meta data for this page
  •  

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
sw:certbot [2020/07/02 18:51] niziaksw:certbot [2020/07/10 13:11] (current) niziak
Line 1: Line 1:
-====== certbot ====== +====== certbot / letsencrypt ====== 
-letsencrypt+
  
 Debian Buster has old ''certbot'' version 0.31 Debian Buster has old ''certbot'' version 0.31
Line 10: Line 10:
  
 ===== obtain wildcard cert ===== ===== obtain wildcard cert =====
-It is only possible using DNS authenticator. 
  
 <code bash> <code bash>
-certbot --certonly --manual -d '*.example.com'+# First obtain normal domain certificate 
 +certbot -d 'example.com' 
 + 
 +# Then obtain again with wildcard. It will ask to Expand existing cert. 
 +certbot -d 'example.com,*.example.com' 
 +</code> 
 + 
 +==== using manual and DNS ==== 
 +<code bash> 
 +certbot certonly --manual -d 'example.com,*.example.com'
 </code> </code>
  
Line 20: Line 28:
 _acme-challenge.example.com. 300 IN TXT "gfj9Xq...Rg85nM" _acme-challenge.example.com. 300 IN TXT "gfj9Xq...Rg85nM"
 </code> </code>
 +Ensure record is propagated:
 +<code bash>
 +$ host -t TXT _acme-challenge.example.com
 +_acme-challenge.example.com descriptive text "gfj9Xq...Rg85nM"
 +</code>
 +
  
 ====== Issues ====== ====== Issues ======