Company
Date Published
Author
Shiloh Heurich
Word count
756
Language
English
Hacker News points
None

Summary

Fastly has introduced the dns-account-01 ACME challenge type within its Certification Authority, Certainly, to enhance security and performance for users managing multiple CAs in a multi-CDN setup. This development addresses the limitations of the traditional dns-01 challenge by eliminating the issue of _acme-challenge label collisions, which previously complicated automated certificate management across different platforms. The dns-account-01 challenge uses a unique identifier for each ACME account, allowing distinct validation paths for each provider and facilitating seamless certificate management. This innovation allows Fastly customers to enjoy improved reliability and flexibility in managing TLS certificates without operational overhead, offering a robust solution for multi-CDN environments. To implement this feature, customers must contact Fastly support to enable dns-account-01 for their accounts, which requires a one-time DNS configuration change.