Certbot DNS Micetro Plugin
A certbot plugin for automating DNS-01 challenges using the BlueCat Micetro DNS management system.
Features
- Automatic DNS TXT record creation and cleanup for ACME challenges
- Support for wildcard certificates
- Secure credential management via INI files
- Preference for external DNS zones over internal zones
- Comprehensive logging and error handling
Installation
From PyPI
pip install certbot-dns-micetro
From Source
git clone https://github.com/cedarville-university/certbot-dns-micetro.git
cd certbot-dns-micetro
pip install .
Configuration
Create a credentials INI file with your Micetro API details:
# micetro.ini
# Micetro API credentials for certbot DNS authentication
# Save this file with restricted permissions: chmod 600 micetro.ini
# Username for your Micetro account
dns_micetro_username = your_micetro_username
# Password for your Micetro account
dns_micetro_password = your_micetro_password
# Micetro API base URL (include the protocol and port if needed)
# Example: https://ipam.yourcompany.com/mmws/api/v2
dns_micetro_url = https://your-micetro-server/mmws/api/v2
# DNS view to use for record management (optional)
# If not set, the default view will be used
dns_micetro_view = external
Important: Secure your credentials file:
chmod 600 micetro.ini
Usage
Obtain a certificate
certbot certonly \
--authenticator dns-micetro \
--dns-micetro-credentials /path/to/micetro.ini \
-d example.com
Obtain a wildcard certificate
certbot certonly \
--authenticator dns-micetro \
--dns-micetro-credentials /path/to/micetro.ini \
-d example.com \
-d "*.example.com"
Certificate renewal
Certificates obtained with this plugin will be automatically renewed by certbot using the same DNS challenge method.
API Requirements
This plugin requires:
- Micetro DNS management system with API access
- Valid user account with DNS zone management permissions
- Network connectivity to the Micetro API endpoint
The plugin authenticates using username/password credentials and obtains a session token from the /sessions endpoint.
Zone Selection
When multiple DNS zones exist for the same domain (e.g., internal and external views), this plugin will:
- Prefer external zones over internal zones
- Use the first available zone if no external zone is found
Troubleshooting
Authentication Issues
- Verify your credentials in the INI file
- Ensure the Micetro API URL is correct and accessible
- Check that your user account has appropriate permissions
DNS Issues
- Verify that the domain's DNS zone is managed by Micetro
- Ensure the zone allows dynamic DNS updates
- Check network connectivity to the Micetro server
Debugging
Enable debug logging to troubleshoot issues:
Set environment variable with export CERTBOT_DNS_MICETRO_DEBUG=1 for detailed API request/response logging
or use the --debug flag with certbot:
certbot certonly \
--authenticator certbot-dns-micetro:dns-micetro \
--certbot-dns-micetro:dns-micetro-credentials /path/to/micetro.ini \
-d example.com \
--debug
Development
Setting up development environment
git clone https://github.com/cedarville-university/certbot-dns-micetro.git
cd certbot-dns-micetro
python -m venv venv
source venv/bin/activate # On Windows: venv\Scripts\activate
pip install -e .
pip install -r requirements.txt
Running tests
python -m pytest tests/
Contributing
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add some amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
License
This project is licensed under the Apache License 2.0 - see the LICENSE file for details.
Acknowledgments
- Built on the certbot framework
- Designed for BlueCat Micetro DNS management
- Inspired by other certbot DNS plugins
Support
For issues and questions:
- Open an issue on GitHub
- Check the certbot documentation for general SSL certificate help
Release files for certbot-dns-micetro 1.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| certbot_dns_micetro-1.0.4.tar.gz | 11.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| certbot_dns_micetro-1.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 23.8 kB
Release files / certbot_dns_micetro-1.0.4.tar.gz
| Download URL | certbot_dns_micetro-1.0.4.tar.gz |
|---|---|
| Size | 11.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
8719bfd3ee30cfebf0681fc87661b654f4613fc7d20530f48b10df6ddffc8f8b
|
|
BLAKE2b-256 checksum How to use checksums |
54fb1b8df4dfb8927f13af212114ca5fddfa66c645b5f84819ef6d21e5007f69
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 12, 2025.
Transparency logRelease files / certbot_dns_micetro-1.0.4-py3-none-any.whl
| Download URL | certbot_dns_micetro-1.0.4-py3-none-any.whl |
|---|---|
| Size | 12.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
3f323fdad84293a4fee6565aaf9df6fd5fa28a63365fbe5fee8263e772de1c60
|
|
BLAKE2b-256 checksum How to use checksums |
6defa1f0019bfca1c8d168e2cb23836aeda2dc448c21fabf7a4ed34e0db6fc58
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 12, 2025.
Transparency log