Problems with powerdns and acme.sh and dns_pdns

Frank Altpeter via Pdns-users <[email protected]> Wed, 15 Apr 2026 12:57:56 +0200
Newsgroups gmane.network.dns.powerdns.user
Message-ID <CANx=-wPvoQVt8CfTr50kb9BYSvw8890XG9srwoYWE2yXY368Gg@mail.gmail.com>
--===============7356798853304566547==
Content-Type: multipart/alternative; boundary="0000000000008ebf2e064f7d9728"

--0000000000008ebf2e064f7d9728
Content-Type: text/plain; charset="UTF-8"

Hi there,

I'm currently struggling with the configuration of running acme.sh against
a powerdns with dns_pdns on DNSSEC enabled zones.

First of all: Yes I know that my dns server is quite old (4.4.1) but for
reasons beyond my control I can't upgrade that one at the moment. It's on
the TODO but requires some other (non-technical) steps for it.

However... the powerdns is configured to serve my domain with DNSSEC, so it
is configured with the following metadata items:

Metadata items:
SOA-EDIT INCEPTION-INCREMENT
SOA-EDIT-API INCREASE

Normal operation works fine. The secondary dns gets the zone without
problems and manual updates to the zone transfer as expected.

When I run acme.sh to renew a certificate within this zone, the API
connection via dns_pdns works fine, the acme challenge gets inserted into
the zone, but the serial is not increased and therefore the secondary does
not get the notification to fetch the added acme challenge records, and so
the validation from the letsencrypt servers fails.

So... is there any idea what I should test to fix this?
Any pointer (besides "upgrade your pdns") is welcome :-)


p-dns:~ # pdnsutil show-zone domain.net
This is a Master zone
Last SOA serial number we notified: 2026020626 == 2026020626 (serial in the
database)
Metadata items:
SOA-EDIT INCEPTION-INCREMENT
SOA-EDIT-API INCREASE
Zone has NSEC semantics

s-dns:~ # pdnsutil show-zone domain.net
This is a Slave zone
Masters: 1.2.3.4:53 [1:2:3:4]:53
Last time we got update from master: Wed 2026-04-15 12:37:26
SOA serial in database: 2026040901
Refresh interval: 28800 seconds
Metadata items:
PRESIGNED 1
Zone is presigned
Zone has NSEC semantics

# dig +short @p-dns.domain.net domain.net soa
p-dns.domain.net. hostmaster.domain.net. 2026040901 28800 3600 604800 86400

# dig +short @p-dns.domain.net domain.net soa
p-dns.domain.net. hostmaster.domain.net. 2026040901 28800 3600 604800 86400

Regards
Frank

-- 
FA-RIPE || https://linktr.ee/frank42

--0000000000008ebf2e064f7d9728
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Hi there,</div><div><br></div><div>I&#39;m currently =
struggling with the configuration of running acme.sh against a powerdns wit=
h dns_pdns on DNSSEC enabled zones.</div><div><br></div><div>First of all: =
Yes I know that my dns server is quite old (4.4.1) but for reasons beyond m=
y control I can&#39;t upgrade that one at the moment. It&#39;s on the TODO =
but requires some other (non-technical) steps for it.</div><div><br></div><=
div>However... the powerdns is configured to serve my domain with DNSSEC, s=
o it is configured with the following=C2=A0metadata items:<br><br>Metadata =
items: <br>	SOA-EDIT	INCEPTION-INCREMENT<br>	SOA-EDIT-API	INCREASE<br></div=
><div><br></div><div>Normal operation=C2=A0works fine. The secondary dns ge=
ts the zone without problems and manual updates to the zone transfer as exp=
ected.</div><div><br></div><div>When I run acme.sh to renew a certificate w=
ithin this zone, the API connection via dns_pdns works fine, the acme chall=
enge gets inserted into the zone, but the serial is not increased and there=
fore the secondary does not get the notification to fetch the added acme ch=
allenge records, and so the validation from the letsencrypt servers fails.<=
/div><div><br></div><div>So... is there any idea what I should test to fix =
this?<br>Any pointer (besides &quot;upgrade your pdns&quot;) is welcome :-)=
</div><div><br></div><div><br></div><div>p-dns:~ # pdnsutil show-zone <a hr=
ef=3D"http://domain.net">domain.net</a><br>This is a Master zone<br>Last SO=
A serial number we notified: 2026020626 =3D=3D 2026020626 (serial in the da=
tabase)<br>Metadata items: <br>	SOA-EDIT	INCEPTION-INCREMENT<br>	SOA-EDIT-A=
PI	INCREASE<br>Zone has NSEC semantics<br></div><div><br></div><div>s-dns:~=
 # pdnsutil show-zone <a href=3D"http://domain.net">domain.net</a></div>Thi=
s is a Slave zone<br>Masters: <a href=3D"http://1.2.3.4:53">1.2.3.4:53</a> =
[1:2:3:4]:53 <br>Last time we got update from master: Wed 2026-04-15 12:37:=
26<br>SOA serial in database: 2026040901<br>Refresh interval: 28800 seconds=
<br>Metadata items: <br>	PRESIGNED	1<br>Zone is presigned<br>Zone has NSEC =
semantics<br><div><br></div><div># dig=C2=A0+short=C2=A0@<a href=3D"http://=
p-dns.domain.net">p-dns.domain.net</a> <a href=3D"http://domain.net">domain=
.net</a> soa<br><a href=3D"http://p-dns.domain.net">p-dns.domain.net</a>. <=
a href=3D"http://hostmaster.domain.net">hostmaster.domain.net</a>. 20260409=
01 28800 3600 604800 86400</div><div><br></div><div># dig=C2=A0+short=C2=A0=
@<a href=3D"http://p-dns.domain.net">p-dns.domain.net</a> <a href=3D"http:/=
/domain.net">domain.net</a> soa<br></div><div><a href=3D"http://p-dns.domai=
n.net">p-dns.domain.net</a>. <a href=3D"http://hostmaster.domain.net">hostm=
aster.domain.net</a>. 2026040901 28800 3600 604800 86400<br></div><div><br>=
</div><div>Regards</div><div>Frank</div><div><br></div><span class=3D"gmail=
_signature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"=
 data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div dir=3D"ltr"><div>=
FA-RIPE || <a href=3D"https://linktr.ee/frank42" target=3D"_blank">https://=
linktr.ee/frank42</a><br></div></div></div></div></div>

--0000000000008ebf2e064f7d9728--

--===============7356798853304566547==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Pdns-users mailing list
[email protected]
https://mailman.powerdns.com/mailman/listinfo/pdns-users

--===============7356798853304566547==--