Skip to content
This repository has been archived by the owner on Apr 24, 2020. It is now read-only.

dns-02: dynamic challenge request: TXT <$token>._acme-challenge.domain.tld #393

Open
ProBackup-nl opened this issue Feb 5, 2018 · 2 comments
Milestone

Comments

@ProBackup-nl
Copy link

ProBackup-nl commented Feb 5, 2018

One of the problems of dns-01 is that it's not able to automate like http-01: there the webserver is able to respond with $token || '.' || $key-thumbprint

It would be nice when that mechanism comes to DNS, to DNS server developers are able to supply an automated.

Instead of statically querying _acme-challenge.domain.tld to prove host/domain ownership, query the dns including the token, like: <$token>._acme-challenge.host.domain.tld

@bifurcation
Copy link
Contributor

Moving this to Defer, because I think several current implementations have in fact been able to automate the DNS challenge (e.g., lego supports a bunch of DNS providers out of the box). If this is a problem, it can be handled in a follow-on spec.

@bifurcation bifurcation added this to the Defer milestone Mar 2, 2018
@hooliganznat

This comment has been minimized.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants