Traefik2.2.1 | Let's Encrypt | DigitalOcean | error: 400 | Timeout during connect (likely firewall problem)

Viewed 1147

Need your help in getting the right inputs to setup https SSL certificates for main domain and subdomain. Since last month I have been trying multiple options and gone through various blogs to try and get an understanding of why in my config I am not able get certificates from Let's Encrypt. It is frustrating at this point as I have hit Let's Encrypt rate limit so many times. Finally, I am reaching out to the community to help me as the rate limits really delays any debugs or fast fixes (I understand why limits are there. Let's encrypt is free service and it should be responsibly used. I think it's required but just frustrating for newbies experimenting).

Setup:

I have purchased a domain from Namecheap = "spin360.digital" I have a Digital Ocean droplet on which I run docker (node apps) = Docker 19.03.12 on Ubuntu 20.04

So far I have managed to get "api.spin360.digital" certificate in 2020 stored in acme.json in the droplet. It is working fine. I can hit from browser "https://api.spin360.digital" to get 200OK and green tick on certificate.

Now in 2021, I was trying to add 2 other subdomains "shopify.spin360.digital" and "bigcom.spin360.digital"

Traefik version: 2.2.1 Nodejs: 12

Here's the config files for reference:


DigitalOcean DNS Records

A   spin360.digital | directs to xxx.xx.xxx.xxx | 3600  | More 
A   bigcom.spin360.digital | directs to xxx.xx.xxx.xxx | 3600  | More 
A   shopify.spin360.digital | directs to xxx.xx.xxx.xxx | 3600  | More 
A   api.spin360.digital | directs to xxx.xx.xxx.xxx | 3600  | More 
CAA *.spin360.digital | authorization: letsencrypt.orgCopywild  3600  | More 
AAAA    *.spin360.digital | directs to xxxx:xxxx:xxx:xx::xxx:xxx | 3600  | More 
A   *.spin360.digital | directs to xxx.xx.xxx.xxx | 3600  | More 
AAAA    spin360.digital | directs to xxxx:xxxx:xxx:xx::xxx:xxx | 3600  | More 
A   spin360.digital | directs to xxx.xx.xxx.xxx| 3600  | More 
NS  spin360.digital | directs to ns2.digitalocean.com. | 1800  | More 
NS  spin360.digital | directs to ns3.digitalocean.com. | 1800  | More 
NS  spin360.digital | directs to ns1.digitalocean.com. | 1800  | More 

Traefik.toml

logLevel = "DEBUG"

[traefikLog]
  filePath = "atraefik.log"

[accessLog]
  filePath = "access.log"

[entryPoints]
  [entryPoints.web]
    address = ":80"
  [entryPoints.web.http.redirections.entryPoint]
    to = "websecure"
    scheme = "https"
  [entryPoints.websecure]
    address = ":443"

 [api]
   dashboard = true
   debug = true

 [certificatesResolvers.lets-encrypt.acme]
   email = "a.b@gmail.com"
   storage = "acme.json"
   [certificatesResolvers.lets-encrypt.acme.tlsChallenge]

 [providers.docker]
   watch = true
   network = "web"

 [providers.file]
   filename = "traefik_dynamic.toml"

traefik_dynamic.toml

[http.middlewares.simpleAuth.basicAuth]
  users = [
    "xxx:xxx"
  ]

 [http.routers.api]
   rule ="Host(`spin360.digital`,
        `monitor.spin360.digital`,`shopify.spin360.digital`,`bigcom.spin360.digital`)"
   entrypoints = ["websecure"]
   middlewares = ["simpleAuth"]
   service = "api@internal"
  [http.routers.api.tls]
    certResolver = "lets-encrypt"
  [[http.routers.api.tls.domains]]
    main = "spin360.digital"
    sans = ["shopify.spin360.digital","bigcom.spin360.digital"]

Firewall Setup

$ufw status
 Status: active

 To                         Action      From
 --                         ------      ----
 22/tcp                     ALLOW       Anywhere
 80/tcp                     ALLOW       Anywhere
 443/tcp                    ALLOW       Anywhere
 22/tcp (v6)                ALLOW       Anywhere (v6)
 80/tcp (v6)                ALLOW       Anywhere (v6)
 443/tcp (v6)               ALLOW       Anywhere (v6)

when I run >

docker run \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v $PWD/traefik.toml:/traefik.toml \
  -v $PWD/traefik_dynamic.toml:/traefik_dynamic.toml \
  -v $PWD/acme.json:/acme.json \
  -p 80:80 \
  -p 443:443 \
  --network web \
  --name traefik \
  traefik:v2.2.1

I get error on console >

ERROR

time="2021-02-11T19:30:44Z" level=error msg="Unable to obtain ACME certificate for domains 
 \"spin360.digital,shopify.spin360.digital,bigcom.spin360.digital\" : unable to generate a 
 certificate for the domains [spin360.digital shopify.spin360.digital 
 bigcom.spin360.digital]: error: one or more domains had a problem:\n[spin360.digital] acme: 
 error: 400 :: urn:ietf:params:acme:error:connection :: Timeout during connect (likely 
 firewall problem), url: \n" providerName=lets-encrypt.acme

I kept traefik running for a couple of minutes while I was checking. When I killed it and restarted again I hit the rate limit - "too many failed authorizations recently"


Reaching out to the community for help. I hope a simple setup like this would benefit many new individuals that would come to stackoverflow for similar issues. It would save them heaps of time.

Thanks.

0 Answers
Related