Page MenuHomePhabricator
Paste P7746

certcentral1001 logs during wildcard certificate issuance
ActivePublic

Authored by Vgutierrez on Oct 31 2018, 4:04 PM.
Oct 31 15:49:33 certcentral1001 systemd[1]: Stopping Central Certificates Service...
Oct 31 15:49:33 certcentral1001 systemd[1]: Stopped Central Certificates Service.
Oct 31 15:49:33 certcentral1001 systemd[1]: Started Central Certificates Service.
Oct 31 15:49:35 certcentral1001 certcentral-backend[25344]: SIGHUP received
Oct 31 15:49:35 certcentral1001 certcentral-backend[25344]: Missing/invalid DNS zone updater CMD timeout, using the default one: 60.00
Oct 31 15:49:35 certcentral1001 certcentral-backend[25344]: Creating initial self-signed certificate for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:35 certcentral1001 certcentral-backend[25344]: Creating initial self-signed certificate for pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:35 certcentral1001 certcentral-backend[25344]: Starting main loop...
Oct 31 15:49:35 certcentral1001 certcentral-backend[25344]: Handling new certificate event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:36 certcentral1001 certcentral-backend[25344]: Triggering DNS zone update...
Oct 31 15:49:36 certcentral1001 certcentral-backend[25344]: Running subprocess ['/usr/local/bin/certcentral-gdnsd-sync.py', '--remote-servers', 'authdns1001.wikimedia.org', 'authdns2001.wikimedia.org', 'multatuli.wikimedia.org', '--', '_acme-challenge.pinkunicorn.wikimedia.org', 't7_OX4Ohp_WNz8g2Sr6V1NV_UVWOxjbEpi0-rsOLkAU', '_acme-challenge.pinkunicorn.wikimedia.org', 'f8vwE9aDHnkujmcnnzrTruPjUKcKJ5l3PayZHV4be5Q']
Oct 31 15:49:39 certcentral1001 certcentral-backend[25344]: Handling pushed CSR event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:39 certcentral1001 certcentral-backend[25344]: Handling validated challenges event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:39 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:41 certcentral1001 certcentral-backend[25344]: ACME Directory hasn't validated the challenge(s) yet for certificate pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:41 certcentral1001 certcentral-backend[25344]: Handling new certificate event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:41 certcentral1001 certcentral-backend[25344]: Triggering DNS zone update...
Oct 31 15:49:41 certcentral1001 certcentral-backend[25344]: Running subprocess ['/usr/local/bin/certcentral-gdnsd-sync.py', '--remote-servers', 'authdns1001.wikimedia.org', 'authdns2001.wikimedia.org', 'multatuli.wikimedia.org', '--', '_acme-challenge.pinkunicorn.wikimedia.org', 'f8vwE9aDHnkujmcnnzrTruPjUKcKJ5l3PayZHV4be5Q', '_acme-challenge.pinkunicorn.wikimedia.org', 't7_OX4Ohp_WNz8g2Sr6V1NV_UVWOxjbEpi0-rsOLkAU']
Oct 31 15:49:44 certcentral1001 certcentral-backend[25344]: Handling pushed CSR event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:44 certcentral1001 certcentral-backend[25344]: Handling validated challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:44 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:46 certcentral1001 certcentral-backend[25344]: ACME Directory hasn't validated the challenge(s) yet for certificate pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:51 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Problem getting certificate for certificate pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 387, in get_certificate
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: finished_order = self.acme_client.poll_and_finalize(order, deadline=deadline)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 635, in poll_and_finalize
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self.finalize_order(orderr, deadline)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 674, in finalize_order
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: self._post(orderr.body.finalize, wrapped_csr)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 93, in _post
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self.net.post(*args, **kwargs)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1082, in post
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self._post_once(*args, **kwargs)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1096, in _post_once
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self._check_response(response, content_type=content_type)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 956, in _check_response
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: raise messages.Error.from_json(jobj)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: acme.messages.Error: urn:ietf:params:acme:error:malformed :: The request message was malformed :: Order's status ("valid") is not acceptable for finalization
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: The above exception was the direct cause of the following exception:
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/certcentral.py", line 620, in _handle_pushed_challenges
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: certificate = session.get_certificate(csr_id)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 396, in get_certificate
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: raise ACMEError('Unable to get certificate') from finalize_error
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: certcentral.acme_requests.ACMEError: Unable to get certificate
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Problem getting certificate for certificate pinkunicorn-wildcard / rsa-2048
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 387, in get_certificate
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: finished_order = self.acme_client.poll_and_finalize(order, deadline=deadline)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 635, in poll_and_finalize
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self.finalize_order(orderr, deadline)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 674, in finalize_order
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: self._post(orderr.body.finalize, wrapped_csr)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 93, in _post
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self.net.post(*args, **kwargs)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1082, in post
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self._post_once(*args, **kwargs)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1096, in _post_once
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: return self._check_response(response, content_type=content_type)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 956, in _check_response
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: raise messages.Error.from_json(jobj)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: acme.messages.Error: urn:ietf:params:acme:error:malformed :: The request message was malformed :: Order's status ("valid") is not acceptable for finalization
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: The above exception was the direct cause of the following exception:
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/certcentral.py", line 620, in _handle_pushed_challenges
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: certificate = session.get_certificate(csr_id)
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 396, in get_certificate
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: raise ACMEError('Unable to get certificate') from finalize_error
Oct 31 15:49:52 certcentral1001 certcentral-backend[25344]: certcentral.acme_requests.ACMEError: Unable to get certificate
Oct 31 15:49:57 certcentral1001 certcentral-backend[25344]: Handling new certificate event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:49:57 certcentral1001 certcentral-backend[25344]: Triggering DNS zone update...
Oct 31 15:49:57 certcentral1001 certcentral-backend[25344]: Running subprocess ['/usr/local/bin/certcentral-gdnsd-sync.py', '--remote-servers', 'authdns1001.wikimedia.org', 'authdns2001.wikimedia.org', 'multatuli.wikimedia.org', '--', '_acme-challenge.pinkunicorn.wikimedia.org', 'f8vwE9aDHnkujmcnnzrTruPjUKcKJ5l3PayZHV4be5Q', '_acme-challenge.pinkunicorn.wikimedia.org', 't7_OX4Ohp_WNz8g2Sr6V1NV_UVWOxjbEpi0-rsOLkAU']
Oct 31 15:50:00 certcentral1001 certcentral-backend[25344]: Handling pushed CSR event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:50:00 certcentral1001 certcentral-backend[25344]: Handling validated challenges event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:50:00 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:50:02 certcentral1001 certcentral-backend[25344]: Pushing the new certificate for pinkunicorn-wildcard / ec-prime256v1
Oct 31 15:50:02 certcentral1001 certcentral-backend[25344]: Handling new certificate event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:03 certcentral1001 certcentral-backend[25344]: Triggering DNS zone update...
Oct 31 15:50:03 certcentral1001 certcentral-backend[25344]: Running subprocess ['/usr/local/bin/certcentral-gdnsd-sync.py', '--remote-servers', 'authdns1001.wikimedia.org', 'authdns2001.wikimedia.org', 'multatuli.wikimedia.org', '--', '_acme-challenge.pinkunicorn.wikimedia.org', 'f8vwE9aDHnkujmcnnzrTruPjUKcKJ5l3PayZHV4be5Q', '_acme-challenge.pinkunicorn.wikimedia.org', 't7_OX4Ohp_WNz8g2Sr6V1NV_UVWOxjbEpi0-rsOLkAU']
Oct 31 15:50:05 certcentral1001 certcentral-backend[25344]: Handling pushed CSR event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:05 certcentral1001 certcentral-backend[25344]: Handling validated challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:05 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:07 certcentral1001 certcentral-backend[25344]: ACME Directory hasn't validated the challenge(s) yet for certificate pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:12 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: Problem getting certificate for certificate pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 387, in get_certificate
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: finished_order = self.acme_client.poll_and_finalize(order, deadline=deadline)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 635, in poll_and_finalize
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: return self.finalize_order(orderr, deadline)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 674, in finalize_order
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: self._post(orderr.body.finalize, wrapped_csr)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 93, in _post
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: return self.net.post(*args, **kwargs)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1082, in post
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: return self._post_once(*args, **kwargs)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1096, in _post_once
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: return self._check_response(response, content_type=content_type)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 956, in _check_response
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: raise messages.Error.from_json(jobj)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: acme.messages.Error: urn:ietf:params:acme:error:malformed :: The request message was malformed :: Order's status ("valid") is not acceptable for finalization
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: The above exception was the direct cause of the following exception:
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/certcentral.py", line 620, in _handle_pushed_challenges
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: certificate = session.get_certificate(csr_id)
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 396, in get_certificate
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: raise ACMEError('Unable to get certificate') from finalize_error
Oct 31 15:50:13 certcentral1001 certcentral-backend[25344]: certcentral.acme_requests.ACMEError: Unable to get certificate
Oct 31 15:50:18 certcentral1001 certcentral-backend[25344]: Handling new certificate event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:19 certcentral1001 certcentral-backend[25344]: Triggering DNS zone update...
Oct 31 15:50:19 certcentral1001 certcentral-backend[25344]: Running subprocess ['/usr/local/bin/certcentral-gdnsd-sync.py', '--remote-servers', 'authdns1001.wikimedia.org', 'authdns2001.wikimedia.org', 'multatuli.wikimedia.org', '--', '_acme-challenge.pinkunicorn.wikimedia.org', 'f8vwE9aDHnkujmcnnzrTruPjUKcKJ5l3PayZHV4be5Q', '_acme-challenge.pinkunicorn.wikimedia.org', 't7_OX4Ohp_WNz8g2Sr6V1NV_UVWOxjbEpi0-rsOLkAU']
Oct 31 15:50:21 certcentral1001 certcentral-backend[25344]: Handling pushed CSR event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:21 certcentral1001 certcentral-backend[25344]: Handling validated challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:21 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:27 certcentral1001 certcentral-backend[25344]: ACME Directory hasn't validated the challenge(s) yet for certificate pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: Problem getting certificate for certificate pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 387, in get_certificate
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: finished_order = self.acme_client.poll_and_finalize(order, deadline=deadline)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 635, in poll_and_finalize
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: return self.finalize_order(orderr, deadline)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 674, in finalize_order
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: self._post(orderr.body.finalize, wrapped_csr)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 93, in _post
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: return self.net.post(*args, **kwargs)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1082, in post
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: return self._post_once(*args, **kwargs)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 1096, in _post_once
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: return self._check_response(response, content_type=content_type)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/acme/client.py", line 956, in _check_response
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: raise messages.Error.from_json(jobj)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: acme.messages.Error: urn:ietf:params:acme:error:malformed :: The request message was malformed :: Order's status ("valid") is not acceptable for finalization
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: The above exception was the direct cause of the following exception:
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: Traceback (most recent call last):
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/certcentral.py", line 620, in _handle_pushed_challenges
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: certificate = session.get_certificate(csr_id)
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: File "/usr/lib/python3/dist-packages/certcentral/acme_requests.py", line 396, in get_certificate
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: raise ACMEError('Unable to get certificate') from finalize_error
Oct 31 15:50:32 certcentral1001 certcentral-backend[25344]: certcentral.acme_requests.ACMEError: Unable to get certificate
Oct 31 15:50:37 certcentral1001 certcentral-backend[25344]: Handling new certificate event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:38 certcentral1001 certcentral-backend[25344]: Triggering DNS zone update...
Oct 31 15:50:38 certcentral1001 certcentral-backend[25344]: Running subprocess ['/usr/local/bin/certcentral-gdnsd-sync.py', '--remote-servers', 'authdns1001.wikimedia.org', 'authdns2001.wikimedia.org', 'multatuli.wikimedia.org', '--', '_acme-challenge.pinkunicorn.wikimedia.org', 'f8vwE9aDHnkujmcnnzrTruPjUKcKJ5l3PayZHV4be5Q', '_acme-challenge.pinkunicorn.wikimedia.org', 't7_OX4Ohp_WNz8g2Sr6V1NV_UVWOxjbEpi0-rsOLkAU']
Oct 31 15:50:40 certcentral1001 certcentral-backend[25344]: Handling pushed CSR event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:40 certcentral1001 certcentral-backend[25344]: Handling validated challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:41 certcentral1001 certcentral-backend[25344]: Handling pushed challenges event for pinkunicorn-wildcard / rsa-2048
Oct 31 15:50:43 certcentral1001 certcentral-backend[25344]: Pushing the new certificate for pinkunicorn-wildcard / rsa-2048