INWX DNS Authenticator plugin for Certbot
Project description
certbot-dns-inwx
INWX DNS authenticator plugin for certbot
An authenticator plugin for certbot to support Let's Encrypt DNS challenges (dns-01) for domains managed by the nameservers of InterNetworX (INWX).
Requirements
- certbot (>=3.0.0)
- setuptools (for manual installation; e.g.
python3-setuptools
)
For older Ubuntu distributions check out this PPA: ppa:certbot/certbot
Installation
- First install the plugin:
- Via Snap (requires certbot to be installed via snap):
snap install certbot-dns-inwx snap set certbot trust-plugin-with-root=ok snap connect certbot:plugin certbot-dns-inwx snap connect certbot-dns-inwx:certbot-metadata certbot:certbot-metadata
- Via pip:
pip install certbot-dns-inwx
-
Configure it with your INWX API Login Details:
vim /etc/letsencrypt/inwx.cfg
with the following content (also see inwx.cfg of the repository):
dns_inwx_url = https://api.domrobot.com dns_inwx_username = your_username dns_inwx_password = """your_password""" dns_inwx_shared_secret = your_shared_secret optional
It is recommended to create a subaccount in the INWX interface and restrict this account to the 'DNS management' role. This prevents the possible loss of your domains in case your account credentials are stolen.
The shared secret is your INWX 2FA OTP key. It is shown to you when setting up the 2FA. It is not the 6 digit code you need to enter when siging in. If you are not using 2FA, simply keep the value the way it is. For general syntax requirements of this file, see here.
-
Make sure the file is only readable by root! Otherwise, all your domains might be in danger:
chmod 0600 /etc/letsencrypt/inwx.cfg
Usage
Request new certificates via a certbot invocation like this:
certbot certonly -a dns-inwx -d sub.domain.tld -d *.wildcard.tld
Renewals will automatically be performed using the same authenticator and credentials by certbot.
Command Line Options
--dns-inwx-propagation-seconds DNS_INWX_PROPAGATION_SECONDS
The number of seconds to wait for DNS to propagate
before asking the ACME server to verify the DNS
record. (default: 60)
--dns-inwx-credentials DNS_INWX_CREDENTIALS
Path to INWX account credentials INI file (default:
/etc/letsencrypt/inwx.cfg)
--dns-inwx-follow-cnames DNS_INWX_FOLLOW_CNAMES
Shall the plugin follow CNAME redirects on validation
records? (default: True)
This command line option is only exposed if
dnspython is installed.
See also certbot --help dns-inwx
for further information.
CNAME Redirects
This plugin supports redirections on the DNS-01 validation records using CNAME records.
For example, you can have a domain a.tld
which is not necessarily managed by INWX and possibly may not be automated via certbot. Additionally, you have a domain b.tld
which is managed by INWX.
An easy solution to automate certificate retrieval for a.tld
is to add a CNAME record for the name _acme-challenge.a.tld
to a.tld
which is pointing to i.e. _a_validation.b.tld
in your providers web interface.
A command like certbot -a dns-inwx -d a.tld
will then make certbot place its validation token at _a_validation.b.tld
via INWX and your validation for a.tld
succeeds.
NOTE: This is an optional feature and requires dnspython to be installed.
To install it use your distribution repository or i.e. pip install dnspython
.
The snap package already ships with it.
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
File details
Details for the file certbot_dns_inwx-3.0.0.tar.gz
.
File metadata
- Download URL: certbot_dns_inwx-3.0.0.tar.gz
- Upload date:
- Size: 14.4 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.12.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | a72beb75118328da629139201457d6ca7562dae49b6d3e3415a7f1e2a433099a |
|
MD5 | f77e602dcbb4be07ffe9f7669a4c8ee3 |
|
BLAKE2b-256 | a08f9f226cf1cc7b669fae1b35120cdd04328c150188fa2b928eab1617e92ee8 |
File details
Details for the file certbot_dns_inwx-3.0.0-py3-none-any.whl
.
File metadata
- Download URL: certbot_dns_inwx-3.0.0-py3-none-any.whl
- Upload date:
- Size: 13.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/5.1.1 CPython/3.12.7
File hashes
Algorithm | Hash digest | |
---|---|---|
SHA256 | 54011d06b3a564f3b18c127b1deb89971976f797ce3f4ddd09f50d17a5728f3d |
|
MD5 | 0179e350aa349be37c26449df800c9b8 |
|
BLAKE2b-256 | c4b5160932201765ea80d5ccf90a2468ccd1349cd3069176d48f013ec7af7d5c |