Metadata-Version: 2.4
Name: certbot-dns-enum
Version: 0.1.0
Summary: enum DNS Authenticator plugin for Certbot
Author: enum
License-Expression: Apache-2.0
Project-URL: Homepage, https://github.com/enumco/certbot-dns-enum
Project-URL: Documentation, https://docs.enum.co/services/dns/
Classifier: Development Status :: 4 - Beta
Classifier: Environment :: Plugins
Classifier: Intended Audience :: System Administrators
Classifier: Operating System :: POSIX :: Linux
Classifier: Programming Language :: Python
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
Classifier: Programming Language :: Python :: 3.12
Classifier: Programming Language :: Python :: 3.13
Classifier: Programming Language :: Python :: 3.14
Classifier: Topic :: Internet :: WWW/HTTP
Classifier: Topic :: Security
Classifier: Topic :: System :: Installation/Setup
Classifier: Topic :: System :: Networking
Classifier: Topic :: System :: Systems Administration
Classifier: Topic :: Utilities
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: LICENSE
Requires-Dist: certbot>=3.0.0
Requires-Dist: requests>=2.20.0
Provides-Extra: test
Requires-Dist: pytest; extra == "test"
Dynamic: license-file

# certbot-dns-enum

[enum](https://enum.co) DNS Authenticator plugin for [Certbot](https://certbot.eff.org).

This plugin automates the process of completing a `dns-01` challenge by creating, and subsequently removing, TXT records using the enum API. It supports wildcard certificates.

## Installation

```sh
pip install certbot-dns-enum
```

## Credentials

The plugin uses the API key of an enum service account. Create a service account with an API key using [enumctl](https://docs.enum.co/cli/installation/):

```sh
enumctl service-accounts create certbot --key certbot --expires-in 1y
```

Store the API key and the ID of the project containing your DNS zone in a credentials file:

```ini
# enum API credentials used by Certbot
dns_enum_api_key = enum_sk_...
dns_enum_project_id = proj-...
```

The API key can manage all DNS zones in its project. Protect the file like a password, for example with `chmod 600`. Certbot warns if the file is readable by other users.

## Arguments

| Argument | Description |
|---|---|
| `--authenticator dns-enum` | Select the enum authenticator plugin (required) |
| `--dns-enum-credentials` | Path to the credentials INI file (required) |
| `--dns-enum-propagation-seconds` | Seconds to wait for DNS changes to propagate before asking the ACME server to verify the record (default: 30) |

## Examples

Certificate for `example.com`:

```sh
certbot certonly \
  --authenticator dns-enum \
  --dns-enum-credentials ~/.secrets/certbot/enum.ini \
  -d example.com
```

Wildcard certificate for `example.com` and `*.example.com`:

```sh
certbot certonly \
  --authenticator dns-enum \
  --dns-enum-credentials ~/.secrets/certbot/enum.ini \
  -d example.com \
  -d '*.example.com'
```
