Add the Let's Encrypt TXT record
Add the _acme-challenge TXT record to a zone in Edge DNS so Let's Encrypt can validate a certificate that Certbot or another ACME client requests.
You can add the TXT record of a Let’s Encrypt DNS-01 challenge to a zone in Edge DNS from Azion Console. Add it when an ACME client outside Azion, such as Certbot, requests the certificate for a hostname of that zone.
A certificate that Azion requests for a workload needs no TXT record from you. When the zone is in Edge DNS, Azion writes the challenge record itself. At another DNS provider, you create a CNAME record instead. To create that record, refer to Issuance and renewal. To have Azion request the certificate, refer to Request a Let’s Encrypt certificate.
Devices that depend on the expired Let’s Encrypt chain cross-signed by IdenTrust reject certificates that use it. For more information, refer to Certificate chain.
Prerequisites
- A zone in Edge DNS that holds the domain of the hostname. To create a zone, refer to Edge DNS guides and tutorials.
- The challenge value that the ACME client provides for the TXT record.
- Access to Azion Console. For more information, refer to How to access Azion Console.
Add the TXT record to the zone
With the DNS-01 challenge, Let’s Encrypt confirms control of the domain through a TXT record in its DNS zone. The record carries the name and the value that the ACME client gives you.
To add the record in Azion Console:
Access Azion Console > Edge DNS.
Select the zone that holds the domain of the hostname.
In Name, enter _acme-challenge. For a hostname below the domain, enter _acme-challenge.<subdomain>, such as _acme-challenge.www.
The name is relative to the zone, so the Console adds the domain for you. When the ACME client gives the full name, enter only the part before the domain. A name typed with the domain carries the domain twice, and Let’s Encrypt never finds the record. For the length and characters a name accepts, refer to Zones and records.
In Record Type, select TXT.
In Value, enter the challenge value that the ACME client provides.
In TTL (seconds), enter how long a resolver can cache the response, in seconds. The field accepts 0 to 604800.
Select Save.
A name that nobody queried before it existed answers within seconds. A name queried before the record exists is answered NXDOMAIN for up to one hour, so save the record before the ACME client validates. For more information, refer to How it works. Let’s Encrypt reads the record when it validates the certificate request.