diff --git a/registration-authorities/acme-for-certificate-manager.mdx b/registration-authorities/acme-for-certificate-manager.mdx index f66da0e8..bdc568f6 100644 --- a/registration-authorities/acme-for-certificate-manager.mdx +++ b/registration-authorities/acme-for-certificate-manager.mdx @@ -48,7 +48,7 @@ The script will: - Help you choose a JWK provisioner on your CA to link your RA to - Create RA configuration files in `/etc/step-ca` - Create a `step` user and group -- Add a systemd service called `step-ca.service` +- Add a systemd service called `step-ca.service`, with a drop-in file at `/etc/systemd/system/step-ca.service.d/local.conf` that sets the `step-ca` command line. To change `step-ca` flags, edit the drop-in file. - Enable and start `step-ca.service` - Export a `STEPPATH` variable in `/root/.bash_profile` diff --git a/step-ca/acme-basics.mdx b/step-ca/acme-basics.mdx index 12ab56fb..e086ee9f 100644 --- a/step-ca/acme-basics.mdx +++ b/step-ca/acme-basics.mdx @@ -159,7 +159,6 @@ Finalizing Order .. done! ✔ Private Key: example.key ``` - ## Next steps - Start tailoring `step-ca` to your infrastructure. See [Provisioners](./provisioners.mdx), [Production Considerations](./certificate-authority-server-production.mdx), and our [Configuration Guide](./configuration.mdx). diff --git a/step-ca/certificate-authority-server-production.mdx b/step-ca/certificate-authority-server-production.mdx index e1a3d157..155fb456 100644 --- a/step-ca/certificate-authority-server-production.mdx +++ b/step-ca/certificate-authority-server-production.mdx @@ -27,6 +27,7 @@ safely and securely in a production environment. - [High Availability](#high-availability) - [Proxying `step-ca` traffic](#proxying-step-ca-traffic) - [Exposing `step-ca` to the internet](#exposing-step-ca-to-the-internet) + - [Using an alternative DNS resolver](#using-an-alternative-dns-resolver) - [Certificate Lifecycle Management](#certificate-lifecycle-management) - [Automate Certificate Renewal](#automate-x509-certificate-lifecycle-management) - [Certificate Revocation](#certificate-revocation) @@ -649,7 +650,6 @@ When connecting an ACME provisioner to the internet, you will need to take preca echo https://ca.example.com/acme/$PROVISIONER_NAME/directory } ``` - ### Alternative: Use federation @@ -659,6 +659,19 @@ there's no need to expose your CA to the internet. Use [multiple autonomous federated CAs](../tutorials/pki-trust-model-federation.mdx) instead. +## Using an alternative DNS resolver + +By default, `step-ca` uses the system DNS resolver to look up `dns-01` challenge records. +In a split-horizon DNS environment, the internal resolver may not see the `TXT` records that your ACME client creates at a public DNS provider. +To send DNS queries to a different resolver, start `step-ca` with the `--resolver` flag: + +```shell +step-ca --resolver 1.1.1.1 $(step path)/config/ca.json +``` + +The flag applies to all DNS queries that `step-ca` makes, including `http-01` and `tls-alpn-01` validation and outbound connections to an upstream CA or to webhook servers. + + ## Certificate lifecycle management ### Automate X.509 certificate lifecycle management