4 ms·
I solve this problem by owning a TLD only for internal use and using letsencrypt’s DNS challenge method: https://news.ycombinator.com/item?id=24543434 https://
by jackweirdy 6y ago
I solve this problem by owning a TLD only for internal use and using letsencrypt’s DNS challenge method:
https://news.ycombinator.com/item?id=24543434 https://news.ycombinator.com/item?id=24543434
- artificialLimbs 6y agoThis is intriguing. Is there a book or resource you'd recommend that I could use to learn more?
- jackweirdy 6y agoProbably the best recommendation I can give is the certbot cloudflare plugin docs: https://certbot-dns-cloudflare.readthedocs.io/en/stable/ https://certbot-dns-cloudflare.readthedocs.io/en/stable/ I use this in my own setup. When letsencrypt provides a DNS challenge, the cloudflare plugin will complete it. The only requirements are (a) owning a domain (b) having cloudflare control it (c) somewhere to run the certbot renewal cron job If you don't like b, you can swap out cloudflare for any of the other DNS providers. I chose it because it's free. For devices which can't run certbot (e.g. a managed network switch) I run certbot on a raspberry pi and use a deployment hook to deploy it. The code for deploying to a tp link switch is open source: https://github.com/NotBobTheBuilder/cert-deploy-t1600g-28ps https://github.com/NotBobTheBuilder/cert-deploy-t1600g-28ps