Skip to main content

certbot-dns-tencentcloud

This package provides a Certbot authenticator plugin that can complete the DNS-01 challenge using the Tencent Cloud API.

Installation

Only Tested on python 3.8, should work on python 3.7 too and forward.

  • no plan to support python2
  • dataclasses is used, so python 3.6 and down will not work. However you can try installing dataclasses from pypi.

Use pip to install this package:

sudo pip3 install certbot-dns-tencentcloud

Verify the installation with Certbot:

sudo certbot plugins

You should see dns-tencentcloud in the output.

Usage

To use this plugin, set the authenticator to dns-tencentcloud via the -a or --authenticator flag. You may also set this using Certbot's configuration file (defaults to /etc/letsencrypt/cli.ini).

You will also need to provide a credentials file with your Tencent Cloud API key id and secret, like the following:

dns_tencentcloud_secret_id  = TENCENTCLOUD_SECRET_ID
dns_tencentcloud_secret_key = TENCENTCLOUD_SECRET_KEY

The path to this file can be provided interactively or via the --dns-tencentcloud-credentials argument.

You can also provide the credential using TENCENTCLOUD_SECRET_ID and TENCENTCLOUD_SECRET_KEY environment variables.

CAUTION: Protect your API key as you would the password to your account. Anyone with access to this file can make API calls on your behalf. Be sure to read the security tips below.

Arguments

  • --dns-tencentcloud-credentials path to Tencent Cloud credentials INI file (Required)
  • --dns-tencentcloud-propagation-seconds seconds to wait before verifying the DNS record (Default: 10)

NOTE: Due to a limitation in Certbot, these arguments cannot be set via Certbot's configuration file.

Example

When in root:

certbot certonly \
  -a dns-tencentcloud \
  --dns-tencentcloud-credentials ~/.secrets/certbot/tencentcloud.ini \
  -d example.com

or if providing credentials using environment variable:

export TENCENTCLOUD_SECRET_ID=<your_secret_id> TENCENTCLOUD_SECRET_KEY=<your_secret_key>
certbot certonly \
  -a dns-tencentcloud \
  -d example.com

Security Tips

Restrict access of your credentials file to the owner. You can do this using chmod 600. Certbot will emit a warning if the credentials file can be accessed by other users on your system.

Use a separate key from your account's primary API key. Make a separate user under your account, and limit its access to only allow DNS access and the IP address of the machine(s) that will be using it.

FAQ

  1. Which strategy should I choose to limit my API key access to only allow DNS resolution related operation?

We now use the new DNSPOD api so you need to give QcloudDNSPodFullAccess strategy (need to add record so write permission is necessary).

  1. renew certs for *.abc.com and abc.com at the same time sometimes show error about incorrect TXT records.

It seems Let's Encrypt cache TXT records for at most 60 seconds, since DNSPod doesn't seem to allow setting TXT record's TTL below 60, in this case the best/safest way is to set --dns-tencentcloud-propagation-seconds longer than 60.

  1. Debug mode?
--dns-tencentcloud-debug true

Metadata

Release files for certbot-dns-tencentcloud 2.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certbot-dns-tencentcloud 2.1.1
File Size Uploaded
certbot_dns_tencentcloud-2.1.1.tar.gz 8.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certbot-dns-tencentcloud 2.1.1
File Interpreter ABI Platform
certbot_dns_tencentcloud-2.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 16.1 kB

Release files / certbot_dns_tencentcloud-2.1.1.tar.gz

Download URL certbot_dns_tencentcloud-2.1.1.tar.gz
Size 8.2 kB
Tags Source
SHA-256 checksum
How to use checksums
0ee523aba325e1d8a45af26af75528e9a3e2b3dea219d7c13597aee910cc1312
BLAKE2b-256 checksum
How to use checksums
98d52a310d57f2c9a959d165cd17d89f55c5b98661dc59892957371f28916d22
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.2

Release files / certbot_dns_tencentcloud-2.1.1-py3-none-any.whl

Download URL certbot_dns_tencentcloud-2.1.1-py3-none-any.whl
Size 7.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e25bfc58d6a24ea7eeb763d178f5519cfadc5334f1104f61ded6adc4993eebc4
BLAKE2b-256 checksum
How to use checksums
a6af42f770c734ca7fc03574e69159863e053558fde2fffa06de3fee72e52780
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.2

Release history Release notifications | RSS feed

This release

2.1.1 This release

2 release files

2.1.0

1 release file

2.0.2

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.3.0

2 release files

1.2.1

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.10

2 release files

1.0.9

2 release files

1.0.8

2 release files

1.0.7

2 release files

1.0.6

2 release files

1.0.5

2 release files

1.0.4

2 release files

1.0.3

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page