Users of the Let’s Encrypt non-profit certificate authority, governed by the community and offering certificates free of charge to anyone, have faced issues with domain validation for the .top zone via DNS when obtaining certificates. Since June 25, the DNS servers responsible for the top-level domain '.top' have ceased to accept requests from the Lets Encrypt resolvers used in the DNS-01 verification process, which is necessary for obtaining certificates with masks that allow coverage for a group of subdomains (e.g., *.example.com).
Initially, it was thought that the problem was related to DNSSEC, but it was later revealed that the failure in DNSSEC verification is not the cause but rather a symptom, and the DNS servers for the '.top' domain are returning errors for all Lets Encrypt requests, indicative of deliberate blocking. Let’s Encrypt staff are trying to reach the owners of the NS servers for .top, but so far without success. domain top, but so far unsuccessfully.
Source: opennet.ru
