acmesh-official / acmesh-official/acme.sh

use specified DNS accounts per domain, is it possible ?

Aperta
#6,781 2 commenti 0 reazioni 0 assegnatari Vedi su GitHub
Lingua principale
Shell
Stelle
47.6k
Fork
5.7k
Merge medio
6g 5h
PR unite (30g)
15

Descrizione

We use acme.sh + acme-dns. acme-dns allows only two TXT records per its account/subdomain. Now we need to specify 3-4 SANs in a single LE certificate. Command looks like this:

```
command: >
acme.sh
--issue
--dns dns_acmedns
--always-force-new-domain-key
-d {{ item.domains | join(' -d ') }}
--cert-file "/nginx-root/{{ item.name }}/cert.pem"
--key-file "/unencrypted-keys/{{ item.name }}/key.pem"
--fullchain-file "/nginx-root/{{ item.name }}/fullchain.pem"
--reloadcmd "..."
```
this commans is executed in docker container. There are environment variables ACMEDNS_BASE_URL, ACMEDNS_USERNAME, ACMEDNS_PASSWORD, ACMEDNS_SUBDOMAIN. All works until `item.domains` contains 1-2 domains. If it contains 3 or more domains acme.sh failed to issue cert after timeout (~20 minutes). When it tries to do get cert I can see only two TXT record in acme-dns but I expected to see 3 or more.

Then I fount that acme-dns does "Rolling update of two TXT records" per account.When creating new account it creates just two empty TXT records in its database and these records are updated by rolling update - no new records are created, just two with rolling update.

So I would like from acme.sh the ability to specify DNS account config per domain and also use the default configuration if per-domain config is not specified.
Is it possible ?

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start by reproducing with the provided `acme.sh --issue --dns dns_acmedns ...` command using 3+ domains instead of 1-2. Next locate the `dns_acmedns` execution path and where `ACMEDNS_BASE_URL`, `ACMEDNS_USERNAME`, `ACMEDNS_PASSWORD`, and `ACMEDNS_SUBDOMAIN` are consumed to confirm whether only one account context is supported. Then run the same containerized flow and compare expected DNS TXT records versus actual acme-dns updates. Done means certificate issuance succeeds reliably for >2 SANs with per-domain (or default-fallback) account behavior, or there is a clear documented limitation.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
bash, shell
Ambito
cli, tooling
Tipo di issue
Funzionalità
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Abbastanza chiara
Idoneità per principianti
44/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.