mirror of
https://github.com/certbot/certbot.git
synced 2026-04-29 02:02:00 -04:00
Certificats Let's Encrypt
These are from certbot/certbot#4174 Add more documentation, and help for NoCredentialsError. Allow multiple DNS records to be provisioned at once and waited for together. Fix doc strings to use "Certbot" instead of "Let's Encrypt." Set TTL to 0. Create a single boto3 session rather than one per API call. Use pagination in Route53 API in case there are many domains. Add a maximum wait time for update to propagate (10 minutes). |
||
|---|---|---|
| certbot_route53 | ||
| .gitignore | ||
| LICENSE | ||
| LICENSE.txt | ||
| MANIFEST.in | ||
| README.md | ||
| sample-aws-policy.json | ||
| setup.cfg | ||
| setup.py | ||
Route53 plugin for Let's Encrypt client
Before you start
It's expected that the root hosted zone for the domain in question already exists in your account.
Setup
-
Create a virtual environment
-
Make sure you have libssl-dev (or your regional equivalent) installed.
pycparsersuffers from https://github.com/eliben/pycparser/issues/148, which is why we need to recompile it, which depends onlibssl-dev. -
Install by adding these to your requirements.txt file:
--no-binary pycparser
-e git+https://github.com/certbot/certbot.git#egg=certbot
-e git+https://github.com/certbot/certbot.git#egg=acme&subdirectory=acme
certbot-route53
We need DNS01 support in certbot, which is only available in master for now.
How to use it
Make sure you have access to AWS's Route53 service, either through IAM roles or
via .aws/credentials.
To generate a certificate:
certbot certonly \
-n --agree-tos --email DEVOPS@COMPANY.COM \
-a certbot-route53:auth \
-d MY.DOMAIN.NAME