Just two question. I have a domain on Register.it. Domain has many subdomains, so I wish to generate a certificate for
*.example.com, example.com
The only option I can use is “Manual DNS verification”. For all my other domains that have NO subdomain I can simply upload control files, but for multiple domains this option si not available.
So I generate _acme-challenge.example.com TXT Records.
https://www.sslforfree.com/create?domains=*.example.com%20example.com generates 2 TXT records.
First question:
when I add those records to my DNS, should I remove the old ones, or can I keep them for a while?
Second question:
I am requested to set a Time to Live equal to 1 second. My provider, REGISTER, allows to use TTL vales > 600 only. I asked them to allow me to use 1 but they said that they cannot. Any value below 600 is forbidden. When I change the TXT records using 600 for TTL, I get no certificates.
Step 3), that is, Verify TXT records, does not work. I have to try / reset certificates many times before it works. Really a mess.
What can I do?