Hacker News new | ask | show | jobs
by tialaramex 1764 days ago
Nobody stops you building an ACME client that does this. However I expect it would mostly accumulate confused bug reports from users who don't know their IP address, or don't even have a public IP address, and certainly can't unblock UDP port 53 on their device.
1 comments

certbot already has a "stand-alone" authorization mechanism that has all those drawbacks, so doing a similar thing for DNS might not be too terrible...

kro pointed out (in this thread) this plugin that is more or less what I described: https://github.com/pawitp/acme-dns-server