3 ms·
> Sadly certbot doesn't do (or it didn't) CNAME redirects for ACME. Are you certain? Not at a real machine at the moment so hard for me to dig into the details
by rdevilla 7mo ago
> Sadly certbot doesn't do (or it didn't) CNAME redirects for ACME.
Are you certain? Not at a real machine at the moment so hard for me to dig into the details but CNAMEing the challenge response to another domain is absolutely supported via DNS-01 [0] and certbot is Let's Encrypt's recommended ACME client: [1]
Since Let’s Encrypt follows the DNS standards when
looking up TXT records for DNS-01 validation, you can
use CNAME records or NS records to delegate answering
the challenge to other DNS zones. This can be used to
delegate the _acme-challenge subdomain to a validation
specific server or zone.
... which is a very common pattern I've seen hundreds (thousands?) of times.
The issue you may have run into is that CNAME records are NOT allowed at the zone apex, for RFC 1033 states:
The CNAME record is used for nicknames. [...] There must not be any other
RRs associated with a nickname of the same class.
... of course making it impossible to enter NS, SOA, etc. records for the zone root when a CNAME exists there.
P.S. doing literally fucking anything on mobile is like pulling teeth encased in concrete. Since this is how the vast majority of the world interfaces with computing I am totally unsurprised that people are claiming 10x speedups with LLMs.
[0] https://letsencrypt.org/docs/challenge-types/ https://letsencrypt.org/docs/challenge-types/
[1] https://letsencrypt.org/docs/client-options/ https://letsencrypt.org/docs/client-options/
- jcalvinowens 7mo agoI tried this too a couple months ago, OP is right, certbot doesn't support the CNAME aliases: it lacks logic to add the TXT record to the redirected name, instead of the name in the certificate. I use acme.sh which does support it: https://news.ycombinator.com/item?id=47066072 https://news.ycombinator.com/item?id=47066072
- rdevilla 7mo agoI still find this hard to believe without some actual example RRs and certbot configs, but this is HN, not serverfault.
- jcalvinowens 7mo agoI remember being annoyed because the docs don't actually say you can't do it: https://certbot-dns-rfc2136.readthedocs.io/en/stable/ https://certbot-dns-rfc2136.readthedocs.io/en/stable/ ...but they also don't say how to specify the zone to be updated like acme.sh does: https://github.com/acmesh-official/acme.sh/blob/master/dnsapi/dns_nsupdate.sh#L10 https://github.com/acmesh-official/acme.sh/blob/master/dnsap... So say you want a cert for *.foo.com, and you have: _acme-challenge.foo.com CNAME _acme-challenge.foo.bar.com ...I can make certbot talk to the foo.bar.com DNS server, but it tries to add the TXT record for _acme-challenge.foo.com, which that DNS server obviously rejects (and even if it accepted it, that obviously wouldn't work). I'd be happy to hear there's a way to do it that I missed. Also I'm specifically talking about the rfc2136 support, maybe some of the proprietary certbot backends do support this. EDIT: Here are more references: https://github.com/certbot/certbot/issues/6566 https://github.com/certbot/certbot/issues/6566 https://github.com/certbot/certbot/pull/5350 https://github.com/certbot/certbot/pull/5350 https://github.com/certbot/certbot/pull/6644 https://github.com/certbot/certbot/pull/6644