Address range for “http-01” ACME challenge

Good day,
I want to list Ip address for “http-01” ACME challenge, for renewal, but I found information that it uses
but that is not possible due to " CDN they use (Akamai)"
I did notice there are 3 adresses:

acme-v01.api.letsencrypt.org
acme-staging.api.letsencrypt.org
acme-v02.api.letsencrypt.org
acme-staging-v02.api.letsencrypt.org

I am located in the eu, can I list only the eu address for port 80, would that work?

some info taken from:

That isn't possible--LE doesn't, and won't, list these IPs as a matter of policy. Edit: see also:

7 Likes

Also, the IP addresses of the API endpoint are not the same as the IP addresses used by the validation servers, as Let's Encrypt uses 4 different data centers around the world for multiple vantage point validation.

7 Likes

DNS validation (instead of http validation) is the way to go, if you require that international http requests to your server are blocked by default.

6 Likes

thanks for the idea, it's a hardware device that has renew integration with let's encrypt, dns is not not a possibility

1 Like

Cool, can you copy certificate files onto the device using SSH/SFTP? If so, you can use any capable client to get your cert using DNS, then copy the files. https://acmeclients.com

4 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.