Let's Debug

Test result for us.oracle.com using http-01

No CAA record on oracle.com (wildcard=false) contains the issuance domain "letsencrypt.org". You must either add an additional record to include "letsencrypt.org" or remove every existing CAA record. A list of the CAA records are provided in the details.
oracle.com. 0 IN CAA 0 issue "symantec.com"
oracle.com. 0 IN CAA 0 issue "digicert.com"
Fatal
No valid A or AAAA records could be ultimately resolved for us.oracle.com. This means that Let's Encrypt would not be able to to connect to your domain to perform HTTP validation, since it would not know where to connect to.
No A or AAAA records found.
Debug
CAA records control authorization for certificate authorities to issue certificates for a domain
oracle.com. 0 IN CAA 0 issue "symantec.com"
oracle.com. 0 IN CAA 0 issue "digicert.com"
Debug
The IANA public suffix is the TLD of the Registered Domain
The TLD for us.oracle.com is: com
Debug
The current status.io status for Let's Encrypt
Operational

Submitted Dec 6 02:29:51 2018. Sat in queue for 2ms. Completed in 5s. Hide verbose information.