3 ms·
For those not running apache, or afraid of messing with their front end settings. I found the DNS verification system for Let's Encrypt to be a breeze, especial
by phn 10y ago
For those not running apache, or afraid of messing with their front end settings. I found the DNS verification system for Let's Encrypt to be a breeze, especially when your DNS provider has an API of some sort (CloudFlare, Route53, etc.)
- niij 10y agoDo you have any links or tips for getting DNS verification working? Is it simply setting a token on the domain's DNS, then having LE issue a cert with all requested subdomains?
- marvinpinto 10y agoI use the lego[1] client for DNS verification and it works pretty well so far (more deets[2]). [1]: https://github.com/xenolf/lego https://github.com/xenolf/lego [2]: https://disjoint.ca/til/2016/03/26/lets-encrypt-tls-certificates-using-route53-dns-verification/ https://disjoint.ca/til/2016/03/26/lets-encrypt-tls-certific...
- phn 10y agoUnder the hood, yes. You set a TXT record with the challenge token and the certs are issued when LE's servers are able to verify it (a few minutes at most for it to propagate, generally). However, people already made hooks that take care of that for you for some providers, for example, the CloudFlare one I experimented with: https://github.com/kappataumu/letsencrypt-cloudflare-hook https://github.com/kappataumu/letsencrypt-cloudflare-hook