惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
News and Events Feed by Topic
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
T
Threat Research - Cisco Blogs
Cloudbric
Cloudbric
Recent Commits to openclaw:main
Recent Commits to openclaw:main
I
Intezer
Attack and Defense Labs
Attack and Defense Labs
P
Privacy International News Feed
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
L
Lohrmann on Cybersecurity
C
Cybersecurity and Infrastructure Security Agency CISA
V2EX - 技术
V2EX - 技术
AWS News Blog
AWS News Blog
O
OpenAI News
L
LINUX DO - 最新话题
N
News | PayPal Newsroom
PCI Perspectives
PCI Perspectives
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Troy Hunt's Blog
Latest news
Latest news
D
Darknet – Hacking Tools, Hacker News & Cyber Security
A
Arctic Wolf
Spread Privacy
Spread Privacy
G
GRAHAM CLULEY
T
Tor Project blog
博客园_首页
Know Your Adversary
Know Your Adversary
有赞技术团队
有赞技术团队
S
Secure Thoughts
美团技术团队
Apple Machine Learning Research
Apple Machine Learning Research
爱范儿
爱范儿
T
Tailwind CSS Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
V
Visual Studio Blog
J
Java Code Geeks
Cisco Talos Blog
Cisco Talos Blog
Schneier on Security
Schneier on Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
S
Security Affairs
Jina AI
Jina AI
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
宝玉的分享
宝玉的分享
量子位
Last Week in AI
Last Week in AI
月光博客
月光博客
罗磊的独立博客
S
SegmentFault 最新的问题

Let's Encrypt Community Support - Latest topics

New Certificate Fails with Unauthorized 403 Seeking Clarity and Consistency on Configuring HTTP-01 challenge for multiple domains Certifiate failing renewal Letsencrypt blocked in Iran Problem with http verification Cyber-attacks from the secondary verification source addresses Certbot failed to authenticate some domains (authenticator: webroot). The Certificate Authority reported these problems: How will clients handle X2 by X1 cross certificate revocation HTTPS Certificate Renewal and Mixed Content Issues Affecting My Real-Time Morse Code Website Using Let’s Encrypt .conf Files and Nginx along with Certbot Forbidden by policy error generating the let’s encrypt certificate SSL Certificate installed for 1 of 2 domains Certificate apparently not working Certbot 5.6.0 Release Would signing the key authorization with the ACME private key increase security? Lego 5.0.0 Release Certificate renewal incomplete: missing domains beeandlunetrading.com We can’t renew your Let’s Encrypt certificate automatically until the issue is resolved Is using preferred-chain "ISRG Root X2" still a good idea? Crypt::LE --delayed not being honored Expressway certificate renewal error even after upgrading to the latest version Yocto Bitbake install of Certbot luadns fails with 'NoneType' object is not callable Intended audience for "tlsserver" profile Trouble finding Charter Communications as Web Hoster 2026.05.08 Gen Y Cross-Certified Subordinate CAs missing serverAuth EKU Certbot deploy-hook Obtaining account ID from xmox.nl email server SSL Certificate Expired - pwgroup.plabcapy.com More cultural recognition of HTTPS adoption Certificado certbot Upcoming Let’s Encrypt Profile Changes On May 13 Lets encrypt certificate issued website scam Issues getting certificates for .de zone Certbot-dns-multi for dns-lego fails with request for two domains Will tlssever profile switch to 45 days next week? Certbot script searching Expired certs shut done websites Automatic renewal across multiple systems serving the same domain Account paused – Request to unpause domain exodus.digitalmansa.com Certificate for web theft phucnha.com DNS-PERSIST without spending an Order Certificate Expired, now I can't create a new one Account paused Invalid unpause URL I need to revoke a cert, how do i do this Recommended Certbot Config for 2 certs with same FQDN with different acme servers The Certificate Authority failed to verify the temporary Apache configuration changes made by Certbot Cannot load certificate "/etc/letsencrypt/live/laurexplore.fr/fullchain.pem" A small static ACME server to distribute certs Certferry - easy distribution of wildcard LE certificates Permission errors on Let's ENcrypt certificate requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer')) The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot LetsEncrypt Consultation SSL/TLS certificate Issue ISRG may have received a National Security Letter or FISA Court Order? Deactivating pending authorization Perhaps this domain is at risk group and is blacklisted on the Let's Encrypt side Certificate renewal error Azuracast letsencrypt error Certbot change provider from Sectigo to CertiNext Privacy policy still mentions disabled services Letsencrypt[.]top is squatting on the LE name and acting as a web client Cert renews not working anymore Root Cert Protection and Signing Process for e.g. Intermediates or Cross-Signs of new Roots DNS Challenge failed incorrect TXT value FreeCert: a lightweight ACME management module for shared hosting and cPanel Certbot is rejecting its own specified _acme-challenge value Not able to renew certificates Issue of SSL Certificate fails Today instantly SSL certificate problems Issue an SSL certificate Wacs Domain cert generation - test successful but real fails 400 Posh-acme db_error submitting renewal Safari won't trust Let's Encrypt certs Does Certbot support CNAME challenge? How does CNAME validation work vs DNS-01? Win-Acme Renewal Failing Suddenly with DNS-01 (Dreamhost) My certicate is obsokete Certbot failed to authenticate some domains Possible deliberate publicly admitted violation of subscriber policy by Tom Murphy VII in the form of HTTPV ARI renewal-info Rate Limit Changes? Missing accounturi field in LE dns-persist-01 challenges Problem obtaining a certificate One cert failing to renew - don't know why Dns-persist-01 deployment status and timeline Issue (apparently) after upgrading certbot/ubuntu [nginx] IPv4 OK, IPv6 NOK Expressway ACME Certificate Renewal failing Certbot nginx challenge times out Certbot 5.5.0 Release Error unmarshaling request Try t Self-Host BitWarden - Having Issues Getting a Cert Various problems with three domains cme_registration.reg: Creating... ╷ │ Error: acme: error: 403 :: POST :: https://acme-v02.api.letsencrypt.org/acme/new-acct :: urn:ietf:params:acme:error:unauthorized :: An account with the provided public key exists but is deactivated Iran's internet outage and challenges for renewing letsencrypt certs Running multiple Certbot renewals in parallel — how to bypass the global lock file? Nginx ipv64.net Fritzbox Dietpi DNS-PERSIST-01 and _validation-persist CNAME Just a small certbot script check An easy way to publish dns-persist-01 records Problem finding dns-persist-01 in staging GoDaddy API access policy update
CNAME and CAA clarification
@Atmospheric · 2026-04-17 · via Let's Encrypt Community Support - Latest topics

April 15, 2026, 3:45pm 1

Hi, I'm trying to understand the CAA issuance policy when it comes to CNAMES.

I have the following situation:

jeaton.org.                3600    IN      CAA     0 issue "sectigo.com"

foo.jeaton.org.  3600    IN      CNAME   bar.jeaton.com.
bar.jeaton.com. 231    IN      CNAME   prod-cf-alb-XXXX.us-east-1.elb.amazonaws.com.

foo.jeaton.org (CNAME in my domain) points to a vendor hostname. Vendor hostname is a CNAME to their amazonaws instance.

I want to allow the vendor to have a letsencrypt.org certificate issued for foo.jeaton.org, which they manage fully.

Right now, as I understand it, letsencrypt will attempt CAA verification. Because they are CNAME records, those are followed and the CAA for prod-cf-alb-XXXX.us-east-1.elb.amazonaws.com is requested. There is no CAA record there, so it walks up the original hostname tree, from foo.jeaton.org to jeaton.org, and finds the CAA policy there which limits issuance to Sectigo, and denies the request.

Since foo.jeaton.org is a CNAME, I can't create a CAA record there. Since bar.jeaton.com is a CNAME, the vendor can't create a CAA record there. Amazon presumably won't create a CAA record for their domain name (I don't actually know, since I'm not Amazon's customer).

Is the only solution to allow letsencrypt.org at the prod-cf-alb-XXXX.us-east-1.elb.amazonaws.com or at the top level of jeaton.org ? I can't do the former, and I don't want to do the latter.

If this is the case, this seems like a fundamental design flaw in using CAA records with CNAMEs, instead of allowing something like _caa.foo.jeaton.org (which I could create).

Correct.

If the vendor wants to be the one to manage and have certificates issued, the CNAME should point to their hostname that does have a CAA record for the providers they're planning on using. It probably shouldn't be a CNAME to some provider like AWS that wouldn't allow for that sort of thing. But a lot of vendors don't know how to handle this properly.

Yes. (Or, change the CNAME to point somewhere else. or to not be a CNAME.)

Well, I can see how it was a choice of tradeoffs that aren't the same choices everyone would have made. But CAA isn't exactly new at this point, and vendors would hopefully know the requirements by now.

5 Likes

rmbolger April 15, 2026, 5:57pm 3

ACME specifics aside, ultimately CNAME records are just delegations. You as the zone owner are giving control over that particular FQDN to a 3rd party for all record types which includes CAA records.

You don't get to decide what sort of cert the vendor will get when you point your records to their namespaces. If they need a cert, they can deal with it because they now control that name. If they need a CAA record for whatever CA they choose to use, they'll have to create it on their own.

3 Likes

jeaton3 April 15, 2026, 7:25pm 4

That's entirely the problem.

The vendor wants to get a letsencrypt.org cert. I want to allow them to do so specifically for this hostname. Given the use of CNAMEs, I can't set one to exempt it from my top-level domain policy. Because the vendor runs on top of AWS and uses CNAMES pointing to AWS for their servers, they can't set one either, only Amazon can. So now no one can get a cert for the service.

I'm trying to work with the vendor to see if they can use my preferred CA, but if not, we're going to be stuck either opening up the entire domain to allowing the entire domain to get letsencrypt certs, or having to rearchitect the service.

I wish I knew why they went with a new RR type instead of a DKIM-like _caa.example.org TXT record.

Oh well.

rmbolger April 15, 2026, 7:51pm 5

If the vendor is running their infrastructure on AWS, why are they trying to get a Let's Encrypt cert instead of an AWS ACM cert which is also free and easily integrates (including automatic renewals) with AWS services such as ALB/NLB?

In any case, it shouldn't be your problem. It's the vendor's problem to deal with.

3 Likes

MikeMcQ April 15, 2026, 7:57pm 6

Have you considered adding a CAA record at your top level that allows only your vendor's ACME account to use LE for your domain?

Like shown at these examples: Certificate Authority Authorization (CAA) - Let's Encrypt

2 Likes

jeaton3 April 15, 2026, 8:28pm 7

If I had a nickel for every time I've asked "why doesn't the vendor..."

It may not be my fault, but it is my problem. :frowning:

Thanks all for your help. I have to fight my way through vendor support to talk to someone who can actually tell me what they can do, since I can't really do anything to fix this.

rmbolger April 15, 2026, 8:57pm 8

If they can tell you why they think they need a Let's Encrypt cert specifically, we might be able to provide guidance. My gut says they're trying to get an LE cert for the origin/backend boxes sitting behind the AWS ALB which is totally unnecessary. Last I checked, ALB does zero cert validation between itself and the origin servers. So you can use any origin cert you want including self-signed, expired, etc.

4 Likes

Why is that a problem? If you need multiple accounts to be able to issue LE certificates, you could limit it to methods, like "letsencrypt.org;validationmethods=dns-01"

This will prevent for example end user customers, from validating with http-01 while having no DNS access, while subvendors still can issue certificates.

However, this still requires Amazon to set up the actual validation records - but maybe their panel actually have support for validation records, as opposed to CAA records.

Another way is to use the accounturi parameter, and then simply sharing account private key with those that should be able to issue for your domain.

For what I know, lets encrypt won't parse multiple CAA with "letsencrypt.org;accounturi" and will stop at the first one.

Boulder (the ACME server implementation used by Let's Encrypt) will check all CAA records for the relevant domain to test whether any of them authorise the issuance. The code for this is at boulder/va/caa.go at e987484a9fd4931bf4c25c3c0c82f7dd3f11e13e · letsencrypt/boulder · GitHub

1 Like

ooh then its no problem for the OP. Then he can make multiple letsencrypt records with different accounturi parameters.

I tought the parsing logic was, "stop at the first CAA record that is "yours" and then read the parameters".

but in this case its simple for the OP to just authorize the accounturi for his all "sub-customers", without opening up his whole domain for issuance.

I asked a very similar question a couple of weeks ago, maybe this thread will help you how CNAME records work.