Quick troubleshooting view
The ACME challenge may succeed while the certificate authority is not allowed to issue by the CAA policy.
- Missing or incorrect CAA issue record
- CAA inherited from a parent domain
- Different issuewild policy for wildcard certificates
- Query CAA on the FQDN and parent names
- Check issue and issuewild values
- Verify TTL
- Correct only the component confirmed by the checks
- Retest the original symptom after the change
- Escalate with collected evidence when the cause remains unclear
Contextual technician plan
Perform this check and preserve the observed result before changing configuration.
“Query CAA on the FQDN and parent names” should produce an observation that clearly confirms or rules out “Missing or incorrect CAA issue record”.
If the observation is normal, lower “Missing or incorrect CAA issue record” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Missing or incorrect CAA issue record” first. Related action: Correct only the component confirmed by the checks.
Perform this check and preserve the observed result before changing configuration.
“Check issue and issuewild values” should produce an observation that clearly confirms or rules out “CAA inherited from a parent domain”.
If the observation is normal, lower “CAA inherited from a parent domain” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “CAA inherited from a parent domain” first. Related action: Retest the original symptom after the change.
Perform this check and preserve the observed result before changing configuration.
“Verify TTL” should produce an observation that clearly confirms or rules out “Different issuewild policy for wildcard certificates”.
If the observation is normal, lower “Different issuewild policy for wildcard certificates” in the ranking and continue with the next distinct check.
If the observation is abnormal, keep the evidence and investigate “Different issuewild policy for wildcard certificates” first. Related action: Escalate with collected evidence when the cause remains unclear.
Repeat the same validation test after the correction and confirm the original symptom is gone. Validate stability before closing the incident.
Before changing configuration, record the current value and a way back.
Escalate with the exact symptom, scope, timestamp and completed checks when the issue remains unresolved.
+Open the complete detailed guideDetailed explanations and original troubleshooting content.
The ACME challenge may succeed while the certificate authority is not allowed to issue by the CAA policy.
Likely causes
- Missing or incorrect CAA issue record
- CAA inherited from a parent domain
- Different issuewild policy for wildcard certificates
- Old DNS configuration still cached
Checks in priority order
- Query CAA on the FQDN and parent names
- Check issue and issuewild values
- Verify TTL
- Retry issuance after propagation
When to escalate
Escalate when the failure affects multiple users, a production dependency is unavailable, or logs show a component outside your control. Include timestamps, scope, tests already performed, and the last known working state.