ACM Certificate request with DNS validation fails immediately

0

As soon as I request a certificate for my domain or any subdomains, validation fails with an error requesting additional information. My domain is certainly nowhere close to Alexa's top 1000. The "Domains" section does not show me any CNAME records that I could enter in my DNS provider (Cloudflare). As instructed by the help center, I am creating a thread here. How can I get my domain ownership validated?

Tim
질문됨 7달 전288회 조회
1개 답변
0

You didn't mention your domain but wild guess is this might be because Cloudflare has CAA records setup for your domain that prevent AWS from issuing the cert.

From https://coady.tech/amplify-cloudflare-caa-error/

CAA records, also knows as Certification Authority Authorization records, are used to restrict which Certificate Authorities are allowed to issue certificates for your domain. In this instance it seems CloudFlare’s Universal SSL automatically created CAA records for the providers they use, including Let’s Encrypt, DigiCert, and others. When AWS Amplify attempts to issue you with a certificate their system will check your domain’s CAA records. If AWS isn’t listed then it will return an error.

You can verify this with your favorite DNS tool or using online services like https://toolbox.googleapps.com/apps/dig/#CAA/

profile picture
전문가
Kallu
답변함 7달 전
  • Thanks for the suggestion. There weren't any CAA records on my domain. I tried to explicitly create the necessary CAA records, as per the article on coady.tech, but that did not help. If it helps, the domain is lllamnyp.su.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠