Hi, I've been using the native ACME client with dns-01 and the Data Plane API as the DNS agent (OVH provider), for a certificate covering both "sub.example.com" and "*.sub.example.com". Issuance kept failing, and the second "acme challenge_ready" sent by the Data Plane API was answered with "Couldn't find an ACME task using crt ... to set as ready!".
The cause is that both authorizations share the same identifier value, and acme_challenge_ready() marks every pending challenge matching the domain at once. The first call therefore triggers the validation before the second TXT record exists. Patch 2 makes each call account for a single challenge. Patch 1 is a small related fix I noticed on the same line: the domain comparison is a prefix match. Both patches are against master. The code was moved into acme_challenge_ready() for 3.5, so they won't apply as-is on 3.4 or 3.3, which have the same bug in cli_acme_chall_ready_parse(). I tested the equivalent change on top of 3.4.5: <TEST RESULT TO FILL IN>. I can send that 3.4 version if it helps with the backport. For reference, two related fixes were needed on the Data Plane API side for this setup, and are proposed there: - https://github.com/haproxytech/dataplaneapi/pull/417 - https://github.com/haproxytech/dataplaneapi/pull/418 One more thing I noticed but did not try to fix: with "challenge-ready dns", the pre-check only reads one TXT value per name, so with two records under the same "_acme-challenge" name, one of the two checks may never match. "cli,delay" works fine as a workaround in the meantime. Thanks, Jérôme Jérôme Billiras (2): BUG/MINOR: acme: exact domain match in acme_challenge_ready() BUG/MEDIUM: acme: only mark one challenge as ready per call doc/configuration.txt | 6 +++++- doc/lua-api/index.rst | 2 ++ src/acme.c | 14 +++++++++----- 3 files changed, 16 insertions(+), 6 deletions(-) -- 2.43.0

