Skip to content

DNS Providers

DNS Providers enable automated DNS-01 challenge validation for ACME-based certificate issuance. When you request a certificate from an ACME CA (like Let’s Encrypt), SSL-CLM can automatically create and clean up the required _acme-challenge TXT records via your DNS provider’s API.

Navigation: Sidebar → Infrastructure → DNS Providers


ColumnDescription
DomainThe DNS zone/domain this provider manages
Provider TypeDNS service (Cloudflare, AWS Route53, Azure DNS, Hostinger)
VerifiedWhether domain ownership has been verified
Verified AtTimestamp of last successful verification
ActionsEdit, Verify, Delete

ProviderType IDAuthentication
CloudflareCLOUDFLAREAPI Token or Global API Key + Email
AWS Route 53AWS_ROUTE53AWS Access Key ID + Secret Access Key
Azure DNSAZURE_DNSTenant ID + Client ID + Client Secret
HostingerHOSTINGERAPI Token

  1. Click + Add DNS Provider
  2. Select the provider type
  3. Enter configuration:
FieldDescription
DomainZone name (e.g., example.com)
API TokenCloudflare API token with DNS edit permissions
Zone ID(Optional) Specific zone ID if managing multiple zones
FieldDescription
DomainHosted zone domain (e.g., example.com)
Access Key IDAWS IAM access key
Secret Access KeyAWS IAM secret key
Hosted Zone ID(Optional) Specific hosted zone ID
RegionAWS region
FieldDescription
DomainDNS zone name
Tenant IDAzure AD tenant ID
Client IDService principal client ID
Client SecretService principal secret
Subscription IDAzure subscription
Resource GroupResource group containing the DNS zone
FieldDescription
DomainDomain name
API TokenHostinger API authentication token
  1. Click Save

After adding a DNS provider, verify that SSL-CLM can manage DNS records:

  1. Click Verify on the provider row
  2. SSL-CLM creates a test TXT record (e.g., _ssl-clm-verify.example.com)
  3. Waits for DNS propagation
  4. Queries DNS to confirm the record exists
  5. Removes the test record
  6. Marks the provider as Verified with a timestamp

If verification fails, check:

  • API credentials have DNS write permissions
  • The domain matches an existing DNS zone
  • Network connectivity to the DNS provider API

When a certificate is requested from an ACME CA using DNS-01 validation:

1. SSL-CLM requests certificate from ACME CA
2. ACME CA responds with DNS-01 challenge token
3. SSL-CLM creates TXT record: _acme-challenge.example.com → {token}
4. SSL-CLM notifies ACME CA that challenge is ready
5. ACME CA verifies TXT record exists
6. ACME CA issues certificate
7. SSL-CLM removes the TXT record (cleanup)

This process is fully automated — no manual DNS intervention required.


ScenarioChallenge TypeDNS Provider Required?
Public web server on port 80/443HTTP-01No
Wildcard certificate (*.example.com)DNS-01Yes
Internal server (no public access)DNS-01Yes
Server behind firewall/NATDNS-01Yes
Standard domain certificateHTTP-01 or DNS-01Optional

Wildcard certificates always require DNS-01 validation. This is an ACME protocol requirement.


DNS provider management requires:

  • dns:read — View DNS providers
  • dns:configure — Add, edit, verify, and delete DNS providers

IssuePossible CauseResolution
Verification failsInsufficient API permissionsCheck that the API token/key has DNS zone write access
Challenge timeoutDNS propagation delayIncrease retry timeout; check DNS TTL settings
Record not createdWrong zone ID or domain mismatchVerify the domain matches the DNS zone exactly
Auth errorExpired or rotated credentialsUpdate the provider credentials