Hacker News new | ask | show | jobs
by rossy 1760 days ago
The "DNS provider with a better API" can be your own bind9 server on the same machine as certbot, updated with RFC 2136. Completely standard, no changing APIs, no 4th party, no maintenance. I set up a server like this at work and haven't touched it for a year and a half.
1 comments

bind hasn't exactly had a flawless security history...

(also hope that not touching it means you've automated security updates at least)