|
|
|
|
|
by zAy0LfpBZLC8mAC
3143 days ago
|
|
Erm ... you had people create TXT records? Why would you do that? Wouldn't people then have to manually update the TXT record on each certificate renew?! Why not have them create a DNAME, a delegation, or just two CNAMEs? |
|
The http-01 challenge is simpler, we can get people setup with one CNAME/A-record.
Once we're serving traffic, we can do all renewals with an http challenge and they don't need to change DNS ever again.