3 ms·
Years ago, an HTTPS-01 challenge was proposed that would have operated like HTTP-01 except using port 443. However, concerns were raised about the safety of thi
by zjs 8y ago
Years ago, an HTTPS-01 challenge was proposed that would have operated like HTTP-01 except using port 443. However, concerns were raised about the safety of this challenge.
I can't find the relevant discussion thread at the moment, but I believe this was because the default configuration in some shared hosting environments would have allowed users to receive certificates to others' websites.
Edit: https://mailarchive.ietf.org/arch/msg/acme/B9vhPSMm9tcNoPrTE_LNhnt0d8U https://mailarchive.ietf.org/arch/msg/acme/B9vhPSMm9tcNoPrTE...
- aidenn0 8y agoThat's an amazingly terrible default behavior. This is why we can't have nice things... [edit] This also means I should probably make a PR for automating DNS-01 with my DNS provider (he.net).
- zjs 8y agoPRs to add support for new DNS providers have been slow to merge, in part because the support story is complex[0]. However, plugins need not live in the main Certbot repository. Maintaining a plugin yourself may be the lowest-friction way to build one right now (or may have its own challenges; I haven't tried that approach). Lexicon supports he.net[1] and Certbot provides a class for building Lexicon-based providers[2] with very little effort (although perhaps more effort and duplication than would be ideal[3][4]). 0: https://github.com/certbot/certbot/issues/6504 https://github.com/certbot/certbot/issues/6504 1: https://github.com/AnalogJ/lexicon/blob/master/lexicon/providers/henet.py https://github.com/AnalogJ/lexicon/blob/master/lexicon/provi... 2: https://github.com/certbot/certbot/blob/master/certbot/plugins/dns_common_lexicon.py https://github.com/certbot/certbot/blob/master/certbot/plugi... 3: https://github.com/certbot/certbot/issues/6178 https://github.com/certbot/certbot/issues/6178 4: https://github.com/certbot/certbot/issues/6621 https://github.com/certbot/certbot/issues/6621
- aidenn0 8y agoThanks for all that information!