Skip to content

Update CHANGELOG.md - #20

Merged
indrora merged 17 commits into
release-2.0from
dnsplugins
Jul 30, 2026
Merged

Update CHANGELOG.md#20
indrora merged 17 commits into
release-2.0from
dnsplugins

Conversation

@bhillkeyfactor

Copy link
Copy Markdown
Collaborator

No description provided.

bhillkeyfactor and others added 17 commits July 7, 2026 13:21
The framework's ResolveDomainValidator matches configured provider
domain patterns (e.g. *.zone.com) against the certificate/zone name,
not the _acme-challenge record name. Resolving on the raw resolved
record name broke the non-delegated path because the _acme-challenge
prefix fails the one-level wildcard match.

Resolve the validator on the cert domain when no CNAME delegation
exists, and on the resolved terminal target when it does, so both the
direct and cross-zone delegated cases select the correct provider.
Fix validator resolution regression for non-delegated challenges
Add a CNAME Delegation section to docsource/configuration.md describing
why challenge names are delegated to an isolated validation zone, how the
CnameResolver follows a multi-level CNAME chain to its terminus, how the
DNS provider plugin is selected against the resolved target (enabling
cross-provider delegation), the loop/depth safety guards, and private-zone
resolution via DnsVerificationServer. Update the enrollment flow summary
to include the CNAME resolution step.
DNS providers are now standalone, pluggable plugins deployed alongside
the AnyCA Gateway rather than built into this ACME plugin. Remove the
hardcoded "supported DNS providers" lists, per-provider credential/config
tables, RFC 2136 setup, and the obsolete IDnsProvider/DnsProviderFactory
"adding new providers" guidance. Point instead to the Keyfactor
-dnsplugin repositories query as the authoritative source, and document
that providers are configured via the Gateway's Domain Validation
config and resolved per domain (including CNAME-delegated targets).
DNS providers are now separate plugins, so the ACME plugin no longer
needs their SDKs or per-provider config fields. Drop the AWS, Azure,
ARSoft (RFC2136), and Nager.PublicSuffix package references (all unused
in code) and remove the DnsProvider selector plus every per-provider
config entry from the integration manifest. Keep the ACME-level fields,
AccountStoragePath (still used for account storage), and
DnsVerificationServer (used for propagation checks and CNAME resolution).
DnsClient is retained for CNAME delegation and TXT propagation.
@indrora
indrora merged commit e906a47 into release-2.0 Jul 30, 2026
1 check passed
indrora added a commit that referenced this pull request Jul 30, 2026
* saas fixes

* Update generated docs

* fixed CAID length issue

* .net 10 build

* updated git ignore

* dns updates

* Changes to support DNS

* dns changes

* dns fixes

* added propigation wait

* Removed Inline DNS Providers

* Moved DNS Resolving away from initialize

* extended propigation delay

* removed unneeded initialize

* dns troubleshooting

* aws and azure plugin removal

* removed all internal dns provider code references and pointed to the plugins

* fixed dns public validation

* CARequestId Fix

* Add FlowLogger-based step tracing and enrollment hardening

Ports the FlowLogger pattern from Keyfactor/barracuda-wafasaas-orchestrator
and adapts it for an IAnyCAPlugin. The accumulated step breadcrumb is
appended to EnrollmentResult.StatusMessage on both success and failure,
so operators see a scannable per-step summary in the Command UI instead
of just a single exception message.

Changes:
- FlowLogger.cs: ported verbatim from barracuda with namespace changed
  to Keyfactor.Extensions.CAPlugin.Acme. Added StepAsync<T> overload
  for async methods that return a value.
- Enroll: wraps each stage (ValidateInput, FormatCsr, LoadConfig,
  CreateHttpClient, InitAcmeAccount, CreateAcmeClient, DecodeCsr,
  ExtractDomainsFromCsr, CreateOrder, ExtractOrderIdentifier,
  FinalizeOrder, DownloadCertificate, EncodeCertificateToPem) as a
  timed flow.Step. Success returns include flow.GetSummary(); failure
  paths include DescribeException(ex) + flow.GetSummary().
- ProcessAuthorizations: takes the flow and records per-domain work in
  three branches (StageDnsRecords / VerifyAndSubmit / CleanupDnsRecords),
  so the breadcrumb shows which specific domain failed when a challenge
  breaks.
- DescribeException helper: unwraps AggregateException/TargetInvocation
  wrappers, surfaces HttpRequestException context, and truncates
  overlong messages so the summary stays readable.
- Initialize: added ValidateConfigForEnrollment — fails fast (at save
  time, not first enroll) on missing DirectoryUrl/Email, non-absolute
  or non-http(s) DirectoryUrl, mismatched EAB key pair, or negative
  DnsPropagationDelaySeconds.

Build: net6.0 / net8.0 / net10.0 — 0 errors, pre-existing warnings only.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs: make Let's Encrypt certificate instructions generic (#15)

Removed specific root/intermediate names (ISRG Root X1, R3) that go stale
when Let's Encrypt rotates their chain. Users are now directed to the
official Let's Encrypt certificates page to identify the currently active
root and intermediate certificates.

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fixed bad references

* Update keyfactor-bootstrap-workflow.yml

* Update keyfactor-bootstrap-workflow.yml

* docs: auto-generate README and documentation [skip ci]

* Add multi-level CNAME delegation support for DNS-01 challenges

Resolve the ACME challenge record name through any chain of CNAME
delegations to its terminal target before staging validation. The
resolved name now drives DNS provider plugin selection, record
creation, propagation verification, and cleanup, so challenges
delegated into a zone on a different provider are routed to the
plugin that owns that zone. Non-delegated domains are unaffected.

* Update CHANGELOG.md

* Update CHANGELOG.md (#20)

* Update CHANGELOG.md

* Fix validator resolution regression for non-delegated challenges

The framework's ResolveDomainValidator matches configured provider
domain patterns (e.g. *.zone.com) against the certificate/zone name,
not the _acme-challenge record name. Resolving on the raw resolved
record name broke the non-delegated path because the _acme-challenge
prefix fails the one-level wildcard match.

Resolve the validator on the cert domain when no CNAME delegation
exists, and on the resolved terminal target when it does, so both the
direct and cross-zone delegated cases select the correct provider.

* docs: document CNAME delegation (proxy) lookup

Add a CNAME Delegation section to docsource/configuration.md describing
why challenge names are delegated to an isolated validation zone, how the
CnameResolver follows a multi-level CNAME chain to its terminus, how the
DNS provider plugin is selected against the resolved target (enabling
cross-provider delegation), the loop/depth safety guards, and private-zone
resolution via DnsVerificationServer. Update the enrollment flow summary
to include the CNAME resolution step.

* docs: auto-generate README and documentation [skip ci]

* docs: replace bundled DNS provider lists with pluggable model

DNS providers are now standalone, pluggable plugins deployed alongside
the AnyCA Gateway rather than built into this ACME plugin. Remove the
hardcoded "supported DNS providers" lists, per-provider credential/config
tables, RFC 2136 setup, and the obsolete IDnsProvider/DnsProviderFactory
"adding new providers" guidance. Point instead to the Keyfactor
-dnsplugin repositories query as the authoritative source, and document
that providers are configured via the Gateway's Domain Validation
config and resolved per domain (including CNAME-delegated targets).

* docs: auto-generate README and documentation [skip ci]

* Remove externalized DNS provider config and unused SDK dependencies

DNS providers are now separate plugins, so the ACME plugin no longer
needs their SDKs or per-provider config fields. Drop the AWS, Azure,
ARSoft (RFC2136), and Nager.PublicSuffix package references (all unused
in code) and remove the DnsProvider selector plus every per-provider
config entry from the integration manifest. Keep the ACME-level fields,
AccountStoragePath (still used for account storage), and
DnsVerificationServer (used for propagation checks and CNAME resolution).
DnsClient is retained for CNAME delegation and TXT propagation.

* docs: auto-generate README and documentation [skip ci]

* Set gateway framework compatibility to 26.2

* docs: auto-generate README and documentation [skip ci]

* Update AcmeCaPlugin.csproj

* docs: auto-generate README and documentation [skip ci]

---------

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* Update integration-manifest.json (#27)

---------

Co-authored-by: Brian Hill <bhill@keyfactor.com>
Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io>
Co-authored-by: Brian Hill <76450501+bhillkeyfactor@users.noreply.github.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants