Scenario
A clustered or load-balanced service renews properly on one node, but the active node keeps failing ACME challenges.
Recommended Resolution Path
- Compare challenge path handling, DNS resolution, and local firewall rules between nodes.
- Check whether the load balancer sends validation traffic consistently to the wrong backend.
- Test HTTP or DNS challenge reachability from outside the environment.
- If cluster design complicates renewal, centralize issuance rather than patching each node differently.
Technician Notes
Document what changed, what confirmed the fix, and whether the issue points to a broader standards gap worth addressing for the client.
- Log in to post comments
Subjects