When you add a website in the mybox panel, a free Let’s Encrypt SSL certificate is automatically activated. In some cases, however, certificate generation may fail. Below are the most common causes and steps to resolve the issue.
Table of Contents
1. Incorrect DNS Configuration
If your domain is not registered with mybox.com and is using external DNS, you must ensure that the domain is correctly pointed to the hosting server.
Check the following:
- DNS servers are set to:
ns1.mybox.comns2.mybox.com
OR
- The A record points directly to the server IP assigned to your hosting account
Additionally, ensure that:
- The
wwwsubdomain also has an A record pointing to the same IP address
After making DNS changes, remember that propagation may take time. SSL generation may fail temporarily until DNS changes fully propagate across the internet.
2. Domain Name Format Issues
In your dhosting panel, verify that the domain name:
- Contains only lowercase letters
- Does not include uppercase characters
Even small formatting inconsistencies can prevent SSL issuance.
3. DNSSEC Interference
If your domain is registered externally and DNSSEC is enabled, it may block successful validation for Let’s Encrypt certificates.
To resolve this:
- Disable DNSSEC at your domain provider if possible
If DNSSEC cannot be disabled, you may need to consider using a commercial SSL certificate instead.
4. Propagation Delays
After DNS changes, it may take some time before the domain is fully reachable worldwide. During this period:
- SSL generation may fail
- Website may be temporarily unavailable or partially accessible
- Validation checks may not pass immediately
Wait for propagation to complete before retrying certificate issuance.
5. When to Contact Support
If you have verified all of the above and the SSL certificate still fails to generate, the issue may require technical assistance from your hosting provider.
In that case, contact support and provide details of:
- Domain name
- DNS configuration
- Error message from SSL generation process
Conclusion
Most Let’s Encrypt SSL generation issues are caused by DNS misconfiguration, propagation delays, or DNSSEC conflicts. Carefully verifying DNS records and domain settings usually resolves the problem without further intervention.