2 ms·
You can achieve this without exposing any service. Let's Encrypt allows you to prove ownership of a domain through DNS 01 hooks. I personally use Duck DNS [1]
by stenioaraujo 8y ago
You can achieve this without exposing any service. Let's Encrypt allows you to prove ownership of a domain through DNS 01 hooks.
I personally use Duck DNS [1] for main internal domains, so I can have a certificate that most tools will recognize as valid. This saves me from adding my cert in every machine that will use that service.
I use dehydrated [2] to get a Let's Encrypt certificate using Duck DNS. There is a good article explaining that by Andreas Gohr [3].
[1] - https://www.duckdns.org/ https://www.duckdns.org/
[2] - https://github.com/lukas2511/dehydrated https://github.com/lukas2511/dehydrated
[3] - https://www.splitbrain.org/blog/2017-08/10-homeassistant_duckdns_letsencrypt#set_up_duckdns https://www.splitbrain.org/blog/2017-08/10-homeassistant_duc...