Repository navigation
Conversation
Add a section to ACME Basics about the --resolver flag. The flag applies to all DNS queries that step-ca makes. A systemd drop-in file can replace ExecStart, and the RA install script creates one at step-ca.service.d/local.conf. Add a section about DNS propagation. step-ca does not retry a dns-01 validation in the background, so the ACME client must wait for propagation before it requests validation. On the RA page, tell users to edit the drop-in file to change step-ca flags. Refs EFF-883 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Move the DNS resolver section from ACME Basics to Production Considerations, and add it to the table of contents. Remove the systemd drop-in and DNS propagation sections. Refs EFF-883 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Describe your changes:
Production Considerations (
step-ca/certificate-authority-server-production.mdx) has a new section, Using an alternative DNS resolver. It tells when to use--resolver(split-horizon DNS), and that the flag applies to all DNS queries thatstep-camakes.The RA page (
registration-authorities/acme-for-certificate-manager.mdx) now tells that the install script creates the drop-in file/etc/systemd/system/step-ca.service.d/local.conf, and that you must edit this file to changestep-caflags.Note: the example
--resolver 1.1.1.1has no port. Released versions ofstep-caneed a port (1.1.1.1:53). smallstep/certificates#2818 makes the port optional. Merge this PR after a release that includes #2818.Related links/other PRs/issues:
馃 Generated with Claude Code