aboutsummaryrefslogtreecommitdiffstats
path: root/domains.conf.5
diff options
context:
space:
mode:
authorLexi Winter <ivy@FreeBSD.org>2025-06-04 08:51:26 +0100
committerLexi Winter <ivy@FreeBSD.org>2025-06-04 08:51:26 +0100
commit63f6a3181fea59360b2bfe430f5c798f88b22527 (patch)
treea9f5471dfdc5478a5b337854660773e3bea861b4 /domains.conf.5
parent7284f9864fad4432b6a6e641c03adee321148107 (diff)
downloadlfacme-63f6a3181fea59360b2bfe430f5c798f88b22527.tar.gz
lfacme-63f6a3181fea59360b2bfe430f5c798f88b22527.tar.bz2
add a TSIG-based dns validation handler
while here, reorganise and improve documentation a bit.
Diffstat (limited to 'domains.conf.5')
-rw-r--r--domains.conf.523
1 files changed, 12 insertions, 11 deletions
diff --git a/domains.conf.5 b/domains.conf.5
index ba65610..fd071e4 100644
--- a/domains.conf.5
+++ b/domains.conf.5
@@ -14,9 +14,9 @@ file is used to configure the certificates that
.Nm lfacme
will issue or renew.
Each line specifies one certificate as a series of whitespace-separated fields.
-The first field is the certificate name, which is used internally by
+The first field is the certificate name, which is used by
.Nm lfacme
-in the certificate filename but is not part of the certificate itself.
+to create the certificate filename but is not part of the certificate itself.
The remaining fields are either certificate options or subject alt names for
the certificate.
.Pp
@@ -63,24 +63,25 @@ The challenge script is passed to
.Xr uacme 1 ;
see the uacme documentation for details on the calling convention.
.Pp
-Two challenge scripts are provided with
+The following challenge scripts are provided with
.Nm lfacme :
.Bl -tag -width kerberos
.It Sy http
Use HTTP-based validation.
-This requires
-.Va ACME_HTTP_CHALLENGE_DIR
-to be set in
-.Xr acme.conf 5 .
+See
+.Xr lfacme-http 5 .
This is the default challenge handler.
+.It Sy dns
+Use DNS-based validation with
+.Xr nsupdate 1 .
+See
+.Xr lfacme-dns 5 .
.It Sy kerberos
Use DNS-based validation with
.Xr nsupdate 1
using Kerberos authentication.
-This requires
-.Va ACME_KERBEROS_PRINCIPAL
-to be set in
-.Xr acme.conf 5 .
+See
+.Xr lfacme-kerberos 5 .
.El
.It Sy hook Ns Li = Ns Ar filename
Invoke