The recent @letsencrypt shutdown of TLS-SNI-01 validation (due to idiotic hosting providers) is very disappointing. It was by far the most convenient, hands-off, universal validation mechanism. https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188 …
-
Show this thread
-
DNS-01 requires making all my DNS zones dynamic, which is a PITA and increases complexity. HTTP-01 requires pre-provisioning site configs and having a mutable webroot. TLS-SNI-01 was great because it didn't clash with actual production configs at all so it always worked.
4 replies 1 retweet 3 likesShow this thread -
Replying to @marcan42
For what it’s worth, this is technically not the case. You can CNAME your _acme-challenge labels into a single dynamic validation zone.
2 replies 0 retweets 1 like -
Replying to @mdhardeman
Ooooh. I didn't think of this. Thanks! I might start using this method for some zones.
1 reply 0 retweets 0 likes -
Replying to @marcan42
Another trick is to add a NS record as each _acme-challenge... delegating the looking of each label to its very own zone, inside that zone , which is dynamic, the TXT is just added on the blank base label.
1 reply 0 retweets 0 likes
Just used the CNAME trick at work yesterday. Good timing.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.