4 ms·
It doesn't. That was one of our mistakes and action items to fix. The original proxy was stood up quickly when it was first discovered IPv6 was broken and the
by bradfitz 3y ago
It doesn't. That was one of our mistakes and action items to fix.
The original proxy was stood up quickly when it was first discovered IPv6 was broken and the people standing up the proxy didn't know at the time how ACME worked.
We'll be changing it to just a TCP proxy.
- ikiris 3y ago> and the people standing up the proxy didn't know at the time how ACME worked yikes
- bradfitz 3y agoTo be fair, it didn't help the provider's docs were inconsistent about whether dns-01 or http-01 was to be used.
- PokestarFan 3y agoI've done enough fighting with Certbot to learn that the path of least resistance is to use dns-01 with the cloudflare plugin, and just make a very limited access key and store it on the servers that I am using to renew the cert.