Win-Acme and using their acme-dns works wiht Let’s Encrypt

The ACME protocol is described in RFC 8555. This is an industry standard used by all ACME Clients and Servers. Let's Encrypt being just one of a number of Certificate Authorities (CA) that provide an ACME Server. There are numerous ACME Clients.

Modifying that standard is very involved. You would be better focused on learning the options available as they are. A good place to start is here: Challenge Types - Let's Encrypt Note the section on TLS-ALPN is a bit stale as it says very few ACME Clients support it. While it is not as well supported as the other challenge types it is supported by quite a few.

Let's Encrypt does not publish the origin IP of their validation servers. LE currently has 5 validation centers around the world which rotate their IP regularly. See: Multi-Perspective Validation & Geoblocking FAQ

If this is a concern stay with the DNS Challenge (or wait for dns-persist). This requires your DNS Servers to be available world-wide but that is often the case. This also avoids the concerns you have regarding HTTP(S) access to your system.

The acme-dns in your first post is good but you should run your own instance and not use their server (as noted earlier)

You haven't said what services you use the certs for but Apache and nginx servers have built-in ACME Clients. Servers like Caddy and others also have ACME Client built-in.

If we understood more about your needs we could give better advice on options.

2 Likes