Letsencrypt Supports Wildcard Certificates
letsencrypt.org
letsencrypt.org
https://community.letsencrypt.org/t/acme-v2-and-wildcard-cer...
https://letsencrypt.org/docs/ct-logs/
Apparently wildcards have been supported since 2018, but I only discovered this last weekend.
Cheers.
Most (?) hosting providers these days probably provide for automated renewal of individual domains, but wildcard certificates are a different matter, especially if your domains are hosted/registered externally and you're not using your hosting providers DNS servers.
If you're lucky and your hosting provider is using e.g. Plesk as a hosting panel and has enabled its built-in DNS server, you might be able to use that as a (hidden) primary server and your registrar's DNS as secondaries and let Plesk update the DNS records as required.
Otherwise you're left with the problem on how to interface between your hosting providers renewal mechanism and your DNS provider's API (hopefully your DNS provider does have an API?), which means you either need to manually update your certificates after all, or else run your own webserver so you can custom-wire the required DNS updates (and running my own webserver isn't a hobby I currently wish to take up).
Yet when it's, say, a certificate for the HomeAssistant service at my personal residence, avoiding the subdomain being published to the transparency log is advantageous from a both a privacy and security perspective.
Naturally, best practices depend on the use-case and context.
https://www.eff.org/deeplinks/2018/02/technical-deep-dive-se...
I thought you just created the TXT record once (manually if need be) and it didn't change when the cert is renewed?
https://letsencrypt.org/docs/challenge-types/
> it only makes sense to use DNS-01 challenges if your DNS provider has an API you can use to automate updates.
I have a domain set up where every subdomain not otherwise specified gives a CNAME to one of the subdomains. (gandi lets me do it, don't know if it's standard) Certbot could easily serve the response to any challenge issued to <random number>.example.com as many times as it takes to be sure.
I created NS records on example.com to delegate all of home.example.com to a wholly different DNS provider. That provider then manages (all of) that zone, but nothing more (important records such as MX remain on example.com).
It's crazy to think that not too long ago, these certificates would cost a small fortune. I'm really grateful to anyone working on making this available for the world to use.