3 ms·
DNS-01 is currently available (at least I believe it is -- I think I saw something about its availability recently). The issue is that I will need to write my o
by kbuck 10y ago
DNS-01 is currently available (at least I believe it is -- I think I saw something about its availability recently). The issue is that I will need to write my own DNS-01 client.
Running a HTTPd on each server is a bad idea for us since it increases DDoS attack surface area. This would essentially have the same distribution issue that I would need to solve with a DNS-01 client as well, so either way new code is required.
- pfg 10y agoYep, dns-01 went live in January. If your DNS server happens to support RFC 2136, take a look at lego[1] - some other provider-specific plugins for DNS are included as well. [1]: https://github.com/xenolf/lego https://github.com/xenolf/lego
- kbuck 10y agoI'm not too worried about the DNS integration; we have a fairly easily-automatable DNS infrastructure owing to the fact that we're frequently changing records around. I'll have to see if we can take advantage of lego to avoid some work on our side.
- walrus01 10y agoYou could have a very lightweight http server that only runs for the 30-second period of time needed to communicate with the ACME server for the certificate issue...
- kbuck 10y agoMany of our servers whitelist ports to harden themselves against attacks, and this whitelisting may not be done on the server itself (e.g. some of our servers do it on upstream networking equipment). We would also have to run some sort of HTTPd on ALL the servers in each round-robin being verified, which would essentially mean all our servers. DNS-01 is a much better fit for us (and our DNS server software makes it somewhat less painful).