# Wildcard Domain Step-By-Step

**URL:** <https://community.letsencrypt.org/t/wildcard-domain-step-by-step/58250>\
**Category:** Help\
**Created:** [March 31, 2018, 3:25pm UTC](https://community.letsencrypt.org/t/wildcard-domain-step-by-step/58250 "2018-03-31T15:25:53Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![sahsanu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/sahsanu/32/89984_2.png) [@sahsanu](https://community.letsencrypt.org/u/sahsanu)\
**Post date:** [March 31, 2018, 8:43pm UTC](https://community.letsencrypt.org/t/wildcard-domain-step-by-step/58250/4 "2018-03-31T20:43:32Z")

</div>

@coder0xff

> [@coder0xff](#):
>
> I’m able to update DNS records as needed

Do you plan to do it manually or you could use a script to automate the process?. I mean, depending on the answer you could use certbot-auto or use another client like [acme.sh](https://github.com/Neilpang/acme.sh).

Right now, the package for Debian Stretch is 0.10.2, if you want a package with a recent version you should install it using [stretch-backports](https://certbot.eff.org/lets-encrypt/debianstretch-other) but the package offered is version 0.21.1 and you need version 0.22.0 or above to be able to issue a wildcard cert so I would install [certbot-auto](https://certbot.eff.org/lets-encrypt/pip-other) and you will get always the last version.

To get a wildcard certificate using certbot-auto and manually add the TXT records:

`certbot-auto certonly --server https://acme-v02.api.letsencrypt.org/directory --manual --preferred-challenges dns -d 'yourdomain.tld,*.yourdomain.tld'`

Edit: I forgot to add the server for acme v2 (with version 0.23.0 you won't need to add this parameter)

Note: you will receive info to add the required TXT records to validate your domain, keep in mind that in the above command the cert will cover `yourdomain.tld` and `*.yourdomain.tld` (if you don't want `yourdomain.tld`, simply remove it from the command `-d '*.yourdomain.tld'`.

Note2: with this method, you won't be able to renew the certificate automatically so you will need to renew it manually.

If you can provide a script to add the txt records and delete them once validated:

```
certbot-auto certonly --server https://acme-v02.api.letsencrypt.org/directory --manual --preferred-challenges dns --manual-auth-hook "/path/to/hook-script.sh" --manual-cleanup-hook "/path/to/hook-clean-script.sh" -d 'yourdomain.tld,*.yourdomain.tld'

```

Edit: I forgot to add the server for acme v2 (with version 0.23.0 you won’t need to add this parameter)

Note: with this method you will be able to renew the cert automatically.

If you don't have your own script, maybe the API used by your DNS provider is covered by [lexicon](https://github.com/AnalogJ/lexicon) (Manipulate DNS records on various DNS providers in a standardized/agnostic way.) you can use this [wonderful guide](https://id-rsa.pub/post/certbot-auto-dns-validation-with-lexicon/) created by @_az to use `lexicon` with `certbot-auto` to automate the process.

As I said, acme.sh has a ton of DNS providers included to automate the process, take a look to its [site](https://github.com/Neilpang/acme.sh) and you will see the DNS providers included and examples to issue wildcard certificates.

I hope this helps.

Cheers,  
sahsanu

---

_[View the full topic](https://community.letsencrypt.org/t/wildcard-domain-step-by-step/58250)._
