gibdns-desec
gibdns provider for deSEC. Hosts such as gibcert execute this binary to publish ACME DNS-01 TXT records and DANE TLSA records.
| Protocol | TXT | TLSA | Zone discovery |
|---|---|---|---|
gibdns/draft-01 |
yes | yes | yes |
Install
Download the archive or .deb for your OS from the
releases page.
Debian package (installs to /usr/libexec/gibdns):
sudo dpkg -i gibdns-desec_*_linux_amd64.deb
Tarball:
sudo install -D -m 0755 gibdns-desec /usr/local/libexec/gibdns/gibdns-desec
From source:
make install PREFIX=/usr/local
The binary is not an interactive CLI and is intentionally not installed on
PATH. Confirm the installation, then let the host invoke it:
# Debian package:
test -x /usr/libexec/gibdns/gibdns-desec
# Source or tarball install:
test -x /usr/local/libexec/gibdns/gibdns-desec
Use /usr/libexec/gibdns/gibdns-desec for a Debian package or
/usr/local/libexec/gibdns/gibdns-desec for a source or tarball install in
host configuration. See Using gibdns
for the host and provider split.
Use with gibcert
Store a deSEC token at /etc/gibcert/desec-token with mode 0600. The token
must not have token-management permission. Then:
provider desec {
type dns
driver exec
command /usr/libexec/gibdns/gibdns-desec
zone example.com.
secret token {
file /etc/gibcert/desec-token
}
}
certificate wildcard-example.com {
account letsencrypt
names example.com *.example.com
challenge dns-01 {
provider desec
propagation-timeout 120s
}
}
zone is optional because this provider advertises zone discovery. Set it
when you want an exact zone selector. If installed from source or a tarball,
use /usr/local/libexec/gibdns/gibdns-desec instead.
gibcert binding details are in External DNS Providers.
Secrets
token(required): a deSEC token without token-management permission
Config
api_url(optional)
deSEC RRsets have a default minimum TTL of 3600 seconds. The provider
advertises that constraint and honors ttl_policy. Patch is implemented as
GET then PUT of the complete RRset, so concurrent_safe_patch is false.
Clients such as gibcert should use if_revision.
Development
make test
make build
make snapshot
Publish a tagged release with make release. That target runs GoReleaser via
go run; a GITEA_TOKEN with package/release access is required.