• Elvith Ma'for@feddit.org
    link
    fedilink
    arrow-up
    6
    ·
    23 hours ago

    Does Trafik also allow DNS based challenges with additional certbot plugins, or does it only work by serving a challenge in /.well-known/?

    I’ve set up my internal homelab with LE certificates, but if I could get rid of certbot and do this automagically, it’d be nice…

    • Rob Bos@lemmy.ca
      link
      fedilink
      English
      arrow-up
      4
      ·
      20 hours ago

      Not all dns providers support acme, I’ve discovered to my recent annoyance. The one I use at work, for instance.

        • Rob Bos@lemmy.ca
          link
          fedilink
          English
          arrow-up
          2
          ·
          14 hours ago

          Yeah. For wildcard DNS from letsencrypt, you can’t do HTTP validation, only DNS, which involves creating a TXT record.

          Your DNS provider needs to run an ACME server, which runs an API that’ll add the required TXT records on request.

          As I understand it.

    • Dhs92@programming.dev
      link
      fedilink
      arrow-up
      7
      ·
      23 hours ago

      I have it setup to use DNS challenges through Cloudflare, but it supports different providers as well. I just add the labels to my docker container and voila, I have TLS