# Issuing a certificate for an IRC server with no website associated (no apache - no nginx)

**URL:** <https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009>\
**Category:** Help\
**Created:** [May 8, 2024, 5:23pm UTC](https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009 "2024-05-08T17:23:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![evanmac](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/evanmac/32/65394_2.png) [@evanmac](https://community.letsencrypt.org/u/evanmac)\
**Post date:** [May 8, 2024, 5:23pm UTC](https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009/1 "2024-05-08T17:23:54Z")

</div>

Here are the instructions:

FIRST you have to install the certbot bin (if not yet installed) with:

apt install certbot

THEN you have to install the python script to make certbot working with dns:

# cd /etc/letsencrypt

# wget [https://github.com/joohoi/acme-dns-certbot-joohoi/raw/master/acme-dns-auth.py](https://github.com/joohoi/acme-dns-certbot-joohoi/raw/master/acme-dns-auth.py)

# chmod +x acme-dns-auth.py

# pico acme-dns-auth.py

The last command is to add the number "3" at first line (you can use you favourite editor) to ensure the last version of python is used:

#!/usr/bin/env python3

My domain is:

[irc.example.com](http://irc.example.com)

I ran this command:

sudo certbot certonly --manual --manual-auth-hook /etc/letsencrypt/acme-dns-auth.py --preferred-challenges dns --debug-challenges -d \*.example.com

in this example I'm issuing a jolly certificate for every subdomains of [example.com](http://example.com), if you want to issue certificate only for a subdomain just change \* with whatever, as here:

sudo certbot certonly --manual --manual-auth-hook /etc/letsencrypt/acme-dns-auth.py --preferred-challenges dns --debug-challenges -d [whatever.example.com](http://whatever.example.com)

My web server is (include version): none

The operating system my web server runs on is (include version): Debian 12

My hosting provider, if applicable, is: eticoweb.it

I can login to a root shell on my machine (yes or no, or I don't know): yes

I'm using a control panel to manage my site (no, or provide the name and version of the control panel): Plesk

The version of my client is (e.g. output of `certbot --version` or `certbot-auto --version` if you're using Certbot): certbot 2.1.0

Well, I was lurking around for a solution to install a certificate against my irc server, which is a macmini 2011 running a Debian12.

I have total control on DNS record trough my provider, but I don't have fixed IP at home, so I have to instruct DNS to redirect [irc.example.com](http://irc.example.com) to [whatever.dyndns.org](http://whatever.dyndns.org) and update dinamically via router setup; this is mandatory because I just manage the DNS zone with my service provider, and the server machine is installed in SOHO environment, with no fixed IP, as said.

So, after issuing the command in the server's shell, the script pauses letting you time for adidng a CNAME record as per the instructions the certbot client give you, something like this:

\_acme-challenge.irc.example.com

CNAME

[da9f5cc8-9012-46d5-a9af-6a3b3946909c.auth.acme-dns.io](http://da9f5cc8-9012-46d5-a9af-6a3b3946909c.auth.acme-dns.io).

Once you've added the DNS record, and saved changes, you can return to your shell and press enter to continue the cert installation.

At the end you'll have a certificate issued for your domain with no need of a webserver running 😃

---

<div class="post-metadata">

**Author:** ![Rip](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/rip/32/70863_2.png) [@Rip](https://community.letsencrypt.org/u/Rip)\
**Post date:** [May 8, 2024, 5:47pm UTC](https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009/2 "2024-05-08T17:47:46Z")

</div>

Hello @evanmac .. This post is interesting and yet I find myself curious why @joohoi would not post it himself?

---

<div class="post-metadata">

**Author:** ![Osiris](https://avatars.discourse-cdn.com/v4/letter/o/839c29/32.png) [@Osiris](https://community.letsencrypt.org/u/Osiris)\
**Post date:** [May 8, 2024, 5:50pm UTC](https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009/3 "2024-05-08T17:50:08Z")

</div>

> [@Rip](#):
>
> This post is interesting and yet I find myself curious why @joohoi would not post it himself?

Probably because the script is ancient and back in the day there probably has been a thread about it already.

> [@evanmac](#):
>
> FIRST you have to install the certbot bin (if not yet installed) with:
> 
> apt install certbot

Please don't use `apt` to install Certbot. It's often ancient and the recommended method of installing Certbot is using `snap`. See [Certbot Instructions | Certbot](https://certbot.eff.org/instructions) for more information.

Further more I have a question: why not simply use the `--standalone` authenticator? It does not require a separate webserver like Apache or nginx. It does require an open port 80, but that usually doesn't really matter.

---

<div class="post-metadata">

**Author:** ![evanmac](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/evanmac/32/65394_2.png) [@evanmac](https://community.letsencrypt.org/u/evanmac)\
**Post date:** [May 8, 2024, 6:46pm UTC](https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009/4 "2024-05-08T18:46:19Z")

</div>

> [@Osiris](#):
>
> Probably because the script is ancient and back in the day there probably has been a thread about it already.

I searched in this forum but I found nothing to solve my problem

> [@evanmac](#):
>
> FIRST you have to install the certbot bin (if not yet installed) with:
> 
> apt install certbot

> [@Osiris](#):
>
> Please don't use `apt` to install Certbot. It's often ancient and the recommended method of installing Certbot is using `snap`. See [Certbot Instructions | Certbot](https://certbot.eff.org/instructions) for more information.

On my distro (debian 12) I ever used apt to install package, and until now I had zero problems ☺

> [@Osiris](#):
>
> Further more I have a question: why not simply use the `--standalone` authenticator? It does not require a separate webserver like Apache or nginx. It does require an open port 80, but that usually doesn't really matter.

Because I run an instance of nextcloud on the same machine and I don't want to mess thing, or modify nginx conf files 😉

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [June 7, 2024, 6:46pm UTC](https://community.letsencrypt.org/t/issuing-a-certificate-for-an-irc-server-with-no-website-associated-no-apache-no-nginx/218009/5 "2024-06-07T18:46:35Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
