# Let people specify a subdomain in the configuration files for verification purposes

**URL:** <https://community.letsencrypt.org/t/let-people-specify-a-subdomain-in-the-configuration-files-for-verification-purposes/105599>\
**Category:** Feature Requests\
**Created:** [November 5, 2019, 4:57pm UTC](https://community.letsencrypt.org/t/let-people-specify-a-subdomain-in-the-configuration-files-for-verification-purposes/105599 "2019-11-05T16:57:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![carpool](https://avatars.discourse-cdn.com/v4/letter/c/ea666f/32.png) [@carpool](https://community.letsencrypt.org/u/carpool)\
**Post date:** [November 5, 2019, 4:57pm UTC](https://community.letsencrypt.org/t/let-people-specify-a-subdomain-in-the-configuration-files-for-verification-purposes/105599/1 "2019-11-05T16:57:46Z")

</div>

I think a really easy way to help people set up Let’s Encrypt on servers behind a load balancer would be to have a configuration setting where we can specify a subdomain for verification purposes that goes directly to the server and skips the load balancer.

For example, let’s say I am hosting [example.com](http://example.com) with two Ubuntu 18.04 servers behind a Cloudflare load balancer pointing to Server1 and Server2 randomly.

It would be very straightforward to set up [server1.example.com](http://server1.example.com) to point to Server1 and [server2.example.com](http://server2.example.com) to point to Server2 skipping the load balancer entirely.

Then, when I run certbot on Server1, if I could tell it to look for the verification file on [server1.example.com](http://server1.example.com) I imagine the setup would be a lot easier!

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [November 5, 2019, 5:00pm UTC](https://community.letsencrypt.org/t/let-people-specify-a-subdomain-in-the-configuration-files-for-verification-purposes/105599/2 "2019-11-05T17:00:16Z")

</div>

That’s not required. Use redirects.

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [November 5, 2019, 5:52pm UTC](https://community.letsencrypt.org/t/let-people-specify-a-subdomain-in-the-configuration-files-for-verification-purposes/105599/3 "2019-11-05T17:52:26Z")

</div>

> [@carpool](#):
>
> Then, when I run certbot on Server1, if I could tell it to look for the verification file on [server1.example.com](http://server1.example.com) I imagine the setup would be a lot easier!

Sure it would be easier. But it wouldn't demonstrate control over the root domain, only over server1, thereby defeating the purpose of the validation. As Juergen says, there are other ways to accomplish this without breaking domain validation--one would be to set up your load balancer to send all requests for `/.well-known/acme-challenge/whatever` to a designated place; another would be to use DNS validation.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 5, 2019, 5:52pm UTC](https://community.letsencrypt.org/t/let-people-specify-a-subdomain-in-the-configuration-files-for-verification-purposes/105599/4 "2019-12-05T17:52:31Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
