Need your help in getting the right inputs to setup https SSL certificates for main domain and subdomain. Since last month I have been trying multiple options and gone through various blogs to try and get an understanding of why in my config I am not able get certificates from Let's Encrypt. It is frustrating at this point as I have hit Let's Encrypt rate limit so many times. Finally, I am reaching out to the community to help me as the rate limits really delays any debugs or fast fixes (I understand why limits are there. Let's encrypt is free service and it should be responsibly used. I think it's required but just frustrating for newbies experimenting).
Setup:
I have purchased a domain from Namecheap = "spin360.digital" I have a Digital Ocean droplet on which I run docker (node apps) = Docker 19.03.12 on Ubuntu 20.04
So far I have managed to get "api.spin360.digital" certificate in 2020 stored in acme.json in the droplet. It is working fine. I can hit from browser "https://api.spin360.digital" to get 200OK and green tick on certificate.
Now in 2021, I was trying to add 2 other subdomains "shopify.spin360.digital" and "bigcom.spin360.digital"
Traefik version: 2.2.1 Nodejs: 12
Here's the config files for reference:
DigitalOcean DNS Records
A spin360.digital | directs to xxx.xx.xxx.xxx | 3600 | More
A bigcom.spin360.digital | directs to xxx.xx.xxx.xxx | 3600 | More
A shopify.spin360.digital | directs to xxx.xx.xxx.xxx | 3600 | More
A api.spin360.digital | directs to xxx.xx.xxx.xxx | 3600 | More
CAA *.spin360.digital | authorization: letsencrypt.orgCopywild 3600 | More
AAAA *.spin360.digital | directs to xxxx:xxxx:xxx:xx::xxx:xxx | 3600 | More
A *.spin360.digital | directs to xxx.xx.xxx.xxx | 3600 | More
AAAA spin360.digital | directs to xxxx:xxxx:xxx:xx::xxx:xxx | 3600 | More
A spin360.digital | directs to xxx.xx.xxx.xxx| 3600 | More
NS spin360.digital | directs to ns2.digitalocean.com. | 1800 | More
NS spin360.digital | directs to ns3.digitalocean.com. | 1800 | More
NS spin360.digital | directs to ns1.digitalocean.com. | 1800 | More
Traefik.toml
logLevel = "DEBUG"
[traefikLog]
filePath = "atraefik.log"
[accessLog]
filePath = "access.log"
[entryPoints]
[entryPoints.web]
address = ":80"
[entryPoints.web.http.redirections.entryPoint]
to = "websecure"
scheme = "https"
[entryPoints.websecure]
address = ":443"
[api]
dashboard = true
debug = true
[certificatesResolvers.lets-encrypt.acme]
email = "a.b@gmail.com"
storage = "acme.json"
[certificatesResolvers.lets-encrypt.acme.tlsChallenge]
[providers.docker]
watch = true
network = "web"
[providers.file]
filename = "traefik_dynamic.toml"
traefik_dynamic.toml
[http.middlewares.simpleAuth.basicAuth]
users = [
"xxx:xxx"
]
[http.routers.api]
rule ="Host(`spin360.digital`,
`monitor.spin360.digital`,`shopify.spin360.digital`,`bigcom.spin360.digital`)"
entrypoints = ["websecure"]
middlewares = ["simpleAuth"]
service = "api@internal"
[http.routers.api.tls]
certResolver = "lets-encrypt"
[[http.routers.api.tls.domains]]
main = "spin360.digital"
sans = ["shopify.spin360.digital","bigcom.spin360.digital"]
Firewall Setup
$ufw status
Status: active
To Action From
-- ------ ----
22/tcp ALLOW Anywhere
80/tcp ALLOW Anywhere
443/tcp ALLOW Anywhere
22/tcp (v6) ALLOW Anywhere (v6)
80/tcp (v6) ALLOW Anywhere (v6)
443/tcp (v6) ALLOW Anywhere (v6)
when I run >
docker run \
-v /var/run/docker.sock:/var/run/docker.sock \
-v $PWD/traefik.toml:/traefik.toml \
-v $PWD/traefik_dynamic.toml:/traefik_dynamic.toml \
-v $PWD/acme.json:/acme.json \
-p 80:80 \
-p 443:443 \
--network web \
--name traefik \
traefik:v2.2.1
I get error on console >
ERROR
time="2021-02-11T19:30:44Z" level=error msg="Unable to obtain ACME certificate for domains
\"spin360.digital,shopify.spin360.digital,bigcom.spin360.digital\" : unable to generate a
certificate for the domains [spin360.digital shopify.spin360.digital
bigcom.spin360.digital]: error: one or more domains had a problem:\n[spin360.digital] acme:
error: 400 :: urn:ietf:params:acme:error:connection :: Timeout during connect (likely
firewall problem), url: \n" providerName=lets-encrypt.acme
I kept traefik running for a couple of minutes while I was checking. When I killed it and restarted again I hit the rate limit - "too many failed authorizations recently"
Reaching out to the community for help. I hope a simple setup like this would benefit many new individuals that would come to stackoverflow for similar issues. It would save them heaps of time.
Thanks.