DNS Providers
DNS Providers
Section titled “DNS Providers”DNS Providers enable automated DNS-01 challenge validation for ACME-based certificate issuance. When you request a certificate from an ACME CA (like Let’s Encrypt), SSL-CLM can automatically create and clean up the required _acme-challenge TXT records via your DNS provider’s API.
Navigation: Sidebar → Infrastructure → DNS Providers
DNS Provider Table
Section titled “DNS Provider Table”| Column | Description |
|---|---|
| Domain | The DNS zone/domain this provider manages |
| Provider Type | DNS service (Cloudflare, AWS Route53, Azure DNS, Hostinger) |
| Verified | Whether domain ownership has been verified |
| Verified At | Timestamp of last successful verification |
| Actions | Edit, Verify, Delete |
Supported Providers
Section titled “Supported Providers”| Provider | Type ID | Authentication |
|---|---|---|
| Cloudflare | CLOUDFLARE | API Token or Global API Key + Email |
| AWS Route 53 | AWS_ROUTE53 | AWS Access Key ID + Secret Access Key |
| Azure DNS | AZURE_DNS | Tenant ID + Client ID + Client Secret |
| Hostinger | HOSTINGER | API Token |
Adding a DNS Provider
Section titled “Adding a DNS Provider”- Click + Add DNS Provider
- Select the provider type
- Enter configuration:
Cloudflare
Section titled “Cloudflare”| Field | Description |
|---|---|
| Domain | Zone name (e.g., example.com) |
| API Token | Cloudflare API token with DNS edit permissions |
| Zone ID | (Optional) Specific zone ID if managing multiple zones |
AWS Route 53
Section titled “AWS Route 53”| Field | Description |
|---|---|
| Domain | Hosted zone domain (e.g., example.com) |
| Access Key ID | AWS IAM access key |
| Secret Access Key | AWS IAM secret key |
| Hosted Zone ID | (Optional) Specific hosted zone ID |
| Region | AWS region |
Azure DNS
Section titled “Azure DNS”| Field | Description |
|---|---|
| Domain | DNS zone name |
| Tenant ID | Azure AD tenant ID |
| Client ID | Service principal client ID |
| Client Secret | Service principal secret |
| Subscription ID | Azure subscription |
| Resource Group | Resource group containing the DNS zone |
Hostinger
Section titled “Hostinger”| Field | Description |
|---|---|
| Domain | Domain name |
| API Token | Hostinger API authentication token |
- Click Save
Domain Verification
Section titled “Domain Verification”After adding a DNS provider, verify that SSL-CLM can manage DNS records:
- Click Verify on the provider row
- SSL-CLM creates a test TXT record (e.g.,
_ssl-clm-verify.example.com) - Waits for DNS propagation
- Queries DNS to confirm the record exists
- Removes the test record
- Marks the provider as Verified with a timestamp
If verification fails, check:
- API credentials have DNS write permissions
- The domain matches an existing DNS zone
- Network connectivity to the DNS provider API
How DNS-01 Validation Works
Section titled “How DNS-01 Validation Works”When a certificate is requested from an ACME CA using DNS-01 validation:
1. SSL-CLM requests certificate from ACME CA2. ACME CA responds with DNS-01 challenge token3. SSL-CLM creates TXT record: _acme-challenge.example.com → {token}4. SSL-CLM notifies ACME CA that challenge is ready5. ACME CA verifies TXT record exists6. ACME CA issues certificate7. SSL-CLM removes the TXT record (cleanup)This process is fully automated — no manual DNS intervention required.
When DNS-01 is Needed
Section titled “When DNS-01 is Needed”| Scenario | Challenge Type | DNS Provider Required? |
|---|---|---|
| Public web server on port 80/443 | HTTP-01 | No |
Wildcard certificate (*.example.com) | DNS-01 | Yes |
| Internal server (no public access) | DNS-01 | Yes |
| Server behind firewall/NAT | DNS-01 | Yes |
| Standard domain certificate | HTTP-01 or DNS-01 | Optional |
Wildcard certificates always require DNS-01 validation. This is an ACME protocol requirement.
Permissions
Section titled “Permissions”DNS provider management requires:
dns:read— View DNS providersdns:configure— Add, edit, verify, and delete DNS providers
Troubleshooting
Section titled “Troubleshooting”| Issue | Possible Cause | Resolution |
|---|---|---|
| Verification fails | Insufficient API permissions | Check that the API token/key has DNS zone write access |
| Challenge timeout | DNS propagation delay | Increase retry timeout; check DNS TTL settings |
| Record not created | Wrong zone ID or domain mismatch | Verify the domain matches the DNS zone exactly |
| Auth error | Expired or rotated credentials | Update the provider credentials |
Related Pages
Section titled “Related Pages”- Certificate Authorities — ACME CA integration that uses DNS providers
- ACME Server — Built-in ACME server with DNS validation support
- Certificates — Certificate issuance that triggers DNS challenges