Hi all
I need to generate a certificate for a domain.
I would have to generate the certificate on a windows machine (the server is not running on this).
I do not have shell access and can not connect remotely to the server in anyway.
The only thing I can do is add or remove DNS entries.
Is it possible to do so? If yes how (preferable explained to do it as a newbie as well)?
In a similar situation - but have full access the server but no access to port 80 and am using no-ip w/ my own domain, so I cannot create the necessary DNS TXT record because it starts w/ a _. I have tried both sslforfree & zerossl and they both need the particular addition to the DNS which is not happening. I tried setting up w/ dynu and either I do not know the syntax for the DNS TXT record, or it will not accept it either. Please assist.
If you have your own domain, you may as well use a âfully-featuredâ DNS host.
e.g. Cloudflare supports dynamic DNS, but Iâm sure itâs not the only candidate. It would have the added bonus of supporting automatic renewal if you used an ACME client like acme.sh.
@_az - Thanks for the links. FWIW, I am running this on a Win10Pro box. I am thinking running Ubuntu in a VM would be the way of least resistance for this automation? This is off topic, but possibly you could help - any preference on which VM client to use - VMWare Player, VirtualBox or Hyper-V?
@_az - Thank You so much for your walkthrough / tutorial. I was having an issue w/ the _acme-challenge being the âNode Nameâ, and was trying to figure out the syntax putting both, the entire _acme-challenge.mydomain.com along w/ the value all in the âTextâ box. Obviously this was not working. Also, ZeroSSL does have a Windows Binary in their tutorial - https://zerossl.com/usage.html#DNS_verification. Just waiting for propagation for another 10-15mins before I attempt to get the cert/s since I just changed the DNS info @ Godaddy from no-ip -> dynu as well as installing dynuâs client on a machine on my LAN and getting it up-to-date also.
EDIT: After propagation, GOOOOOOOOAAL!!! Green Little Lock and no more nag screen!! Thanks
@_az - Appreciate the pull request greatly. While I do not have an issue renewing the certs myself, an automated setup would be the icing on the cake :). Thanks.
A Dynu plugin was actually added to Posh-ACME the other day thanks to a generous user. I haven't pushed a release version that has it yet. But there are instructions in the readme for installing directly from the master branch if you're desperate.
Lol, that'll teach me to reply before reading the rest of the thread. Thanks @_az!