ActivCERT

DNS provider configuration procedures

Common provider workflow

Store provider authentication values as GENERAL-SECRET credentials, create the provider, verify access, and inspect both the generic and provider-specific views. VERIFY checks provider access without publishing a challenge record.

VERIFY DCV-ROUTE53, VERIFY DCV-AZURE, and VERIFY DCV-DESEC submit asynchronous verification tasks. Add , WAIT to wait up to five minutes. SUCCESS means the verification completed; FAILED means the task failed, was aborted, requires operator action, could not be read, or reached the wait limit. A timeout leaves the task active. Every accepted submission reports a Task Handle; inspect it with INFO TASK <task-handle> or continue waiting with WAIT TASK <task-handle>, TIMEOUT <seconds>. Without WAIT, SUBMITTED confirms task acceptance; it does not confirm provider access.

Amazon Route 53

Create protected credentials for AWS authentication, then configure the hosted zone used for DNS challenges. Replace the hosted-zone placeholder and region with your approved values. Verify access and inspect the saved provider before using it with an issuer:

ADD CREDENTIAL route53-access, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL route53-secret, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL route53-token, TYPE GENERAL-SECRET, PROMPT
ADD DCV-ROUTE53 public-dns, ACCESS-KEY-ID route53-access, &
  SECRET-ACCESS-KEY route53-secret, SESSION-TOKEN route53-token, &
  REGION us-east-1, HOSTED-ZONE-ID <hosted-zone-id>, TTL 60
VERIFY DCV-ROUTE53 public-dns, WAIT
INFO DCV public-dns
INFO DCV-ROUTE53 public-dns, DETAIL

Omit SESSION-TOKEN and its credential only for AWS credentials that do not require a session token.

Microsoft Azure DNS

Configure an Azure DNS provider using an Entra service principal and the tenant, subscription, resource group, and zone that contain the challenge records. Store its client identifier and secret as credentials, then verify access and inspect the provider:

ADD CREDENTIAL azure-client-id, TYPE GENERAL-SECRET, PROMPT
ADD CREDENTIAL azure-client-secret, TYPE GENERAL-SECRET, PROMPT
ADD DCV-AZURE public-azure, CLIENT-ID azure-client-id, &
  CLIENT-SECRET azure-client-secret, TENANT-ID <tenant-id>, &
  SUBSCRIPTION-ID <subscription-id>, RESOURCE-GROUP <resource-group>, &
  ZONE <zone-name>, TTL 60
VERIFY DCV-AZURE public-azure, WAIT
INFO DCV public-azure
INFO DCV-AZURE public-azure, DETAIL

The Entra service principal requires DNS Zone Contributor access to the selected DNS zone.

deSEC

Store the deSEC API token as a protected credential and select the zone in which ActivCERT will publish DNS challenges. The example then verifies access and displays the generic and provider-specific configuration:

ADD CREDENTIAL desec-token, TYPE GENERAL-SECRET, PROMPT
ADD DCV-DESEC public-desec, API-TOKEN desec-token, &
  ZONE <zone-name>, TTL 900
VERIFY DCV-DESEC public-desec, WAIT
INFO DCV public-desec
INFO DCV-DESEC public-desec, DETAIL

Use the TTL and propagation values required by the selected deSEC zone.