Skip to main content

Certbot plugin for Oxford Hydra DNS API

Project description

Certbot Hydra Plugin

A certbot Hydra plugin for use with the University of Oxford Hydra DNS system.

Enables the use of certbot to create a LetsEncrypt SSL certificate, which in turn can be used to automate SSL certificate renewal.

As the ownership validation mechanism uses DNS, no direct access is required to the website or service being protected with the certificate. This is especially useful to help generate SSL certificates for internal infrastructure or other services not open to the world.

Hydra Tokens

This plugin uses the Hydra API, access by the token based authentication mechanism, described at https://blogs.it.ox.ac.uk/networks/2024/05/31/hydra-token-authentication/, with further detail documented at https://wiki.it.ox.ac.uk/networks/HydraTokens.

To create a token, navigate to https://www.networks.it.ox.ac.uk/itss/ipam/allocations and then search for the (sub)domain you want to create a token for.

The token should be restricted to only have access to the records it needs to modify.

Setup

To you use the plugin you should follow the instructions in the links above to generate a set of credentials then populate a config file (for example /etc/letsencrypt/dns-hydra.ini) with data in the following format:

[dns_hydra]
api-username = x/y 
api-password = zzzzzzzz

This file needs to be suitable secured as it contains credentials which can modify your dns and are also providing proof of ownership of the domain.

Usage

Once installed, run with command:

certbot certonly --authenticator dns-hydra --dns-hydra-config-file /etc/letsencrypt/dns-hydra.ini -d yourdomain.jordan.ox.ac.uk

All being well, this will create a set of certificate files in the normal letsencrypt / certbot directory (e.g. /etc/letsencrypt/live/yourdomain.jordan.ox.ac.uk) for use by Apache or other applications.

See https://certbot.eff.org/instructions?ws=apache&os=pip for an example of how to use this to setup an auto-renewal of your certificate.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

certbot_dns_hydra-0.2.1.tar.gz (8.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

certbot_dns_hydra-0.2.1-py3-none-any.whl (12.0 kB view details)

Uploaded Python 3

File details

Details for the file certbot_dns_hydra-0.2.1.tar.gz.

File metadata

  • Download URL: certbot_dns_hydra-0.2.1.tar.gz
  • Upload date:
  • Size: 8.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.2

File hashes

Hashes for certbot_dns_hydra-0.2.1.tar.gz
Algorithm Hash digest
SHA256 8af76f2328a02872cf219c61fc771f71bcd72bdb7f592cbdb1217134f7dcb1c1
MD5 f5d5662fdc0a02db677d1a06801f6cf7
BLAKE2b-256 2dc34a55cc3cbea404050da055e5e31be94bb7a3a9b7d657c506640b11498893

See more details on using hashes here.

File details

Details for the file certbot_dns_hydra-0.2.1-py3-none-any.whl.

File metadata

File hashes

Hashes for certbot_dns_hydra-0.2.1-py3-none-any.whl
Algorithm Hash digest
SHA256 46a6bd7e10232ba931b9c9add02ad4a5389f64fb5318b7dfc465f71bd36b4500
MD5 7bd17e7be00a31f5f20e581840d0774d
BLAKE2b-256 9f3601a6417c189892f45666c5c3e9cb492440de222fb6aab21d528cb6d0aa35

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page