Commit Graph
3 Commits
  • dnsmint: honour DNSMint_Api instead of overwriting it
    The assignment was unconditional, so exporting DNSMint_Api did nothing - the
    plugin reset it to the default every time it was sourced. Every neighbouring
    plugin with an _Api variable treats it as an override; this one only looked
    like it did.
    
    Found while writing the dnsapi2 entry: the sentence documenting the override
    would have been false.
  • Add DNSMint DNS API
    DNSMint mints hostnames on domains it operates and serves from its own
    authoritative nameservers, so records are published through its API
    rather than a zone you run.
    
    An ACME challenge goes to the DNS-01 endpoint, which derives the hostname
    from the challenge name: no root zone to detect, no record id to track,
    and the value published is the value removed. Wildcards work because the
    API keeps the two newest values for a name.
    
    Any other TXT name is an ordinary record under a hostname and goes to the
    records endpoint instead, which is why the add and rm functions branch on
    the _acme-challenge label. Issuing certificates needs only the dns01:write
    scope; the record endpoint needs hostnames:read and hostnames:write.
    
    Tested against Let's Encrypt staging for a wildcard plus its apex, and
    the non-challenge TXT path against the live API.
  • Add DNSMint DNS API
    DNSMint mints hostnames on domains it operates and serves from its own
    authoritative nameservers, so a customer has no zone of their own and the
    challenge is published through its API.
    
    The hostname is derived server-side from the challenge name, so there is
    no root zone to detect and no record id to track: the value published is
    the value removed. Wildcards work because the API keeps the two newest
    values for a name, which is what the apex and wildcard pair needs.
    
    Tested against Let's Encrypt staging for a wildcard plus its apex.