I moved my domain to Route53 and am now getting problems with Certbot renewal. Certbot has been running great for 4 years, but is now failing to renew.
When running sudo certbot renew --apache
i get this error:
Type: None
Detail: DNS problem: looking up A for somedomain.com: DNSSEC:
DNSKEY Missing; DNS problem: looking up AAAA for
somedomain.com: DNSSEC: DNSKEY Missing
DNSSEC is not, and hasn't ever been enabled for that domain in Route53, so not sure why Certbot fails.
I am at a loss here and would really like to use Route53 instead of the old domain manager.
EDIT: It looks like DNSSEC was activated by default for .se domains in the old domain manager (Loopia).
This is what i see under Registered domains in Route 53:
Using Ubuntu/Apache/python3-certbot-apache
UPDATE: I removed the record in Route53 Registered domains, but now i'm getting this error instead:
Detail: DNS problem: looking up A for somedomain.com: DNSSEC:
DNSKEY Missing; DNS problem: looking up AAAA for
somedomain.com: DNSSEC: Bogus