2/12 domains SSL Edge Certificate 'Pending Validation' for over 24 hours

2 domains are still “Pending Validation”. It was like this for a couple weeks, more than 24 hours ago I disabled SSL for maybe 30-45+ minutes and enabled it again, now more than a day later they still haven’t updated.

I recently added 2 other domains and SSL worked just fine just shortly after. But 2 that have been added some weeks ago are still not updating, and disabling SSL and enabling it back didn’t solve the issue- as I’ve noticed this is the most suggested solution.

Can you by any chance share the domain names where this issue appears?

copytrade.me & gosocial.trade

for copytrade.me its this error: ERR_HTTP2_PROTOCOL_ERROR

for gosocial.trade its: ERR_SSL_VERSION_OR_CIPHER_MISMATCH

Almost the same problem as I previously posted here: Edge Certificates (pending validation Txt) 24hr+.

At the domain registrar for the domain copytrade.me, Porkbun, you have DNSSEC enabled, and as such DNS resolvers across the world expect that your domain’s DNS data also holds cryptographic DNSSEC signatures, and that they will validate according to the DS record set that has been set from the domain registrar.

However, this DS record does not match the one Cloudflare has provided, and as such, the cryptographic signatures Cloudflare currently adds to domain’s DNS data are invalid, when they are being compared with the DS record, which is the reason there are validation errors while trying to access your domain.

You have the following options to solve your problem:

→ If you want to have your domain’s DNS data to be protected with DNSSEC, do this:

  1. Log in to Porkbun, and then go to:
    Porkbun - Domain Name System Security (DNSSEC) for COPYTRADE.ME
    → Delete all the records you see under “Current DNSSEC Configuration” on this page.
    → Add a new one (typically using “dsData”) here, which MUST be a 100% match to the details you see in your Cloudflare account.
    → See: https://dash.cloudflare.com/?to=/:account/:zone/dns/settings

NOTE: The DNSSEC setup will literally be a fiasco, if the data that Porkbun holds is NOT a 100% match to what the Cloudflare page says. The details Cloudflare ask you to add will be shown when you expand the view by clicking on the "DS Record → " on the Cloudflare link above.

→ If you do not want your domain’s DNS data to be protected with DNSSEC, you can do this:

  1. Log in to Porkbun, and then go to:
    Porkbun - Domain Name System Security (DNSSEC) for COPYTRADE.ME
    → Delete all the records you see under “Current DNSSEC Configuration” on this page.

Same as above, and same procedures.

You have the following options to solve your problem:

→ If you want to have your domain’s DNS data to be protected with DNSSEC, do this:

  1. Log in to Porkbun, and then go to:
    Porkbun - Domain Name System Security (DNSSEC) for GOSOCIAL.TRADE
    → Delete all the records you see under “Current DNSSEC Configuration” on this page.
    → Add a new one (typically using “dsData”) here, which MUST be a 100% match to the details you see in your Cloudflare account.
    → See: https://dash.cloudflare.com/?to=/:account/:zone/dns/settings

NOTE: The DNSSEC setup will literally be a fiasco, if the data that Porkbun holds is NOT a 100% match to what the Cloudflare page says. The details Cloudflare ask you to add will be shown when you expand the view by clicking on the "DS Record → " on the Cloudflare link above.

→ If you do not want your domain’s DNS data to be protected with DNSSEC, you can do this:

  1. Log in to Porkbun, and then go to:
    Porkbun - Domain Name System Security (DNSSEC) for GOSOCIAL.TRADE
    → Delete all the records you see under “Current DNSSEC Configuration” on this page.

After making any of the changes to through Porkbun, please be advised that it may take between 48-96 hours to fully propagate worldwide, which neither Cloudflare, Porkbun, nor anyone else can expedite.

1 Like

Thank you! appreciate the help, didnt realize I had it enabled on those Deleted them, so will wait and see.

Thanks again!

Me ocurre el mismo problema con esta web: turnoregistrocivil. com