Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can do it with an NS record, ie _acme_challenge.realdomain.com pointing to the DNS server that you can program to serve the challenge response. No need to make a CNAME and involve an additional domain in the middle.




Yeah, but then you can just as well use http-01 with like same effort.

no, because dns supports wildcard certificates, unlike http.

dns-01 is also good for services on a private network.

Ah, good point.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: