DNS-01 validation: what about a 'race condition'?

Tangent: Boulder had (still has?) a limit of 4096 bytes for a TXT record response and will ignore the rest. People (like @rmbolger) have tested this to fit 60-70 challenge responses (see Raise the cap for TXT records per subdomain · Issue #76 · joohoi/acme-dns · GitHub)

See also an explanation in this thread: Limitation of TXT record response SIZE

And also @Osiris comments on the boulder code here:

(I was searching the forum because I recalled one of the ISRG staff posting about tweaking some of that response logic a few years ago -- maybe Matthew McPherrin -- but couldn't find it)

3 Likes