• [^] # Re: regarder comme ca se passe

    Posté par . En réponse au message Génération certificats avec bind9 via RFC2136. Évalué à 1.

    le challenge DNS qui est ce que tu recherches j'imagine, consiste à mettre un enregistrement DNS particulier (TXT il me semble) qui t'es demandé par le client ACME

    Exactement, par contre dans mon cas c'est certbot qui fait la demande.

    Dans le log certbot, il y a ceci.

    certbot_dns_rfc2136._internal.dns_rfc2136:No authoritative SOA record found for _acme-challenge.subdomain.mondomain.fr
    certbot_dns_rfc2136._internal.dns_rfc2136:No authoritative SOA record found for subdomain.mondomain.fr
    certbot_dns_rfc2136._internal.dns_rfc2136:Received authoritative SOA response for mondomain.fr
    

    Je pense que certbot peut ajouter les entrées TXT qui vont bien mais n'es pas autorisé par bind9.