Skip to main content

Certbot DNS Authenticator for PowerDNS

PowerDNS DNS Authenticator plugin for Certbot. This plugin uses the PowerDNS HTTP API to request modifications for the DNS-01 challenge.

A design goal of this plugin is to use the minimal amount of custom code to achieve integration with PowerDNS. As such it uses the existing Lexicon-based DNS framework in Certbot.

Installation

  1. Install the plugin from PyPI

    pip install certbot-dns-pdns
    

    Alternatively you can also install both certbot and the plugin using pipx:

    pipx install certbot certbot-dns-pdns
    
  2. Verify that the plugin is installed:

    $ certbot plugins
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    * dns-pdns
    Description: Obtain certificates using a DNS TXT record (if you are using
    PowerDNS for DNS).
    Interfaces: Authenticator, Plugin
    Entry point: EntryPoint(name='dns-pdns',
    value='certbot_dns_pdns.dns_pdns:Authenticator', group='certbot.plugins')
    
    [...]
    

Usage

Create a credentials file to use with this plugin:

~/pdns-credentials.ini

dns_pdns_endpoint = https://pdns-api.example.com
dns_pdns_api_key = <Your API Key>
dns_pdns_server_id = localhost # see https://doc.powerdns.com/authoritative/http-api/server.html
dns_pdns_disable_notify = false # Disable notification of secondaries after record changes

The available configuration options correspond to the DNS-Lexicon settings for the PowerDNS provider.

Run Certbot using the plugin as the authenticator:

certbot certonly \
    --authenticator dns-pdns \
    --dns-pdns-credentials ~/pdns-credentials.ini \
    ...

Contributing

Pull requests are welcome. GitHub automatically runs pre-commit on any pull requests, so you may want to enable pre-commit on your end, so your PR doesn't fail these checks.

This repository uses Conventional Commits commit messages. Check the git log for examples on how to use them.

License

Apache License 2.0

Maintainer

Release files for certbot-dns-pdns 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certbot-dns-pdns 0.1.1
File Size Uploaded
certbot_dns_pdns-0.1.1.tar.gz 6.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certbot-dns-pdns 0.1.1
File Interpreter ABI Platform
certbot_dns_pdns-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 14.9 kB

Release files / certbot_dns_pdns-0.1.1.tar.gz

Download URL certbot_dns_pdns-0.1.1.tar.gz
Size 6.9 kB
Tags Source
SHA-256 checksum
How to use checksums
d059d1c1cc21eab259a24ee69c1d9d8fb077fd90f58cf8de904b0f5bd576986f
BLAKE2b-256 checksum
How to use checksums
1f2afbfd103249b03e842e3886d95725b6860013c6a0d052e6d8013bd4446964
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.0.0 CPython/3.12.3

Release files / certbot_dns_pdns-0.1.1-py3-none-any.whl

Download URL certbot_dns_pdns-0.1.1-py3-none-any.whl
Size 8.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
8e0bf82245323d33ca1c889c9facc24349c5f3ffc951136fe8bf88e1c82060fe
BLAKE2b-256 checksum
How to use checksums
01aaf777db00f1a36a6dd2a91a9a94e4d0af25fd2efeefbc059e14be20577fe4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/5.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page