3 ms·
You don't even need the DNS to be local and expose anything at all to the internet. You can just as well push the TXT records to your usual DNS through your reg
by blattimwind 7y ago
You don't even need the DNS to be local and expose anything at all to the internet. You can just as well push the TXT records to your usual DNS through your registrar's API. This generally just works.
- cm2187 7y agoAgree. Though I would rather state it "just" works. You need to watch for DNS propagation, particularly if your DNS provider has some sort of CDN-like features (which is the case for instance of OVH) which makes the timing of the propagation non deterministic and non observable (you will likely be served by a different DNS server than the let's encrypt bot, how can you check it has propagated?). Let's encrypt will only check the DNS entry once, if it doesn't find it, it fails the authentication process and doesn't retry (contrary to the specs).
- dspillett 7y agoI still run my own DNS servers, so for me "your registrar's API" is directly poking bind and I only have myself to blame if anything goes wrong! Keeping the little DNS service for the certs means if I break that the rest stays sane. I also don't have to worry about delays transferring changes to zones if there are any intermittent network issues.