domain: grillmagazine.gr
I have installed Let’s encrypt on my server and under Cloudflare’s SSL/TLS settings, I was using the Full (strict) setting. I have also added a DNS record of NS _acme-challenge so I will not have to manually update the site’s acme-challenge on Cloudflare. Everything was working fine but around half a month ago, the site was not accessible via any browser, and I was getting an SSL-related error.
After I checked the server (everything was working well) I saw on Cloudflare that the Universal SSL was pending. I disabled and re-enabled Universal SSL, but after 5 days now it still says “Cloudflare will validate the certificate on your behalf. No action is required.”
It seems to be stuck for some reason I can not figure out why.
So far, DNSSEC wasn’t being used.
Cloudflare nameservers are correctly set.
Did you used or were using some kind of a CNAME setup maybe? Or some 3rd-party integrator or hosting partner of Cloudflare for your domain name?
As far as I can see, currently, you’re either using “Pause Cloudflare for this Website” option, or some of the DNS records are unproxied (DNS-only)?
Have you tried contacting Cloudflare Support about this issue so far?
Kindly, I’d suggest you to write a ticket to Cloudflare support due to your account and/or domain issue and share the ticket number here with us so we could escalate this issue:
Login to Cloudflare and then contact Cloudflare Support by clicking on the Get More Help button. If you get automatic reply, reply and indicate to it you need more help and reference to this topic
Or send an an e-mail to support[at]cloudflare[dot]com from your e-mail associated with your Cloudflare account
I was using LE’s SSL cert on the origin host and I am using the setting I described in my last reply so that the acme-challenge can be updated correctly every 90 days that the SSL needs to be updated.
I have tried to download a cURL for windows and run it through cmd, but I might be doing something wrong. Digicert must also be enabled on the origin server? Currently let’s encrypt is a cron Job handled from the server itself.
I don’t know what this is exactly. I can see that is not enabled on the SSL tab.
No special CNAME setups. Just the usual www. and nothing more.
I have paused Cloudflare for this domain and re-enabled it to test If this was creating a problem with issuing the SSL. After that, I just unproxied the DNS records because the site was not accessible. It was popping an SSL error and the site was offline.
I have created a support ticket from my Cloudflare account and the ticket ID is 2511098.