Let's Encrypt has announced their new API production endpoint is now available.
That means you can now use the acme-dns-tiny code from branch
v2 to use their new API and receive wilcard certificates.
I've already used it on my own server and it seems to work well. I'll merge this branch in
master by end of the week. Please be sure to follow tags instead of master branch on your productions to be sure to use the version you need.
About the new code available in
- It's only compatible with ACME RFC draft-09 (the one currently used by Let's Encrypt) and can ask wildcard certificates
- It has replaced the
CheckChallengeDelayoption by a
TTLone which will be used to install TXT records on your server and wait before asking to check the challenge (defaulted to 10 seconds)
- The way to declare contact options has been updated to follow the draft-09 recommendation
- It has now a
--verbosecommand argument to have a little bit more output
- tools to deactivate an ACME account and to rollover keys have been updated too
And, for advanced users:
- For those who need to install exactly same configuration file on multiple servers, you can use the
--csrcommand argument to specify the CSR file path (which is the option which will be different in this case)
- If you installed a CNAME on domains prefixed by
_acme-challenge, it will be followed to install the TXT records on the alias instead (note, it won't follow a chain of CNAME, just one alias). That allows you to configure TSIG keys on a different zone and have more precise DNS update policy.
Hoping you'll like it !