Re: [Acme] scope in dns-account-01 and dns-02 challenge

2024-03-19 Thread Ilari Liusvaara
On Mon, Mar 18, 2024 at 04:03:07PM -0700, Jacob Hoffman-Andrews wrote: > Thanks, authors, for the updates in > https://datatracker.ietf.org/doc/html/draft-ietf-acme-scoped-dns-challenges-00 > . > > Adding a "scope" (host, wildcard, or subdomain) to the DNS record name is > great. Reading the draft

Re: [Acme] scope in dns-account-01 and dns-02 challenge

2024-03-19 Thread Jacob Hoffman-Andrews
Seo Suchan said: > Would it be illegal to server probe both scope and pass if there is intended token? This is a possibility, but it's inefficient and I think it's likely to lead to implementation bugs. Better to be clear and explicit on both sides. Amir Omidi said: > My intention that I should p

[Acme] expiry in dns-account-01

2024-03-19 Thread Jacob Hoffman-Andrews
The latest dns-account-01 draft ( https://datatracker.ietf.org/doc/html/draft-ietf-acme-scoped-dns-challenges-00) incorporates recommendations from the dnsop domain control verification draft ( https://datatracker.ietf.org/doc/html/draft-ietf-dnsop-domain-verification-techniques-03 ). The dnsop dr