Update CHANGELOG.md - #20
Merged
Merged
Conversation
The framework's ResolveDomainValidator matches configured provider domain patterns (e.g. *.zone.com) against the certificate/zone name, not the _acme-challenge record name. Resolving on the raw resolved record name broke the non-delegated path because the _acme-challenge prefix fails the one-level wildcard match. Resolve the validator on the cert domain when no CNAME delegation exists, and on the resolved terminal target when it does, so both the direct and cross-zone delegated cases select the correct provider.
Fix validator resolution regression for non-delegated challenges
Add a CNAME Delegation section to docsource/configuration.md describing why challenge names are delegated to an isolated validation zone, how the CnameResolver follows a multi-level CNAME chain to its terminus, how the DNS provider plugin is selected against the resolved target (enabling cross-provider delegation), the loop/depth safety guards, and private-zone resolution via DnsVerificationServer. Update the enrollment flow summary to include the CNAME resolution step.
Cname delegation dnsplugins
DNS providers are now standalone, pluggable plugins deployed alongside the AnyCA Gateway rather than built into this ACME plugin. Remove the hardcoded "supported DNS providers" lists, per-provider credential/config tables, RFC 2136 setup, and the obsolete IDnsProvider/DnsProviderFactory "adding new providers" guidance. Point instead to the Keyfactor -dnsplugin repositories query as the authoritative source, and document that providers are configured via the Gateway's Domain Validation config and resolved per domain (including CNAME-delegated targets).
Cname delegation dnsplugins
DNS providers are now separate plugins, so the ACME plugin no longer needs their SDKs or per-provider config fields. Drop the AWS, Azure, ARSoft (RFC2136), and Nager.PublicSuffix package references (all unused in code) and remove the DnsProvider selector plus every per-provider config entry from the integration manifest. Keep the ACME-level fields, AccountStoragePath (still used for account storage), and DnsVerificationServer (used for propagation checks and CNAME resolution). DnsClient is retained for CNAME delegation and TXT propagation.
Cname delegation dnsplugins
Cname delegation dnsplugins
indrora
added a commit
that referenced
this pull request
Jul 30, 2026
* saas fixes * Update generated docs * fixed CAID length issue * .net 10 build * updated git ignore * dns updates * Changes to support DNS * dns changes * dns fixes * added propigation wait * Removed Inline DNS Providers * Moved DNS Resolving away from initialize * extended propigation delay * removed unneeded initialize * dns troubleshooting * aws and azure plugin removal * removed all internal dns provider code references and pointed to the plugins * fixed dns public validation * CARequestId Fix * Add FlowLogger-based step tracing and enrollment hardening Ports the FlowLogger pattern from Keyfactor/barracuda-wafasaas-orchestrator and adapts it for an IAnyCAPlugin. The accumulated step breadcrumb is appended to EnrollmentResult.StatusMessage on both success and failure, so operators see a scannable per-step summary in the Command UI instead of just a single exception message. Changes: - FlowLogger.cs: ported verbatim from barracuda with namespace changed to Keyfactor.Extensions.CAPlugin.Acme. Added StepAsync<T> overload for async methods that return a value. - Enroll: wraps each stage (ValidateInput, FormatCsr, LoadConfig, CreateHttpClient, InitAcmeAccount, CreateAcmeClient, DecodeCsr, ExtractDomainsFromCsr, CreateOrder, ExtractOrderIdentifier, FinalizeOrder, DownloadCertificate, EncodeCertificateToPem) as a timed flow.Step. Success returns include flow.GetSummary(); failure paths include DescribeException(ex) + flow.GetSummary(). - ProcessAuthorizations: takes the flow and records per-domain work in three branches (StageDnsRecords / VerifyAndSubmit / CleanupDnsRecords), so the breadcrumb shows which specific domain failed when a challenge breaks. - DescribeException helper: unwraps AggregateException/TargetInvocation wrappers, surfaces HttpRequestException context, and truncates overlong messages so the summary stays readable. - Initialize: added ValidateConfigForEnrollment — fails fast (at save time, not first enroll) on missing DirectoryUrl/Email, non-absolute or non-http(s) DirectoryUrl, mismatched EAB key pair, or negative DnsPropagationDelaySeconds. Build: net6.0 / net8.0 / net10.0 — 0 errors, pre-existing warnings only. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs: make Let's Encrypt certificate instructions generic (#15) Removed specific root/intermediate names (ISRG Root X1, R3) that go stale when Let's Encrypt rotates their chain. Users are now directed to the official Let's Encrypt certificates page to identify the currently active root and intermediate certificates. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fixed bad references * Update keyfactor-bootstrap-workflow.yml * Update keyfactor-bootstrap-workflow.yml * docs: auto-generate README and documentation [skip ci] * Add multi-level CNAME delegation support for DNS-01 challenges Resolve the ACME challenge record name through any chain of CNAME delegations to its terminal target before staging validation. The resolved name now drives DNS provider plugin selection, record creation, propagation verification, and cleanup, so challenges delegated into a zone on a different provider are routed to the plugin that owns that zone. Non-delegated domains are unaffected. * Update CHANGELOG.md * Update CHANGELOG.md (#20) * Update CHANGELOG.md * Fix validator resolution regression for non-delegated challenges The framework's ResolveDomainValidator matches configured provider domain patterns (e.g. *.zone.com) against the certificate/zone name, not the _acme-challenge record name. Resolving on the raw resolved record name broke the non-delegated path because the _acme-challenge prefix fails the one-level wildcard match. Resolve the validator on the cert domain when no CNAME delegation exists, and on the resolved terminal target when it does, so both the direct and cross-zone delegated cases select the correct provider. * docs: document CNAME delegation (proxy) lookup Add a CNAME Delegation section to docsource/configuration.md describing why challenge names are delegated to an isolated validation zone, how the CnameResolver follows a multi-level CNAME chain to its terminus, how the DNS provider plugin is selected against the resolved target (enabling cross-provider delegation), the loop/depth safety guards, and private-zone resolution via DnsVerificationServer. Update the enrollment flow summary to include the CNAME resolution step. * docs: auto-generate README and documentation [skip ci] * docs: replace bundled DNS provider lists with pluggable model DNS providers are now standalone, pluggable plugins deployed alongside the AnyCA Gateway rather than built into this ACME plugin. Remove the hardcoded "supported DNS providers" lists, per-provider credential/config tables, RFC 2136 setup, and the obsolete IDnsProvider/DnsProviderFactory "adding new providers" guidance. Point instead to the Keyfactor -dnsplugin repositories query as the authoritative source, and document that providers are configured via the Gateway's Domain Validation config and resolved per domain (including CNAME-delegated targets). * docs: auto-generate README and documentation [skip ci] * Remove externalized DNS provider config and unused SDK dependencies DNS providers are now separate plugins, so the ACME plugin no longer needs their SDKs or per-provider config fields. Drop the AWS, Azure, ARSoft (RFC2136), and Nager.PublicSuffix package references (all unused in code) and remove the DnsProvider selector plus every per-provider config entry from the integration manifest. Keep the ACME-level fields, AccountStoragePath (still used for account storage), and DnsVerificationServer (used for propagation checks and CNAME resolution). DnsClient is retained for CNAME delegation and TXT propagation. * docs: auto-generate README and documentation [skip ci] * Set gateway framework compatibility to 26.2 * docs: auto-generate README and documentation [skip ci] * Update AcmeCaPlugin.csproj * docs: auto-generate README and documentation [skip ci] --------- Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> * Update integration-manifest.json (#27) --------- Co-authored-by: Brian Hill <bhill@keyfactor.com> Co-authored-by: Keyfactor <keyfactor@keyfactor.github.io> Co-authored-by: Brian Hill <76450501+bhillkeyfactor@users.noreply.github.com> Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.