logoalt Hacker News

lysacelast Monday at 3:50 PM4 repliesview on HN

Unfortunately they are a bit extra bothersome to automate (depending on your DNS provider/setup) because of the DNS CNAME-method validation requirement.


Replies

jsheardlast Monday at 3:59 PM

Yep, but next year they intend to launch an alternative DNS challenge which doesn't require changing DNS records with every renewal. Instead you'll create a persistent TXT record containing a public key, and then any ACME client which has the private key can keep requesting new certs forever.

https://letsencrypt.org/2025/12/02/from-90-to-45#making-auto...

show 3 replies
cortesoftlast Monday at 4:33 PM

If you are using a non-standard DNS provider that doesn’t have integration with certbot or cert-manager or whatever you are using, it is pretty easy to set up an acme-dns server to handle it

https://github.com/joohoi/acme-dns

Reventlovlast Monday at 5:15 PM

also you can use https://github.com/krtab/agnos if you don't have any api access

show 1 reply
ls612last Monday at 7:42 PM

When I set up a wildcard cert for my homelab services it was easy to have Cloudflare give me an API token to do the DNS validation for LE.