SSL Cert issued via TXT record instead of CNAME or allowing to install our own SSL Bundles
aliavali
Would it be possible to utilize a txt record instead of cname? I use domain forwarders for my subdomains, but doing so with PorkBun requires SSL on root and wildcard ; but this conflicts with beacons' need for root domain cname.
Otherwise I have to manually remove one validation to revalidate another every 3 months.
PorkBun utilizes TXT records via Lets Encrypt, from my understanding for domain validation you can have multiple TXT records for both Lets Encrypt and Google Trust Services. This should let both PorkBun and Beacons coexist without causing me to manually juggle every 3 months.
Beacons creates a wildcard record for SSL.
Porkbun also creates a wildcard record for SSL.
Both which conflict because you both demand a CNAME record.
Two options either both use txt, or you accept a certificate bundle.
Accepting the certificate bundle allows for Porkbun to continue hosting SSL and auto renews for you so you don't conflict at all. While allowing all your services to work within the avali.live domain and subdomain spaces.
I reached out about this via email support, Jacky Z. suggested I submit this as a feedback/feature request.
Hopefully this copy/paste from my support email helps. Been here since the beginning and want to continue supporting Beacons <3
Jacob Choi-Durham
Hi aliavali — thanks for taking the time to write this up (and for sticking with us). Totally hear you on how painful it is to have to juggle SSL validation every few months when Porkbun and Beacons are both trying to manage wildcard/root records. This context is super helpful; I’m going to share it with the team so we can look into whether supporting TXT-based validation and/or allowing you to install your own certificate bundle is something we can accommodate, and we’ll follow up once we have next steps.