@Lemmchen Are you verifying yourself that with the firewall up the DNS records get updated? Are you running any of your own DNS servers?
Check both whois and dig $domain ns.
If your firewall isn't affecting _any_ of your domain's nameservers _and_ you've checked while a letsencrypt verification is in progress that the DNS record has been created and is publicly fetchable, then I'm stumped.
@Lemmchen Then the acme verification is hitting your provider's DNS servers (or rather, one of the DNS servers listed as authoritative with your registrar) and the verifier never needs to hit your infrastructure directly.
Unless you're hosting your own DNS and for some reason want to apply a blocklist to that.
@Lemmchen The letsencrypt acme server IP addresses aren't published and rotate frequently to prevent mitm attacks near the source. Placing them on an allowlist is not the solution you're looking for.
@Lemmchen Are you verifying yourself that with the firewall up the DNS records get updated? Are you running any of your own DNS servers?
Check both
whoisanddig $domain ns.If your firewall isn't affecting _any_ of your domain's nameservers _and_ you've checked while a letsencrypt verification is in progress that the DNS record has been created and is publicly fetchable, then I'm stumped.
What's the actual error you're getting?
@Lemmchen Then the acme verification is hitting your provider's DNS servers (or rather, one of the DNS servers listed as authoritative with your registrar) and the verifier never needs to hit your infrastructure directly.
Unless you're hosting your own DNS and for some reason want to apply a blocklist to that.
@Lemmchen Only open the port when you're expecting an acme verification. Or do DNS-based verification.
@Lemmchen The letsencrypt acme server IP addresses aren't published and rotate frequently to prevent mitm attacks near the source. Placing them on an allowlist is not the solution you're looking for.