The recent @letsencrypt shutdown of TLS-SNI-01 validation (due to idiotic hosting providers) is very disappointing. It was by far the most convenient, hands-off, universal validation mechanism. https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188 …
-
Show this thread
-
DNS-01 requires making all my DNS zones dynamic, which is a PITA and increases complexity. HTTP-01 requires pre-provisioning site configs and having a mutable webroot. TLS-SNI-01 was great because it didn't clash with actual production configs at all so it always worked.
4 replies 1 retweet 3 likesShow this thread -
Replying to @marcan42
I disagree. I have manually added the necessary zone contents without dynamic DNS (as in nsupdate) support. Dynamic is easier but not strictly required.
1 reply 0 retweets 0 likes -
Replying to @DrScriptt
Wanna sign up to manually do the 2-monthly renewals for me for free? I have about 40-odd certificates for 100+ (sub)domains, so that's one every couple of days on average ;)
1 reply 0 retweets 0 likes -
Replying to @marcan42
Nope. Not for free.
I’ve not needed to change the DNS (or well known file) entry after the initial setup.
It keeps reusing old info.
1 reply 0 retweets 0 likes -
Replying to @DrScriptt
Good to know. Still not nice if I need to manually go edit DNS every time I need a new cert ;)
2 replies 0 retweets 0 likes -
Replying to @marcan42
You need to add records when you request a cert for a new name. But renewals of existing names should be no-op for DNS. (Clarifying creation vs renewal.)
1 reply 0 retweets 0 likes
Right, I'm saying even for renewal the required TXT record still needs to be changed according to everything I'm reading. Are you sure you aren't being misled by cached authorization objects?
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.