▲ | Arnavion 2 days ago | |
You can have multiple TXT records for the same domain identifier, and the ACME server will look through all of them to find the one that it expects. So for an order that requests SANs example.org and *.example.org, where the server asks for two authorizations to be completed for _acme-challenge.example.org, you can create both TXT records at the same time. https://datatracker.ietf.org/doc/html/rfc8555#section-8.4 >2. Query for TXT *records* for the validation domain name >3. Verify that the contents of *one of the TXT records* match the digest value (Emphasis mine.) |