Hi @mikev, hopefully you’re running the client software on a server that’s able to accept incoming HTTPS connections from the general public, at least for the duration of the validation process.
I’m not sure whether we’ll publish a list of hosts that may perform validations. One security challenge for DV validation is that an attacker might be able to manipulate the network path between the host that performs the validation and the host that responds. To address this, we might in the future perform validations from several different locations on the Internet. We might not want to let prospective attackers know all of the network paths or locations that they’d have to manipulate in order to interfere with the validation for a particular name or server.