TLS Won't Renew – Challenge Failure

A few weeks ago I got TLS renewal errors (“has multiple A records”). Based on help articles, I made www the primary domain. Now I’m getting “SniCertificate::CertificateInvalidError: Unable to verify challenge for *” instead. I searched the troubleshooting page I was directed to and it had no info about the challenge.

I’m using netlify’s DNS which gives very few options that I can configure. What can I do to get this working?

hey curi, which domain is this regarding? and i got the same error for too. All my domains are set up the same way so it may apply to them all.

By the time I took a look just now, SSL is working well on both domains. I don’t see any problems in your DNS config or certificates.

Note that our system does retry all certificate provisioning automatically when there is an error, so it is likely that our automation repaired the error in the meantime.

Please let me know if you’re still seeing any unexpected behavior and include some more details (screenshot of your browser, perhaps?) if so!