mirror of
https://codeberg.org/Codeberg/Documentation.git
synced 2026-08-15 14:53:29 -07:00
Update CAA recommendation (#822)
Caddy will first try against staging, so this also requires a CAA record. Reviewed-on: https://codeberg.org/Codeberg/Documentation/pulls/822
This commit is contained in:
parent
05b677d374
commit
a76b575339
1 changed files with 4 additions and 2 deletions
|
|
@ -25,8 +25,10 @@ and configure it to serve content from Codeberg Pages.
|
|||
{% admonition "warning" "Known pitfalls for failed certificate errors" %}
|
||||
|
||||
If you have a [CAA record](https://en.wikipedia.org/wiki/DNS_Certification_Authority_Authorization#Record) configured,
|
||||
you must [explicitly allow Let's Encrypt in your CAA record](https://letsencrypt.org/docs/caa/).
|
||||
The value of the CAA record would look like `letsencrypt.org;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/292520050;validationmethods=tls-alpn-01,http-01`.
|
||||
you must [explicitly allow Let's Encrypt (staging) in your CAA record](https://letsencrypt.org/docs/caa/).
|
||||
This means you need to add two extra CAA records.
|
||||
The first record has a value of `letsencrypt.org;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/292520050;validationmethods=tls-alpn-01,http-01`.
|
||||
The second record has a value of `letsencrypt.org;accounturi=https://acme-staging-v02.api.letsencrypt.org/acme/acct/272029763;validationmethods=tls-alpn-01,http-01`.
|
||||
|
||||
If you're using [DNSSec](https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions) on your custom domain, you might run into TLS certificate issues because `codeberg.page` doesn't use DNSSec at the moment.
|
||||
In this case you must add `A` / `AAAA` / `TXT` records for all domains instead of `CNAME` records. You can use [this tool](https://dnssec-analyzer.verisignlabs.com) to verify your setup.
|
||||
|
|
|
|||
Loading…
Reference in a new issue