Right now the code sets the DNS server list as the nameservers list to make one TXT query, so as long as one answers the challenge is going to be considered as valid. We need to loop and check each DNS server.
Description
Details
Related Objects
- Mentioned In
- rOSACcefcf253ec24: debian: Add release 0.16 to changelog
rOSACab936d77f339: Release 0.16
rOSAC267463d32fdf: acme_requests: Validate dns-01 challenges against all the DNS servers
rOSAC1b9ce513d7ef: Release 0.16
rOSAC336b26f2406e: Release 0.15
rOSACc7d707122b25: acme_requests: Validate dns-01 challenges against all the DNS servers
rOSAC0f8ae91f7e61: acme_requests: Validate dns-01 challenges against all the DNS servers
rOSAC94faa1b2c996: acme_requests: Validate dns-01 challenges against all the DNS servers
T219414: acme-chief fails to issue certificates against LE staging environment - Mentioned Here
- T203396: certcentral: challenge checking on *all* pooled backend hosts
Event Timeline
Dupe of T203396: certcentral: challenge checking on *all* pooled backend hosts ? Or not quite? Definitely related either way.
Change 502965 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@master] acme_requests: Validate dns-01 challenges against all the DNS servers
Change 502965 merged by jenkins-bot:
[operations/software/acme-chief@master] acme_requests: Validate dns-01 challenges against all the DNS servers
Change 503000 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@master] Release 0.15
Change 503000 merged by Vgutierrez:
[operations/software/acme-chief@master] Release 0.16
Change 503005 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@debian] acme_requests: Validate dns-01 challenges against all the DNS servers
Change 503006 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@debian] Release 0.16
Change 503005 merged by Vgutierrez:
[operations/software/acme-chief@debian] acme_requests: Validate dns-01 challenges against all the DNS servers
Change 503006 merged by Vgutierrez:
[operations/software/acme-chief@debian] Release 0.16
Change 503010 had a related patch set uploaded (by Vgutierrez; owner: Vgutierrez):
[operations/software/acme-chief@debian] debian: Add release 0.16 to changelog
Change 503010 merged by jenkins-bot:
[operations/software/acme-chief@debian] debian: Add release 0.16 to changelog