Due to the dispute with the web design agency, we changed the name servers of our domain name, switched to another host and we are not using Cloudflare anymore. We get the following error in LetsEncrypt installation. Since we don’t have access to the Cloudflare panel, we can’t purge or delete the cache. What is your advice?
DNSLookupFailed
FATAL
A fatal issue occurred during the DNS lookup process for /fulmaks.com/CAA.
DNS response for /fulmaks.com had fatal DNSSEC issues: validation failure <fulmaks.com. CAA IN>: No DNSKEY record from 173.245.58.51 for key /fulmaks.com. while building chain of trust
TXTRecordError
FATAL
An error occurred while attempting to lookup the TXT record on _acme-challenge.fulmaks.com . Any resolver errors that the Let's Encrypt CA encounters on this record will cause certificate issuance to fail.
DNS response for _acme-challenge.fulmaks.com had fatal DNSSEC issues: validation failure <_acme-challenge.fulmaks.com. TXT IN>: No DNSKEY record from 2400:cb00:2049:1::adf5:3b29 for key fulmaks.com. while building chain of trust
The nameservers are correctly set and do not point to Cloudflare any more. So, at this point you are not using any Cloudflare service.
However, your DNSSEC configuration is broken and probably still has the Cloudflare configuration, you need to change that at your registrar, to reflect whatever Digital Ocean provided you with. That is a question for them however, Cloudflare is not involved any more.
Thank you. Nameservers correctly pointed to digital ocean 24 hours ago but we are still getting DNSSEC error while installing SSL. I think need more time?
There is no DS record on my domain registrar control panel. When changing name server from CloudFlare to another should i remove DS records on cloudflare too?
Some registrars do not have DNSSEC on their control panels. How did you enable DNSSEC in the first place? Probably best to open a support ticket with your registrar.
Moral of the story: Never let another company have exclusive control over your domain.
We changed name servers Cloudflare to Digital Ocean on our registrar. 50 + hours passed but sitill not working. When name servers directed to Cloudflare are changed, does it take longer to propagading than any of provider?
We have no access Cloudflare control panel to remove domain