@pilot

Are you sure you want to delete the question?

If your question is resolved, you may close it.

Leaving a resolved question undeleted may help others!

We hope you find it useful!

Automated Certificate Management has failed (Incorrect DNS Settings)

Discussion

Herokuから以下のメールが来た

Automated Certificate Management has failed for the following domains:
Domain	Reason
<my-domain-name>	Incorrect DNS Settings

Dyno/アプリが起動していなかったのが原因だったので
ミニマムアプリをデプロイ・起動してACMをリフレッシュした

# 1. リポジトリをクローン
heroku git:clone -a <my-app-name>
cd <my-app-name>

# 2. package.json を作成
@'
{"scripts":{"start":"node index.js"}}
'@ | Out-File -Encoding utf8 package.json

# 3. index.js を作成
@'
require('http').createServer((_, res) => res.end('ok')).listen(process.env.PORT)
'@ | Out-File -Encoding utf8 index.js

# 4. Procfile を作成(BOMなしASCIIで出力)
"web: node index.js" | Out-File -FilePath Procfile -Encoding ascii

# 5. コミット&プッシュ
git add .
git commit -m "minimum app"
git push heroku main

# 6. Dynoが起動したらACMをリフレッシュ
heroku certs:auto:refresh -a <my-app-name>

Dynoの起動確認・ACMのステータス確認はHerokuダッシュボード(Settings画面)で行った

0 likes

解決おつかれさまです。補足で2点だけ。

1. 根本原因の補足

ACMが「Incorrect DNS Settings」を返すのは、DNSの問題だけじゃなく「Herokuがドメインの所有権を検証できない」状態全般で出ます。Dynoが停止してるとHeroku側がHTTP-01チャレンジ(Let's Encryptの検証リクエスト)を受けられないので、DNS設定が正しくてもこのエラーになります。

つまりエラーメッセージが嘘をついてます。「Incorrect DNS Settings」じゃなくて「Certificate Validation Failed」が正確。Herokuのエラーメッセージに騙されるパターンなので、同じ状況の人がこの記事に辿り着くと助かると思います。

2. 再発防止のTips

Dynoが寝ないようにするなら、無料プランでなければ heroku ps:scale web=1 で明示的にDynoを起動状態に固定できます。また heroku certs:auto:info でACMのステータスを定期確認するスクリプトを組んでおくと、証明書切れの前に気づけます。

# ACMステータス確認(cronで週1回など)
heroku certs:auto -a <my-app-name> | grep -i status

dosanko_tousan — 非エンジニア・主夫。Claude(Anthropic)と組んで検証しています。

1Like

Your answer might help someone💌