Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-05 Thread Mark Andrews
Unfortunately comments section on that page doesn’t work. You press preview and you get a error response back. > On 6 Aug 2020, at 02:21, Brett Delmage wrote: > > On Wed, 5 Aug 2020, Mark Andrews wrote: > >> If I use the example zone on that page *no* errors are reported. >> If I modify

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-05 Thread Brett Delmage
On Wed, 5 Aug 2020, Mark Andrews wrote: If I use the example zone on that page *no* errors are reported. If I modify restarchitect.com to have a A record at _acme-challenge.restarchitect.com then errors will be reported. I certainly did get an error originally. I would not have found this

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-04 Thread Mark Andrews
> On 5 Aug 2020, at 13:12, Brett Delmage wrote: > > On Wed, 5 Aug 2020, Mark Andrews wrote: > >> Your key name usage is not consistent. acmesh-ottawatch != ottawatch-acmesh > > Thank you! Fixed and working. > >> Why are you adding `check-names warn;`? check-names does NOT apply to TXT >>

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-04 Thread Brett Delmage
On Wed, 5 Aug 2020, Mark Andrews wrote: Your key name usage is not consistent. acmesh-ottawatch != ottawatch-acmesh Thank you! Fixed and working. Why are you adding `check-names warn;`? check-names does NOT apply to TXT records. Previously I was getting the error "bad owner name

Re: Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-04 Thread Mark Andrews
Thanks for full details. Your key name usage is not consistent. acmesh-ottawatch != ottawatch-acmesh Why are you adding `check-names warn;`? check-names does NOT apply to TXT records. Mark > On 5 Aug 2020, at 08:44, Brett Delmage wrote: > > I'm having a problem getting nsupdate to work, as

Cannot get nsupdate to work (for letsencrypt acme.sh client)

2020-08-04 Thread Brett Delmage
I'm having a problem getting nsupdate to work, as shown below. (Despite reading the man pages I'm not 100% clear about the exact scope of the grant options and it may not be right. Examples would be helpful.) I generated the key: ddns-confgen -k acmesh-ottawatch. -z ottawatch.ca # To