Automating certificate renewal with DNS validation

June 21, 2026

HTTP validation needs port 80 reachable from the outside. The day a firewall rule changes, renewals quietly start failing and the certificate expires weeks later.

DNS validation only needs API access to the zone, so it keeps working whatever happens to the web ports. Pair it with a deploy hook that copies the new files into place, fixes permissions and reloads only the services that use them.

acme.sh --issue --dns dns_provider -d host.example.com
acme.sh --install-cert -d host.example.com \
  --fullchain-file /etc/ssl/host/fullchain.crt \
  --key-file /etc/ssl/host/cert.key \
  --reloadcmd "/usr/local/bin/deploy-cert.sh"

Finally, check the expiry date from a monitoring job rather than trusting the renewal cron.

Back to all notes