Skip to main content

Hetzner DNS Authenticator certbot plugin

codecov Tests, Coverage PyPI version Supported Python

This certbot plugin automates the process of completing a dns-01 challenge by creating, and subsequently removing, TXT records using the Hetzner Cloud API.

Requirements

Install

Install this package via pip in the same python environment where you installed your certbot.

pip install certbot-dns-hetzner

Usage

To start using DNS authentication for the Hetzner DNS or cloud API, pass the following arguments on certbot's command line:

Option Description
--authenticator dns-hetzner select the authenticator plugin (Required)
--dns-hetzner-credentials Hetzner DNS API credentials INI file. (Required)
--dns-hetzner-propagation-seconds Seconds to wait for the TXT record to propagate

Please make sure to use the absolute path for the credentials file - some users experienced problems with relative paths.

Version 4.x only supports Hetzner Cloud API

Version 3.x selects either the old DNS API or the new cloud API depending on the provided credentials.
Note: Make sure to use the correct credentials for the different domains. Only one API is working for one domain.

Pre 3.x only the Hetzner DNS API is supported.

Credentials

Generate an API token as described here.

An example credentials.ini file:

dns_hetzner_api_token = nohnah4zoo9Kiejee9aGh0thoopee2sa

Examples

To acquire a certificate for example.com

certbot certonly \\
 --authenticator dns-hetzner \\
 --dns-hetzner-credentials /path/to/my/hetzner.ini \\
 -d example.com

To acquire a certificate for *.example.com

   certbot certonly \\
     --authenticator dns-hetzner \\
     --dns-hetzner-credentials /path/to/my/hetzner.ini \\
     -d '*.example.com'

Troubleshooting

Plugin not showing up

If certbot plugins does not show the installed plugin, you might need to set CERTBOT_PLUGIN_PATH.

CERTBOT_PLUGIN_PATH=/usr/local/lib/python3.X/site-packages/ certbot renew

See letsencrypt community thread

Renewing certificate fails

Please ensure to use an absolute path for the credentials file - some users experienced problems with relative paths.

Not working with snap

We did not nor plan to support snap - it was created from this repo.
Feel free to start a new snap package yourself - we would happily link it here.

Thanks to

Of course certbot, which examples and documentation I used to implement this plugin. And to https://github.com/m42e/certbot-dns-ispconfig which served as an excellent example and README template as well.

and of course to all contributors and people raising issues.

Metadata

Release files for certbot-dns-hetzner 4.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certbot-dns-hetzner 4.0.0
File Size Uploaded
certbot_dns_hetzner-4.0.0.tar.gz 8.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certbot-dns-hetzner 4.0.0
File Interpreter ABI Platform
certbot_dns_hetzner-4.0.0-py2.py3-none-any.whl Python 3, Python 2 none any Details

Total release size: 17.8 kB

Release files / certbot_dns_hetzner-4.0.0.tar.gz

Download URL certbot_dns_hetzner-4.0.0.tar.gz
Size 8.4 kB
Tags Source
SHA-256 checksum
How to use checksums
cc122c13b19e96bac8f9d7f7715887f6e0313b56be253de71e8877a8eacb6e3a
BLAKE2b-256 checksum
How to use checksums
bef1f32ae191b57bb98d5ed7e497c56e4ad815a4766923e96da467c9721501bc
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}

Release files / certbot_dns_hetzner-4.0.0-py2.py3-none-any.whl

Download URL certbot_dns_hetzner-4.0.0-py2.py3-none-any.whl
Size 9.4 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
1dd5d43467bb624996d36a416ceeffb4068be7b315a774a6e7fc2b562140743f
BLAKE2b-256 checksum
How to use checksums
45c5f32e10fe3bdf95360ef7f5a79f27a86be102fbeed5dce1dc8930ed40baef
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via uv/0.11.7 {"installer":{"name":"uv","version":"0.11.7","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"Ubuntu","version":"24.04","id":"noble","libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":true}
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page