Comment on Issue #64 that was blocking DNS-PERSIST-01 has been resolved
IanTwenty@piefed.social 1 week ago
So if I understand: hosters will be able to provide the proof at a time/schedule of their choosing. On actual servers a simpler, automated cert renew process without the need for them to hold nameserver API credentials.
You put an account id/token into dns, which allows machines to renew the cert under that account with just the account credentials (key).
So after setting it up, the token stays the same forever and you don’t need to touch dns.
Such tokens are already used by acme clients when they renew their certs. It’s also how acme providers can detect expiring certificates for example.
I find it a bit weird, since the whole deal of shortening lifetimes was in part to protect against stolen certificates, and now by stealing the account key you are again stealing the ability to indefinitely make certificates.
At least you can “revoke” such access by switching the account and updating the dns record authorizing it.