Comment on PasswordManagement: which one of these options would you choose?

<- View Parent
Chewy7324@discuss.tchncs.de ⁨8⁩ ⁨months⁩ ago

DNS-01 challenge allows for domain ownership verification without open ports and instead looks for a txt record. Using a tool like lego[1] with the respective dns provider’s API automatically creates and deletes the txt record after generating a certificate.

Because the ownership is verified by dns txt entriy, the (sub-)domain doesn’t have to point to a publicly routable host. This allows for using any IP, so I’m using a local ip only available through wireguard or my local network (E.g. bitwarden.example.com points to 192.168.1.123).

The disadvantage is that the provider has to be supported and you have to store an API key for your domain on the server.

github.com/go-acme/lego

source
Sort:hotnewtop