could this be escalated to your infrastructure team?