# DNS-based challange for verification of LetsEncrypt/SSL-certs?

**URL:** <https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561>\
**Category:** Issuance Tech\
**Created:** [February 24, 2017, 9:29am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561 "2017-02-24T09:29:27Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![jjaone](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjaone/32/11537_2.png) [@jjaone](https://community.letsencrypt.org/u/jjaone)\
**Post date:** [February 24, 2017, 9:29am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/1 "2017-02-24T09:29:27Z")

</div>

How does one generate DNS-01 challange that can be added to server DNS-records forLetsEncrypt/ SSL-verification?

With which client and with which args?

Can this be done with cerbot/letsencrypt?

Are there clients that can do the issuance and renwal automatically scripted?

Thanks for any info on this.

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [February 24, 2017, 9:44am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/2 "2017-02-24T09:44:27Z")

</div>

hi @jjaone

one adds a DNS record type TXT

that depends on the client

yes certbot can be used for dns challenges using --manual and --preferredchallenges arguments

you can review this:

> [@Certbot plugin for AWS Route53](https://community.letsencrypt.org/t/certbot-plugin-for-aws-route53/27201):
>
> I…

> **[Examples for DNS 01 hooks](https://github.com/dehydrated-io/dehydrated/wiki/Examples-for-DNS-01-hooks)**
>
> letsencrypt/acme client implemented as a shell-script – just add water - dehydrated-io/dehydrated

there is also a python project for a DNS lexicon

> **[dns-lexicon](https://pypi.org/project/dns-lexicon/)**
>
> Manipulate DNS records on various DNS providers in a standardized/agnostic way

you can also script your own plugins

[http://letsencrypt.readthedocs.io/en/latest/contributing.html#code-components-and-layout](http://letsencrypt.readthedocs.io/en/latest/contributing.html#code-components-and-layout)

---

<div class="post-metadata">

**Author:** ![jjaone](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjaone/32/11537_2.png) [@jjaone](https://community.letsencrypt.org/u/jjaone)\
**Post date:** [February 24, 2017, 9:56am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/3 "2017-02-24T09:56:53Z")

</div>

Thanks for the answer. I’m using letsencrypt 0.11.1 and the ‘–manual’ command only have these switches:

```
--manual-auth-hook MANUAL_AUTH_HOOK
                      Path or command to execute for the authentication
                      script (default: None)
--manual-cleanup-hook MANUAL_CLEANUP_HOOK
                      Path or command to execute for the cleanup script
                      (default: None)
--manual-public-ip-logging-ok
                      Automatically allows public IP logging (default: Ask)

```

The ‘certbot’ command does not seem to recognize that "–preferredchallenges’ argument but says:  
\> certbot: error: unrecognized arguments: --preferredchallenges dns-01

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [February 24, 2017, 10:11am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/4 "2017-02-24T10:11:57Z")

</div>

sorry for the sarcasm but a big fan of copy and paste 😉

[http://letsencrypt.readthedocs.io/en/latest/using.html#certbot-commands](http://letsencrypt.readthedocs.io/en/latest/using.html#certbot-commands)

–preferred-challenges PREF\_CHALLS  
A sorted, comma delimited list of the preferred  
challenge to use during authorization with the most  
preferred challenge listed first (Eg, “dns” or “tls-  
sni-01,http,dns”). Not all plugins support all  
challenges. See  
[https://certbot.eff.org/docs/using.html#plugins](https://certbot.eff.org/docs/using.html#plugins) for  
details. ACME Challenges are versioned, but if you  
pick “http” rather than “http-01”, Certbot will select  
the latest version automatically. (default: )

the manual even gives you the syntax 😃

below is how i usually do mine 😃

 ![](https://global.discourse-cdn.com/letsencrypt/original/2X/b/b833ea967fb0c9d85d6f9bd7a4368cba64edb789.PNG)

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [February 24, 2017, 10:17am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/5 "2017-02-24T10:17:40Z")

</div>

also thanks heaps for posting the manual hook stuff

i been thinking about how to do something and those will be perfect

i am also guilty of not RTFMing ☹

---

<div class="post-metadata">

**Author:** ![jjaone](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjaone/32/11537_2.png) [@jjaone](https://community.letsencrypt.org/u/jjaone)\
**Post date:** [February 24, 2017, 10:17am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/6 "2017-02-24T10:17:54Z")

</div>

Ok, found out that the correct arg is actually “–preferred-challanges” and using a command:

```
   `/letsencrypt-auto certonly --agree-tos --renew-by-default --manual --preferred-challenges=dns -d mydns.domain1.tld`

```

I was able to generate a DNS-challange:

```
    Please deploy a DNS TXT record under the name
    _acme-challenge.mydns.domain1.tld with the following value:
    JHPIuUHGBkadaodaiweirfblaabvlaabadasasajqxU

```

which then should be added to server DNS-record as a TXT record, with a very shor TTL.

---

<div class="post-metadata">

**Author:** ![ahaw021](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/ahaw021/32/14882_2.png) [@ahaw021](https://community.letsencrypt.org/u/ahaw021)\
**Post date:** [February 24, 2017, 10:23am UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/7 "2017-02-24T10:23:48Z")

</div>

nice one! let me know how you go with the hook stuff

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [February 24, 2017, 1:52pm UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/8 "2017-02-24T13:52:40Z")

</div>

> [@jjaone](#):
>
> Ok, found out that the correct arg is actually "--preferred-challanges" and using a command:

Yes, you would have seen that information when you would have run `certbot --help manual` 🙂 But as it's not specific for _just_ the manual plugin, you would have found it in the "optional arguments" in that same output. Just don't blindly stare at the part after "manual:" 😉

---

<div class="post-metadata">

**Author:** ![jjaone](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjaone/32/11537_2.png) [@jjaone](https://community.letsencrypt.org/u/jjaone)\
**Post date:** [February 24, 2017, 2:33pm UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/9 "2017-02-24T14:33:12Z")

</div>

> [@Osiris](#):
>
> > [@jjaone](#):
> >
> > Ok, found out that the correct arg is actually "--preferred-challanges" and using a command:
> 
> Yes, you would have seen that information when you would have run `certbot --help manual` 🙂 But as it's not specific for _just_ the manual plugin, you would have found it in the "optional arguments" in that same output. Just don't blindly stare at the part after "manual:" 😉

I had run --manual and several help commands and read the docs of those letsencypt-auto/certbot-auto (old) clients that were installed in our hosts (after I got this task to make SSL-certs to our servers that were moved behind NAT-firewalls three days ago) and they did not have anything about DNS-veriification, also the advice given by @ahaw01 who actully answered this question had it written in incorrect format, which I actually corrected after finding out the arg/options that should be used.

Of course many things _could have been_ searched and _could have been done_, but after having done a lot of search and experiments with those clients that we had and reading about in these forums that documentation is somwehat sparse on how to use DNS-based verification I decided to asked. And I was actully given an anwer that lead me to correct path and now we have the solution which you can see above.

Instead of you @Osiris OT commenting/complaining about how we found out the commands, you could have provided the correct format and arguments as an answer to the Q that was asked, which was more about the defails of the whole procedure to achieve DNS-based verificatiion of SSL:s with LetsEncrypt of which the generation of the challenge with any of the appropriate clients is just one part.

Just don't \*blindly stare \*at the words written here but try to understand why and for what they are written 🙂

---

<div class="post-metadata">

**Author:** ![jjaone](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/jjaone/32/11537_2.png) [@jjaone](https://community.letsencrypt.org/u/jjaone)\
**Post date:** [February 24, 2017, 2:39pm UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/10 "2017-02-24T14:39:55Z")

</div>

> [@ahaw021](#):
>
> nice one! let me know how you go with the hook stuff

Yes thank you for your command examples, they were were helpful foo.

I'm now experimenting with different solutions to automatice this DNS-based challenge generation and verification and renewal process, cause we are still in testing phase and the DNS-records management polices are not exactly clear yet, so Iän not sure if there will be any APIs available for us to automate thist.

But there seems to be many Python-based scripts that can automate parts of those DNS-hooks, but I am still looking for a pure Bash-based solution (especially for the renewal part), cause I do not want to install stuff on our production servers just for SSL/DNS-verification (unless it is absolutely necessary).

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [March 26, 2017, 2:39pm UTC](https://community.letsencrypt.org/t/dns-based-challange-for-verification-of-letsencrypt-ssl-certs/28561/11 "2017-03-26T14:39:54Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
