Certbot authorization allows your own server to obtain a Let's Encrypt SSL certificate via DNS validation (DNS-01 challenge), including a wildcard certificate (*.yourdomain.ch). Certbot automatically creates the TXT record _acme-challenge in your SwissCenter DNS zone and removes it once the certificate is issued.
This feature is useful when the certificate needs to be installed on your own server (dedicated server, VPS, NAS, network equipment) or when you require a wildcard certificate. For websites hosted with us, no action is required: Let's Encrypt certificates are issued and renewed automatically.
Prerequisites
- The domain uses SwissCenter's DNS servers (its zone is managed in your console).
- A server under your control with Certbot and its extension
certbot-dns-rfc2136 (package python3-certbot-dns-rfc2136 on Debian and Ubuntu, or pip install certbot-dns-rfc2136).
- The public IP address from which this server connects to the Internet.
Enable the authorization
- Log in to your hosting management console.
- Access the relevant domain by clicking its name, then open the DNS manager.
- Click on Tools, then on Certbot authorization.
- In IP restriction, enter the public IP address of your server (for example
203.0.113.10), or a network in CIDR format (for example 203.0.113.0/24). IPv6 is accepted.
- Set the Status to Active and save.
The window then displays two elements to copy:
- Certbot configuration file: four lines (
dns_rfc2136_server, dns_rfc2136_name, dns_rfc2136_secret, dns_rfc2136_algorithm);
- Command line: the ready-to-use Certbot command for your domain.
Obtain the Certificate on Your Server
- Copy the content of the configuration file into
/etc/certbot.conf and protect it:
chmod 600 /etc/certbot.conf
- Run the command displayed in the console:
certbot certonly --dns-rfc2136 --dns-rfc2136-credentials /etc/certbot.conf -d yourdomain.ch
- For a wildcard certificate, add the star name (the quotes prevent the shell from interpreting the star):
certbot certonly --dns-rfc2136 --dns-rfc2136-credentials /etc/certbot.conf -d yourdomain.ch -d "*.yourdomain.ch"
By default, Certbot waits 60 seconds for the record to be published before requesting validation. If validation fails, increase this delay with --dns-rfc2136-propagation-seconds 120.
Renewal then happens automatically via the scheduled task installed by Certbot (certbot renew), as long as the authorization remains active.
Security: Read Before Enabling
- The key grants permission to modify the entire DNS zone of the domain, not just the validation record. Treat it like a password: do not share it, do not publish it in a code repository, and keep the file in
chmod 600.
- Always restrict the IP address. The default proposed value,
0.0.0.0/0, allows access from the entire Internet: replace it with your server's address. The key remains the primary protection; the IP restriction is a second barrier.
- The key is specific to each domain. To block updates, set the Status to Inactive: they are immediately refused. Note: reactivating it restores the same key. If you believe your key has been compromised, keep the authorization inactive and open a support ticket to obtain a new one.
Troubleshooting
- "REFUSED" or "NOTAUTH": Your server's IP address does not match the entered restriction, or the authorization is inactive. Check your server's actual public IP address (for example on https://mon-ip.info/).
- "Unable to determine base domain": The domain does not use SwissCenter's DNS servers, or the name passed to
-d does not match the configured domain.
- Validation times out: Increase
--dns-rfc2136-propagation-seconds.
If the problem persists, open a support ticket indicating the domain, the command run, and the full error message (without the secret key).