logoalt Hacker News

echoangletoday at 8:43 AM2 repliesview on HN

DNS TXT challenge for example. Also better because you can get wildcard certs.


Replies

ameliaquiningtoday at 4:26 PM

The great virtue of the in-band challenge types is that web servers can just handle them out of the box, without any need for a separate setup step that depends on your stack. I think this has done a heck of a lot to increase adoption of HTTPS.

sureglymoptoday at 11:58 AM

Also, DNS-PERSIST-01 seems to be coming soon for Let's Encrypt, which should allow even people that can't easily dynamically update their DNS records to get wildcard certs. I assume this might become more widely used than HTTP-01 challenges.

show 1 reply