[Letsencrypt-devel] Bug#869255: Bug#869255: Bug#869255: DNS: wait a bit longer when NXDOMAIN returned in response to challenges

Mattia Rizzolo mattia at debian.org
Sun Jul 30 14:37:39 UTC 2017


On Sat, Jul 29, 2017 at 10:56:15PM +0200, zebian at umlaeute.mur.at wrote:
> ouch, are you suggesting to fix a race condition by adding longer timeouts?

No.
Upstream suggested to modify the hook to wait until the update actually
happened, as for example done in
https://github.com/bennettp123/dehydrated-email-notify-hook/blob/master/hook.sh

> anyhow, i've a hook-script for dehydrated in the NEW queue since about 1.5
> months [1] that seems to fix this issue, by polling all DNS servers that are
> authoritative for the given NS entry *until* the relevant records show up.

yes, something like that.

-- 
regards,
                        Mattia Rizzolo

GPG Key: 66AE 2B4A FCCF 3F52 DA18  4D18 4B04 3FCD B944 4540      .''`.
more about me:  https://mapreri.org                             : :'  :
Launchpad user: https://launchpad.net/~mapreri                  `. `'`
Debian QA page: https://qa.debian.org/developer.php?login=mattia  `-
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.alioth.debian.org/pipermail/letsencrypt-devel/attachments/20170730/4656ccd5/attachment.sig>


More information about the Letsencrypt-devel mailing list