• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Resolved Let's encrypt - auto-renew with external primary DNS server?

vic666

New Pleskian
All the domains hosted on my Plesk server are managed through an external DNS server. As far as I understand, this setup is not compatible with automatically renewing certificates from Let's Encrypt because the Plesk server needs direct access to the DNS records. So, for this to work, Plesk needs to be the primary name server. Is that correct?

If yes, is there a way to easily transfer the existing DNS records over to Plesk without me having to type each record manually?
 
All the domains hosted on my Plesk server are managed through an external DNS server. As far as I understand, this setup is not compatible with automatically renewing certificates from Let's Encrypt because the Plesk server needs direct access to the DNS records. So, for this to work, Plesk needs to be the primary name server
All of our DNS is managed on external DNS servers too. Assuming you have configured both your Plesk & your external DNS properly, using external DNS servers is compatible with automatically renewing certificates from Let's Encrypt. Having said that, If they are *Wildcard certificates from Let's Encrypt, then you'll need to renew those manually. They will not autorenew, because of the DNS entry that is required for certificate verification purposes at each renewal. (Edit)
Is that correct?
See above, hence no, that is not correct.
If yes, is there a way to easily transfer the existing DNS records over to Plesk without me having to type each record manually?
See above again, but this is not needed.
 
Last edited:
Hi l_c, thanks for your reply.

Clearly, what you propose, works, thank you for that. When I worked with the wildcard domain, I had to manipulate my DNS records and add a TXT record (_acme-challenge.example.com). This does not seem to be the case when I just secure the domain itself and the www subdomain, I'm not being asked to change anything in DNS. Can you confirm this is what you meant?

I'm just a bit confused with your statement that "two DNS entries are required for cert verification purposes". Which two entries are you referring to? It seems to me that it's just the one TXT record I mentioned.
 
When I worked with the wildcard domain, I had to manipulate my DNS records and add a TXT record (_acme-challenge.example.com). This does not seem to be the case when I just secure the domain itself and the www subdomain, I'm not being asked to change anything in DNS. Can you confirm this is what you meant?
Yes that is eaxctly what was meant :)
....It seems to me that it's just the one TXT record I mentioned.
With only one domain on the *wildcard certificate, yes you're correct. It's only one TXT record for verification purposes.
If there is more than one domain and/or more levels of sub-domains say, the number of TXT records for verification purposes increases.
Sorry. Can see now that that wasn't made clear enough in the original post, so have corrected that for any future readers of this thread.
 
Back
Top