Sorry, I forgot to fill in the test result before sending, here it is: I applied the equivalent of these two patches on top of the cli_acme_chall_ready_parse() function in 3.4.5 (isteq() for the exact match, and only marking one pending challenge per call), rebuilt, and tested against a real OVH-hosted zone with a certificate covering both « sub.example.com" and « *.sub.example.com".
Before the fix: the first "acme challenge_ready ... domain sub.example.com" marked both challenges ready at once, the validation started immediately, and failed since the second TXT record wasn't deployed yet. The second "acme challenge_ready" call then returned "Couldn't find an ACME task ... to set as ready!", since both challenges were already gone (one validated as pending, the other aborted). After the fix: the first call answers "Remaining challenges to deploy: 1", the second "All challenges ready! ...", and the certificate is issued correctly with both records present. Thanks, Jérôme

