Campfire
Archive Tags About

DNS-PERSIST-01: A New Model for DNS-based Challenge Validation

Visit link →
Screenshot of DNS-PERSIST-01: A New Model for DNS-based Challenge Validation
When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges. For subscribers who need wildcard certificates or who prefer not to expose infrastructure to the public Internet, the DNS-01 challenge type has long been the only choice. DNS-01 works well. It is widely supported and battle-tested, but it comes with operational costs: DNS propagation delays, recurring DNS updates at renewal time, and automation that often requires distributing DNS credentials throughout your infrastructure.
February 18, 2026
networking security automation
Permalink: 2026/w08/dns-persist-01-a-new-model-for-dns-based-challenge-validatio

Related Links

  • How tsnet helped Cleric build programmable, zero-config connectivity networking security automation
  • Build a Tiny Certificate Authority For Your Homelab networking security automation
  • Safe Yolo Mode: Running LLM Agents in VMs with Libvirt and Virsh networking security automation
  • Avoir son ASN personnel pour annoncer ses IPs sur Internet networking security automation
  • Building a Multi-Site Kubernetes Cluster with BGP Anycast networking automation security
← Back to Week 08

© 2026 Timo Sugliani · Weekly curated links, shared around the tech campfire