Skip to content
GitLab
  • Menu
Projects Groups Snippets
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • SUCS SUCS
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 18
    • Issues 18
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 0
    • Merge requests 0
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • sucs
  • SUCSSUCS
  • Issues
  • #55
Closed
Open
Created Nov 19, 2020 by Thomas Lake@tswsl1989🔧Maintainer

Move Certbot challenges to DNS

Uni firewall changes are restricting port 80 access to some machines (despite our previous request). As there's little need for direct port 80 access (we just redirect to HTTPS), consider moving to dns-01 challenges for Let's Encrypt instead of HTTP

We would need to configure BIND on Silver to accept updates, and then generate and store update keys on the relevant machines. The BIND configuration on Silver can restrict each machine to only permit updates for it's specific challenge key.

Docs reference: https://certbot-dns-rfc2136.readthedocs.io/en/stable/

Assignee
Assign to
Time tracking