<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — iRedMail EE -- Enhancement Request ACME DNS-01]]></title>
	<link rel="self" href="https://forum.iredmail.org/feed-atom-topic21184.xml" />
	<updated>2026-07-21T14:56:52Z</updated>
	<generator>PunBB</generator>
	<id>https://forum.iredmail.org/topic21184-iredmail-ee-enhancement-request-acme-dns01.html</id>
		<entry>
			<title type="html"><![CDATA[Re: iRedMail EE -- Enhancement Request ACME DNS-01]]></title>
			<link rel="alternate" href="https://forum.iredmail.org/post92121.html#p92121" />
			<content type="html"><![CDATA[<div class="quotebox"><cite>ZhangHuangbin wrote:</cite><blockquote><p>Hi,</p><p>Sorry we have no plan for this SHORTLY. <img src="https://forum.iredmail.org/img/smilies/sad.png" width="15" height="15" alt="sad" /></p></blockquote></div><br /><p>that is ok, we can wait for it to come out</p><p>what would also be nice is signature and email disclaimer management per domain as well</p><p>along with MTA-STS, TLS-RPT and DANE management</p><p>we are developers as well, we could assist with some of this if interested</p>]]></content>
			<author>
				<name><![CDATA[subarticThrone]]></name>
				<uri>https://forum.iredmail.org/user144938.html</uri>
			</author>
			<updated>2026-07-21T14:56:52Z</updated>
			<id>https://forum.iredmail.org/post92121.html#p92121</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: iRedMail EE -- Enhancement Request ACME DNS-01]]></title>
			<link rel="alternate" href="https://forum.iredmail.org/post92120.html#p92120" />
			<content type="html"><![CDATA[<p>Hi,</p><p>Sorry we have no plan for this SHORTLY. <img src="https://forum.iredmail.org/img/smilies/sad.png" width="15" height="15" alt="sad" /></p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>https://forum.iredmail.org/user2.html</uri>
			</author>
			<updated>2026-07-21T14:28:58Z</updated>
			<id>https://forum.iredmail.org/post92120.html#p92120</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[iRedMail EE -- Enhancement Request ACME DNS-01]]></title>
			<link rel="alternate" href="https://forum.iredmail.org/post92119.html#p92119" />
			<content type="html"><![CDATA[<p>==== REQUIRED BASIC INFO OF YOUR IREDMAIL SERVER ====<br />- iRedMail version (check /etc/iredmail-release): 2026071501&nbsp; &nbsp;EE v1.8.1<br />- Deployed with iRedMail Easy or the downloadable installer?<br />- Linux/BSD distribution name and version: Ubuntu 22.04.05<br />- Store mail accounts in which backend (LDAP/MySQL/PGSQL): MariaDB 1.7.2<br />- Web server (Apache or Nginx): NGINX<br />- Manage mail accounts with iRedAdmin-Pro? EE<br />- [IMPORTANT] Related original log or error message is required if you&#039;re experiencing an issue.<br />====<br />Huangbin,</p><p>iRedMail Enterprise Edition currently provides a convenient SSL Certificate interface that allows administrators to add multiple server and web hostnames, issue a Let’s Encrypt certificate, and have iRedMail manage deployment and renewal automatically.</p><p>Are there plans for adding support for ACME DNS-01 validation as an alternative to the current IP/web based validation (HTTP-01) method?</p><p>A possible implementation could include:</p><p>Selection of the ACME challenge method:<br />&nbsp; &gt;&gt; HTTP-01<br />&nbsp; &gt;&gt; DNS-01</p><p>Initial DNS provider support for Cloudflare / GoDaddy</p><p>Secure storage of a restricted Cloudflare / GoDaddy API token</p><p>DNS zone and credential validation before certificate issuance<br />Continued automatic certificate installation and renewal through the existing Enterprise Edition workflow</p><p>Support for wildcard names, such as *.domain.tld</p><p>A provider or hook interface that could later support additional DNS services</p><p>The current Enterprise Edition certificate management works well. DNS-01 support would extend that functionality for environments where:</p><p>&nbsp; &gt;&gt; Port 80 is unavailable or intentionally restricted<br />&nbsp; &gt;&gt; A hostname cannot point directly to the mail server during validation<br />&nbsp; &gt;&gt; Wildcard certificates are required<br />&nbsp; &gt;&gt; Multiple DNS zones are managed centrally<br />&nbsp; &gt;&gt; Administrators want certificate validation to remain independent of web path</p><p>Ideally, the Enterprise Edition would remain responsible for the complete certificate lifecycle, including issuance, renewal, installation, service reloads, status reporting, and expiration warnings. This would avoid competing external ACME clients or administrator written deployment scripts modifying certificates managed by iRedMail.</p><p>For Cloudflare, the integration could use a restricted API token limited to DNS record editing and zone access for the selected zones.</p><p>Would be great if considered <img src="https://forum.iredmail.org/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></content>
			<author>
				<name><![CDATA[subarticThrone]]></name>
				<uri>https://forum.iredmail.org/user144938.html</uri>
			</author>
			<updated>2026-07-21T14:03:58Z</updated>
			<id>https://forum.iredmail.org/post92119.html#p92119</id>
		</entry>
</feed>
