Your idea of just randomly blocking access from certain IP address ranges doesn’t really provide you with any security at all. If you’re worried about rusaian hackers or whatever, most people exploiting anything have access to botnets with whatever bespoke IP address ranges they need to bypass those sort of rules.
In anti fraud we see this commonly, people using stolen details will happily get better matches with GEOIP than the legitimate users of the credentials. Blocking specific countries IP allocations is just providing a false sense security on your part.
Like? For what price?
> Blocking specific countries IP allocations is just providing a false sense security on your part.
No, it's a preventative measure. Just like changing SSH to a non-standard port reduces pointless attempts.
If you own example.com, you can delegate to dnsauth.example.com for $0 (or simply the price of a Internet-facing machine that has DNS open).
Say you want a cert for www.example.com. LE will check for ownership by looking up _acme-challenge.www.example.com. Instead of having a TXT record with the nonce, _acme-challenge.www is actually a CNAME pointing to _acme-challenge.www.dnsauth--where the TXT nonce lives.
The DNS daemon that is authoritative for dnsauth can be the traditional BIND, or other software:
* https://github.com/joohoi/acme-dns
This is often called 'DNS alias' mode:
* https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mo...
* https://www.eff.org/deeplinks/2018/02/technical-deep-dive-se...
This isn't some special "Let's Encrypt DNS forwarding mode" that DNS providers have to explicitly support. It's simply part of "how DNS works".
And which of those also have an API that is supported by Certbot?
I would really like names where a setup like this has been tested and works.
Certbot allows for hook scripts, and you can use a utility that can talk multiple APIs:
* https://github.com/AnalogJ/lexicon
> I would really like names where a setup like this has been tested and works.
The guy who runs BSDCan and PgCon uses it for his personal stuff as well as FreshPorts.org, etc:
* https://dan.langille.org/2017/05/31/creating-a-txt-only-nsup...
* https://dan.langille.org/2019/02/01/acme-domain-alias-mode/
He used acme.sh, though I'm more partial to dehydrated:
* https://github.com/dehydrated-io/dehydrated/wiki/example-dns...
We use it at work, but I don't want to dox myself. :)
And as I stated in the very first sentence, it is self-serve:
> If you own example.com, you can delegate to dnsauth.example.com for $0 (or simply the price of a Internet-facing machine that has DNS open).
We do this at work: our main registrar does not have a restricted API, so we have a sub-domain that lives on a DNS server in our DMZ. Internal ACME clients update the desired TXT records when asking LE for a cert.
The cost is the price for keeping a VM running and updated, which for us is minimal since it is on our private cloud.
Every layer of security makes attacks that much more costly.
Run your own DNS server and get a registrar lock. If that is not feasible, and consultants are too expensive, I would look into the more expensive dns providers that provide custom interface that fit the threat model of your system. If that is also too expensive then I would take a second look at the risk analysis and recalculate the cost of each risk.
I'm always a little surprised when there are short comings in IAM like that with route53 and records. It seems like a natural thing to be able to control, but for some reason you don't have resource level controls on hosted zones. It's all or nothing.
There is no way to create a token allowing access only to _acme-challenge record.
Let's Encrypt is obeying normal DNS mechanics, so when they ask for a TXT record for _acme-challenge.cat-photos.example.com and get a CNAME as a response, they'll ask for the TXT record for the name in the CNAME answer instead. If that's cat-photos.cert-issuer.example.com then a token valid only for the sub-domain cert-issuer.example.com can write that TXT record.
You sort out the CNAME once, probably when creating cat-photos.example.com or setting it up to get a certificate, and then afterwards the API token is enough for automation.