Skip to content

Document the step-ca --resolver flag and dns-01 retries - #566

Open
tashian wants to merge 2 commits into
mainfrom
carl/eff-883-document-dns-resolver-configuration-and-retry-behavior
Open

tashian wants to merge 2 commits into
mainfrom
carl/eff-883-document-dns-resolver-configuration-and-retry-behavior

Conversation

@tashian

@tashian tashian commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Describe your changes:

Production Considerations (step-ca/certificate-authority-server-production.mdx) has a new section, Using an alternative DNS resolver. It tells when to use --resolver (split-horizon DNS), and that the flag applies to all DNS queries that step-ca makes.

The RA page (registration-authorities/acme-for-certificate-manager.mdx) now tells that the install script creates the drop-in file /etc/systemd/system/step-ca.service.d/local.conf, and that you must edit this file to change step-ca flags.

Note: the example --resolver 1.1.1.1 has no port. Released versions of step-ca need a port (1.1.1.1:53). smallstep/certificates#2818 makes the port optional. Merge this PR after a release that includes #2818.

Related links/other PRs/issues:

馃 Generated with Claude Code

Add a section to ACME Basics about the --resolver flag. The flag
applies to all DNS queries that step-ca makes. A systemd drop-in file
can replace ExecStart, and the RA install script creates one at
step-ca.service.d/local.conf.

Add a section about DNS propagation. step-ca does not retry a dns-01
validation in the background, so the ACME client must wait for
propagation before it requests validation.

On the RA page, tell users to edit the drop-in file to change step-ca
flags.

Refs EFF-883

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@tashian
tashian requested a review from a team as a code owner October 8, 2026 00:47
Move the DNS resolver section from ACME Basics to Production
Considerations, and add it to the table of contents. Remove the
systemd drop-in and DNS propagation sections.

Refs EFF-883

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant