Creating an ACME certificate for internal DNS over TLS in pfSense. What method do I chose depicted in the screenshot attached, Any other suggestions would be helpful.
This is not a case of wanting a certificate for localhost. This is a certificate for use with DoT, although I am not sure why an existing certificate cannot be used or why the challenge is not automated using Cloudflare.
I don't know what the question really is, or how it relates to Let's Encrypt. Maybe @mrvmlab can help us with some more relevant details.
@linkp I will try to keep this short I am running pfSense and I have DNS over TLS setup for external DNS. That works great. I see where I can also with in pfSense offer DNS over TLS to my internal clients ( HomeLab ) It is not working internally and the only results as to why it may be is due to a certificate being the issue ( self singed ) So I wanted to issue a certificate based on my registered domain name with ACME and use that. How ever I did not know what Method to use under the Domain SAN list when filling in the Services>ACME>Certificate options Edit. So this very well may be a question for Netgate support rather then Let's Encrypt I am not 100% sure.
if it can use domain name like android you can just use plain LE certificate: if you need a certificate for RAW IP address: LE doesn't offer it now. For public IP I think there is commercial CAs that are willing to sell you some: zerossl by api and google trust service comes to mind
Within a home lab, you usually don't need a publicly-trusted certificate like those issued by Let's Encrypt. You can likely issue your own certificate from your own internal certificate authority, and make the other devices on the network trust that authority.
That is correct @schoen; however I do not fully understand what the OP is exactly trying to accomplish and what they would like. Thus the reason for the question.