The recent @letsencrypt shutdown of TLS-SNI-01 validation (due to idiotic hosting providers) is very disappointing. It was by far the most convenient, hands-off, universal validation mechanism. https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188 …
Good to know. Still not nice if I need to manually go edit DNS every time I need a new cert ;)
-
-
The documentation says you're wrong and tokens are not persisted. They should have 128 bits of entropy. Are you sure about this? Have you successfully completed two authorizations more than 60 days apart with the same TXT record?
-
I thought I had. But it’s been too long. So maybe I’m wrong. Sorry.
End of conversation
New conversation -
-
-
You need to add records when you request a cert for a new name. But renewals of existing names should be no-op for DNS. (Clarifying creation vs renewal.)
-
Right, I'm saying even for renewal the required TXT record still needs to be changed according to everything I'm reading. Are you sure you aren't being misled by cached authorization objects?
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
I’ve not needed to change the DNS (or well known file) entry after the initial setup.
It keeps reusing old info. 