Issue with SSL - Pending validation TXT

What is the name of the domain?

thepoundpuppies com

What is the error message?

Connecting to thepoundpuppies [dot] com… Host resolves to 104.21.74.204 which is a Cloudflare IP address Connection failed, OpenSSL/3.0.2: error:0A000410:SSL routines::sslv3 alert handshake failure.

What is the issue you’re encountering

SSL is stuck at pending validation txt

What steps have you taken to resolve the issue?

I checked everything and contacted my registrar (Spaceship)
They confirmed DNSSEC is off and everything is correct and recommended to contact Cloudflare.
I also checked this:
https://cf.sjr.dev/tools/check?ae44312e5c54497fb152724eed4cf458

Was the site working with SSL prior to adding it to Cloudflare?

No

What is the current SSL/TLS setting?

Full

What are the steps to reproduce the issue?

Open the website or chekc the link cf[dot]sjr[dot]dev/tools/check?ae44312e5c54497fb152724eed4cf458

It seems the domain was only registered today, so if you have only just added the domain to Cloudflare then wait for an hour or so for the SSL certificate to be generated.

Thnak you for your response.

I don’t think this is the case.
This week I’ve added 15 domains to Cloudflare from a different registrar (NameCheap) and everything ran perfectly in 5 minutes.

This time I added 2 domains from another registrar (Spaceship) and both of them are not receiving SSL certs in 4-6 hours.
I can wait 24 hours but my gut says something is wrong. I contacted Spaceship they confirm everything is correct on their side.

I tried to enable DNSSEC on my second domain but it doesn’t help either. I see the same issue with SSL cert.

Make sure Universal SSL is enabled here at the bottom of the page…
https://dash.cloudflare.com/?to=/:account/:zone/ssl-tls/edge-certificates

If it is, you can try to disable it, wait 2-3 minutes, then enable it again and see if that triggers the certificate issuance. Don’t do this repeatedly or you will hit rate limits of the CA and the certificate won’t be issued.

2 Likes

Thank you for your suggestion.

The Universal SSL was enabled.
I disabled it as suggested for ~5 minutes. I noticed the status of Edge certificate changed to Deleted. I then re-enabled it but it didn’t help.
The status is “Pending validation (TXT)” and SSL certificate is not provided.

The issue is still there.

I can wait 24 hours, but my recent experience with 15 other domains showed that it starts working within several minutes. Something is wrong here.

I can see 2 more TXT records were created. If the certificate doesn’t get issued you’ll need to raise a support ticket to ask for help.

1 Like

How can I raise the support ticket?

P.S. I’m on the free plan so the support ticket is probably not an option.

Free plan users can raise account, billing and registrar tickets. Go here…
https://dash.cloudflare.com/?to=/:account/support

After submitting the ticket you may not be able to view it in the dashboard, in that case follow up using the email sent by the ticketing system.

1 Like

Just an update that the issue is still there.
I plan to open a ticket.

Just an update.
I have submitted the support ticket but it was not successful since I’m on the free plan.

I lost hope of resolving it and started moving the domain out of Cloudflare.
When I checked it today I noticed that SSL certificate was successfully provided.

So the issue is resolved finally.
However, I have not figured out a root cause or solution. If this happens again, the only recipe is to wait or upgrade for 1 month just to receive support.