Specifically, the intention is to use a single wildcard certificate 
*.intra.example.com rather than one for each subdomain. I don't know if that 
changes anything.

(also I'm new to this mailing list business)

July 9, 2021 4:03 PM, "Brian Candler" <b.cand...@pobox.com 
(mailto:b.cand...@pobox.com?to=%22Brian%20Candler%22%20<b.cand...@pobox.com>)> 
wrote:
On 09/07/2021 14:43, informant--- via Pdns-users wrote:  I intend to set up a 
PowerDNS authoritative server and recursor, where a few subdomains will be 
forwarded to the auth server for internal use only. (local IP addresses) We do 
not wish to allow lookups for these domains by any external host. So far, so 
good.

Now, additionally, I would like to employ Let’s Encrypt certificates for these 
private services by using DNS wildcard challenge. This, of course, requires 
that the DNS server be public. My question, then, is can I set up PowerDNS in 
such a way that the DNS server allows the necessary lookups required to 
complete the DNS challenge, but prevents lookups for any subdomains by any 
external host?  

        You have a domain like "int.example.com" where you don't want any names 
to be visible to the outside world, but you want to be able to obtain 
certificates for them. Correct?
_______________________________________________
Pdns-users mailing list
Pdns-users@mailman.powerdns.com
https://mailman.powerdns.com/mailman/listinfo/pdns-users

Reply via email to