Duckdns cert
-
Hello everyone, not having in-depth knowledge about acme, I wanted to ask for clarification on the management of the names dns duckdns and let encrypt.
I have some .duckdns.org names available and I wanted to configure acme for pfsense . I saw that in the generation of the certificate there is the possibility to select duckdns . I was asking , if I enter the name of one of the servers example firstserver.duckdns.org and select the method with dns-duckdns.org by entering the token , this procedure frees me from the fact that pfsense will not have the port 80 open for the sambio and the renewal of the certificate . Or if someone explained to me how it works I would be grateful.
Thank you
-
I've found some answers : dns duckdns and letsencrypt
-
@Gertjan Hi , I wanted to update you that I was able to request the LE certificate through the method options with ducke dns . Without opening any port 80 , the procedure was successful and the certificate is valid and active . Thanks anyway for your directions.
-
You are using then the dns_duckdns.sh DNS acme.sh method ?
-
@Gertjan Hi, I only used the parameters proposed in the certificate section (e.g. DNS-duckdns ) and entered the key where I registered the names of my interest . I performed the acme test of the certificate first, after seeing that it worked I changed to the production version. Now it works . I have activated the pfsense cron in the certificates section and I hope that at the expiration it will perform the renewal . I didn't have the need to open port 80 on the firewall. At the moment this is what .
-
@frankz said in Duckdns cert:
I didn't have the need to open port 80 on the firewall.
Because you are using another method.
The one you use know login into duckdns with your credentials and "does what needs to be done" so Letsencrypt can do the checks. -
@Gertjan Considered this better this way. Instead I can't make haproxy work !!!!
-
@frankz
Sorry, I don't know what haproxy is - not using it.
Doesn't seem to be discussed in this sub forum as here it's "ACME" only.