Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Domain name does not end with a valid public suffix (TLD) #103

Closed
fly-man- opened this issue Nov 17, 2023 · 2 comments
Closed

Domain name does not end with a valid public suffix (TLD) #103

fly-man- opened this issue Nov 17, 2023 · 2 comments

Comments

@fly-man-
Copy link

I thought that when I set the Domain mode to lockdown to only be able to use the domains I specified it would be able to do

*.grandhotel.internal

But for some reason LabCA returns the following error when requesting a certificate:

root@servicehub:/home/service/lego# ./lego --server https://local-ca/directory -a -m beheerder@grandhotel.local --http -d *.grandhotel.internal run
2023/11/17 20:35:06 [INFO] [*.grandhotel.internal] acme: Obtaining bundled SAN certificate
2023/11/17 20:35:06 Could not obtain certificates:
        acme: error: 400 :: POST :: https://local-ca/acme/new-order :: urn:ietf:params:acme:error:rejectedIdentifier :: Error creating new order :: Cannot issue for "*.grandhotel.internal": Domain name does not end with a valid public suffix (TLD)

Is this something that's build into Boulder to "reject" the domainname and how do I allow .internal to be used within my homelab ?

@hakwerk
Copy link
Owner

hakwerk commented Nov 19, 2023

It should indeed work for non-official TLDs. Is there some more information in the server logs?

I think someone once had this issue because the domain configured in the lockdown started with a dot, which it shouldn't.

@fly-man-
Copy link
Author

  • Checked the logs, no errors popping up

  • Checked the configuration and the domain is correctly in there, only difference that I have is that I am 1 revision behind (July 2023 instead of October 2023)

Oddly I think I might have to just grab a backup from my configs and then reinstall ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants