challenges.addr.tools - dns-01 ACME challenge helper zone
$ example="LCa0a2j_xo_5m0U8HTBBNBNCLXBkg7-g-YpeiGJm564" $ curl -d "secret=1SuperSecret" -d "txt=$example" https://challenges.addr.tools OK
$ sha224=$(echo -n "1SuperSecret" | shasum -a 224 | cut -c 1-56) $ dig txt +short $sha224.challenges.addr.tools "LCa0a2j_xo_5m0U8HTBBNBNCLXBkg7-g-YpeiGJm564"
The DNS zone challenges.addr.tools is meant to ease the use of dns-01 ACME challenges in automated or batch TLS certificate issuance from certificate authorities such as Let's Encrypt.
Let txt be a dns-01 ACME challenge validation string, secret be a strong password, and sha224 be the SHA-224 hash of secret.
A GET, POST, or PUT request to https://challenges.addr.tools with secret=secret
and txt=txt specified as URL query parameters or, alternatively for POST and PUT requests, as
form values will temporarily add txt as a TXT record to the domain
sha224.challenges.addr.tools. Responds with body OK and status code
201 on success.
A GET, POST, or PUT to https://challenges.addr.tools with only secret=secret
specified responds with body sha224.challenges.addr.tools and makes no update.
sha224.challenges.addr.tools is meant to be the target of a CNAME at your "_acme-challenge"
subdomain.
Remember to properly encode your secret value in your requests if it contains special characters. See curl's "--data-urlencode" option.
Say you want to obtain a wildcard TLS certificate for example.com from Let's Encrypt using Certbot.
First, pick a strong password. We'll use "1SuperSecret", but you shouldn't.
Add a CNAME record to point _acme-challenge.example.com to the subdomain of challenges.addr.tools named by calculating the SHA-224 hash of "1SuperSecret". This should look similar to:
| Name: | _acme-challenge.example.com |
|---|---|
| Type: | CNAME |
| Target: | 1d23d5e1a9a689668e8510aef992aa358cb54992d0c4327842a1416f.challenges.addr.tools |
Now when Let's Encrypt queries _acme-challenge.example.com for the challenge TXT record, they will follow the CNAME to 1d23d5…a1416f.challenges.addr.tools. We can give Certbot a command to automatically add the challenge TXT record to that subdomain:
$ certbot certonly \ --manual \ --manual-auth-hook 'curl -fsS -d "secret=1SuperSecret" -d "txt=$CERTBOT_VALIDATION" https://challenges.addr.tools' \ --preferred-challenges dns \ -d example.com \ -d '*.example.com'