YourWebTech documentation

Certificate Automation (ACME DNS-01)

Let certbot, acme.sh or lego renew Let's Encrypt and ZeroSSL certificates, wildcards included, by updating YWT DNS on their own with a key limited to ACME challenge records.

Certificate Automation (ACME DNS-01)

Wildcard certificates such as *.example.ch can only be validated with the ACME DNS-01 challenge: on every issue and renewal, your certificate tool publishes a TXT record at _acme-challenge.example.ch and removes it afterwards. Certificates are getting shorter-lived (47 days from 2029), so this has to happen without anyone editing records by hand.

YWT DNS accepts these changes as standard RFC 2136 dynamic updates signed with a TSIG key. certbot, acme.sh and lego support this out of the box, so there is nothing extra to install from us.

This works for domains on YWT nameservers (ns1.ywt.ch / ns2.ywt.ch). See Nameservers if your domain uses others.

What a key can do

  • Add and remove TXT records at _acme-challenge names of the domain it was made for: _acme-challenge.example.ch, _acme-challenge.www.example.ch and so on.
  • Nothing else. It cannot change other records, other names or other domains. Anything else in an update is ignored.
  • A domain can have up to 10 keys, each with its own label, and you can revoke each one on its own.
  • Keys are deleted when the domain is deleted or transferred to another registrar.

Create a key

Open your domain in the panel and go to Nameservers & DNS Records.

In Certificate automation (ACME), click Create key and give it a label, for example the name of the server that will use it.

Copy the secret and the setup for your tool. The secret is shown only once. If you lose it, revoke the key and create a new one.

The panel shows everything your tool needs:

SettingValue
Serverns1.ywt.ch, port 53 (the panel also shows its IP address, which certbot needs)
Key nameacme-<random>.example.ch
Algorithmhmac-sha256
Secretshown once, when you create the key

If _acme-challenge is currently a CNAME (for example because you delegated challenges to another DNS provider), updates are refused: a TXT record cannot exist next to a CNAME. Delete that CNAME in your DNS records first. The panel warns you when this is the case.

Set up your tool

The examples request a certificate for example.ch and *.example.ch. Replace the key name, secret and server address with the values from the panel; the panel fills them in for you.

Install the certbot-dns-rfc2136 plugin (on Debian and Ubuntu: apt install python3-certbot-dns-rfc2136). Save the credentials as /etc/letsencrypt/ywt-example.ch.ini and make the file readable only by root (chmod 600):

dns_rfc2136_server = <IP address of ns1.ywt.ch>
dns_rfc2136_port = 53
dns_rfc2136_name = acme-0123456789.example.ch.
dns_rfc2136_secret = <secret>
dns_rfc2136_algorithm = HMAC-SHA256

certbot needs the server's IP address, not its name. The panel shows it; dig +short ns1.ywt.ch prints it too. Then request the certificate:

certbot certonly --dns-rfc2136 --dns-rfc2136-credentials /etc/letsencrypt/ywt-example.ch.ini -d example.ch -d '*.example.ch'

certbot renew reuses these settings for every renewal.

acme.sh uses nsupdate (package bind9-dnsutils or dnsutils). Save the key as /etc/acme-ywt-example.ch.key, readable only by root:

key "acme-0123456789.example.ch." {
  algorithm hmac-sha256;
  secret "<secret>";
};

Then issue the certificate:

NSUPDATE_SERVER=ns1.ywt.ch NSUPDATE_ZONE=example.ch NSUPDATE_KEY=/etc/acme-ywt-example.ch.key \
  acme.sh --issue --dns dns_nsupdate -d example.ch -d '*.example.ch'

acme.sh remembers these settings and uses them for its automatic renewals.

lego reads the key from environment variables:

RFC2136_NAMESERVER=<IP address of ns1.ywt.ch> \
RFC2136_TSIG_ALGORITHM=hmac-sha256. \
RFC2136_TSIG_KEY=acme-0123456789.example.ch. \
RFC2136_TSIG_SECRET='<secret>' \
  lego --email you@example.com --dns rfc2136 -d example.ch -d '*.example.ch' run

Renew with the same variables and renew instead of run.

Troubleshooting

  • update failed: REFUSED or NOTAUTH: the key name or secret is wrong, the key was revoked, or _acme-challenge is a CNAME (see above).
  • The update succeeds but no record appears: the tool tried to write something other than a TXT record at an _acme-challenge name. Only those are accepted; the rest of an update is skipped.
  • Validation fails right after the update: the record needs a few seconds to reach both nameservers. The tools wait for this by default (certbot 60 seconds); check with dig TXT _acme-challenge.example.ch @ns2.ywt.ch.

Revoke a key

Click Revoke next to the key. Tools that still use it can no longer update DNS, so their next renewal fails until they get a new key. Revoke a key whenever a server that holds it is retired or may be compromised.

On this page