Update README.md
This commit is contained in:
parent
cbd3045a82
commit
9f20694196
1 changed files with 50 additions and 93 deletions
87
README.md
87
README.md
|
@ -1,64 +1,40 @@
|
|||
# certbot-dns-ionos
|
||||
|
||||
IONOS DNS Authenticator plugin for Certbot
|
||||
|
||||

|
||||
|
||||
This plugin automates the process of completing a ``dns-01`` challenge by
|
||||
creating, and subsequently removing, TXT records using the IONOS Remote API.
|
||||
|
||||
## Configuration of IONOS
|
||||
|
||||
In the `System -> Remote Users` you have to have a user, with the following rights
|
||||
|
||||
- Client Functions
|
||||
- DNS zone functions
|
||||
- DNS txt functions
|
||||
|
||||
|
||||
.. _IONOS: https://www.ionos.de/
|
||||
.. _Certbot: https://certbot.eff.org/
|
||||
|
||||
## Installation
|
||||
|
||||
### Snap
|
||||
|
||||
[](https://snapcraft.io/certbot-dns-ionos)
|
||||
|
||||
|
||||
### Pip
|
||||
|
||||
`pip install certbot-dns-ionos`
|
||||
|
||||
|
||||
## Named Arguments
|
||||
|
||||
To start using DNS authentication for ionos, pass the following arguments on
|
||||
certbot's command line:
|
||||
| Command args | Command definition |
|
||||
| --- | --- |
|
||||
|``--authenticator dns-ionos`` | select the authenticator plugin (Required) |
|
||||
|``--dns-ionos-credentials`` |ionos Remote User credentials INI file. (Required) |
|
||||
|``--dns-ionos-propagation-seconds``|waiting time for DNS to propagate before asking the ACME server to verify the DNS record. (Default: 10, Recommended: >= 600) |
|
||||
|
||||
|
||||
|
||||
|``--dns-ionos-propagation-seconds``|waiting time for DNS to propagate before asking the ACME server to verify the DNS record. (Default: 30, Recommended: 60) |
|
||||
## Credentials
|
||||
|
||||
An example ``credentials.ini`` file:
|
||||
|
||||
```ini
|
||||
dns_ionos_prefix = myapikeyprefix
|
||||
dns_ionos_secret = verysecureapikeysecret
|
||||
dns_ionos_endpoint = https://api.hosting.ionos.com
|
||||
```
|
||||
The key can be managed under the following link: https://developer.hosting.ionos.de/?source=IonosControlPanel
|
||||
|
||||
The path to this file can be provided interactively or using the
|
||||
`--dns-ionos-credentials` command-line argument. Certbot
|
||||
records the path to this file for use during renewal, but does not store the
|
||||
file's contents.
|
||||
|
||||
> [!CAUTION]
|
||||
> You should protect these API credentials as you would the
|
||||
password to your ionos account. Users who can read this file can use these
|
||||
|
@ -66,21 +42,17 @@ credentials to issue arbitrary API calls on your behalf. Users who can cause
|
|||
Certbot to run using these credentials can complete a ``dns-01`` challenge to
|
||||
acquire new certificates or revoke existing certificates for associated
|
||||
domains, even if those domains aren't being managed by this server.
|
||||
|
||||
Certbot will emit a warning if it detects that the credentials file can be
|
||||
>
|
||||
> Certbot will emit a warning if it detects that the credentials file can be
|
||||
accessed by other users on your system. The warning reads "Unsafe permissions
|
||||
on credentials configuration file", followed by the path to the credentials
|
||||
file. This warning will be emitted each time Certbot uses the credentials file,
|
||||
including for renewal, and cannot be silenced except by addressing the issue
|
||||
(e.g., by using a command like ``chmod 600`` to restrict access to the file and
|
||||
``chmod 700`` to restrict access to the folder).
|
||||
|
||||
|
||||
## Examples
|
||||
|
||||
To acquire a single certificate for both ``example.com`` and
|
||||
``*.example.com``, waiting 900 seconds for DNS propagation:
|
||||
|
||||
```bash
|
||||
certbot certonly \
|
||||
--authenticator dns-ionos \
|
||||
|
@ -93,18 +65,13 @@ To acquire a single certificate for both ``example.com`` and
|
|||
-d '*.example.com'
|
||||
```
|
||||
## Docker
|
||||
|
||||
In order to create a docker container with a certbot-dns-ionos installation,
|
||||
create an empty directory with the following ``Dockerfile``:
|
||||
|
||||
```docker
|
||||
|
||||
FROM certbot/certbot
|
||||
RUN pip install certbot-dns-ionos
|
||||
```
|
||||
|
||||
Proceed to build the image
|
||||
|
||||
```docker
|
||||
docker build -t certbot/dns-ionos .
|
||||
```
|
||||
|
@ -130,33 +97,23 @@ chown root:root /etc/letsencrypt/.secrets
|
|||
chmod 700 /etc/letsencrypt/.secrets
|
||||
```
|
||||
The file 'domain.tld.ini' must be replaced with the version of the example 'credentials.ini' adapted to your provider.
|
||||
|
||||
## Changelog
|
||||
|
||||
- 2024.01.08
|
||||
|
||||
- Update README.rst
|
||||
- Add Link to IONOS control panel and reference between credentials.ini and domain.tld.ini
|
||||
|
||||
- 2023.11.13
|
||||
|
||||
- Fix managed zone lookup to ensure correct domain is selected where there are two domains with the same ending e.g. example.com and thisisanexample.com (PR #22)
|
||||
|
||||
- 2022.11.24
|
||||
|
||||
- remove zope to fix compatibility with Certbot 2.x (Fixes #19)
|
||||
|
||||
As a reminder, Certbot will default to issuing ECDSA certificates from release 2.0.0.
|
||||
If you update from a prior certbot release, run the plugin once manually. You will be prompted
|
||||
to update RSA key type to ECDSA.
|
||||
|
||||
- 2022.05.15
|
||||
- Added capability to handle multiple domain validations #16
|
||||
|
||||
- 2021.09.20.post1
|
||||
|
||||
- Fix version number
|
||||
|
||||
- 2021.09.20
|
||||
|
||||
- Fix #9 Domain not known when using subdomain
|
||||
* 2024.10.15
|
||||
* Update README.md, changed from README.rst
|
||||
* Addition of a snap
|
||||
* Correction in case of API error
|
||||
* 2024.01.08
|
||||
* Update README.rst
|
||||
* Add Link to IONOS control panel and reference between credentials.ini and domain.tld.ini
|
||||
* 2023.11.13
|
||||
* Fix managed zone lookup to ensure correct domain is selected where there are two domains with the same ending e.g. example.com and thisisanexample.com (PR #22)
|
||||
* 2022.11.24
|
||||
* Remove zope to fix compatibility with Certbot 2.x (Fixes #19)
|
||||
* As a reminder, Certbot will default to issuing ECDSA certificates from release 2.0.0.
|
||||
* If you update from a prior certbot release, run the plugin once manually. You will be prompted to update RSA key type to ECDSA.
|
||||
* 2022.05.15
|
||||
* Added capability to handle multiple domain validations #16
|
||||
* 2021.09.20.post1
|
||||
* Fix version number
|
||||
* 2021.09.20
|
||||
* Fix #9 Domain not known when using subdomain
|
||||
|
|
Loading…
Reference in a new issue