burnley
Regular Pleskian
Lately we have had a lot of clients and their technical providers that have started using the Plesk REST API to implement DNS based validation for SSL certificate automation projects. At present they can generate an API Key at the client level which is locked down via IP.
The issue is many have asked how to restrict the key so its only usable for a specific domain or sub-domain in their account as they need to provide access for a 3rd party to validate certificates on externally managed infrastructure. Several have also pointed out the key grants all client level permissions. There seems to be no way to limit a KEY to DNS only related commands or even more tightly ones related specifically to verification records for SSL certificates.
So far the only solution seems to be to use an external provider such as Cloudflare. Is this something Plesk is looking at addressing in a future release or did I overlook something in the REST API. Has anyone else found a good solution using Plesk?
The issue is many have asked how to restrict the key so its only usable for a specific domain or sub-domain in their account as they need to provide access for a 3rd party to validate certificates on externally managed infrastructure. Several have also pointed out the key grants all client level permissions. There seems to be no way to limit a KEY to DNS only related commands or even more tightly ones related specifically to verification records for SSL certificates.
So far the only solution seems to be to use an external provider such as Cloudflare. Is this something Plesk is looking at addressing in a future release or did I overlook something in the REST API. Has anyone else found a good solution using Plesk?