Blain Smith @blainsmith@fosstodon.org · activity timestamp last week DNS-PERSIST-01: A New Model for DNS-based Challenge Validationhttps://letsencrypt.org/2026/02/18/dns-persist-01.html #DNS #TLS #ACME #LetsEncrypt Read more Read less Translate Translate DNS-PERSIST-01: A New Model for DNS-based Challenge Validation When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges. For subscribers who need wildcard certificates or who prefer not to expose infrastructure to the public Internet, the DNS-01 challenge type has long been the only choice. DNS-01 works well. It is widely supported and battle-tested, but it comes with operational costs: DNS propagation delays, recurring DNS updates at renewal time, and automation that often requires distributing DNS credentials throughout your infrastructure. Reply Boost or quote Boost Quote You cannot quote this post Like More actions Copy link Flag this post Block