Let’s Encrypt with Cert Warden
-
Administration
- 30 Days Money Back
- Automatic payments
- Cancel a contract
- Change address data
- Change contact person (company)
- Change password
- Display bills
- Emergency support costs
- FAQ infrastructure and security
- Fewer Invoices
- Invoice by mail
- Manage Contacts
- Monthly consolidated invoice
- Partner administration
- Password Forgotten
- Payment methods
- Payment slip
- Product Transfer
- Recruiting friends
- Reminder
- Server Data Centre
- Setting up two-factor authentication
- Storage Overview for Resellers
- Top up credit
- Unlock Express
- Webmail Link
- weitere Artikel ( 21 ) Einklappen
-
Cloud Storage
- Add as network drive
- Create cloud storage user
- first steps
- Login Cloud Memory
- mount under Linux
- PC backup to the cloud
- weitere Artikel ( 1 ) Einklappen
-
DNS Service
- Change DNS entries
- Change SPF entry
- DNS API
- DNS API Powershell example
- DNS Entries in the DNS Package
- DNSSEC Deactivate
- DynDNS with a MikroTik router
- Let's Encrypt with Cert Warden
- Questions about DNS Service
- Set up your own SPF server
- SPF entry
- TLD's that support DNSsec
- weitere Artikel ( 7 ) Einklappen
-
Domain
- .ZUERICH DOMAINS Register
- Activate Whois Privacy
- Cancel domain
- Change contacts
- Change DNS entries
- Change DNS Server
- Check DNSSEC
- Configure domain for mail traffic
- Connect website to Squarespace
- Connect website with Wix
- Connect your website to Jimdo
- Deactivate DNS Records
- Difference in domain redirect
- DNSSEC
- DNSSEC Deactivate
- Domainreseller
- Enable Domain Access
- Enable domain forwarding
- Extend domain
- Google Optimization
- Google search optimization
- Google SiteVerification
- Link domain
- Own Nameserver
- Proper DNS records
- Questions about the domain
- Restore a domain
- Restriction forwarding
- Search engine registrationa
- Set up your own SPF server
- Transfer domain
- Use an external domain
- What is DANE/TLSA?
- What is MagicDANE?
- weitere Artikel ( 29 ) Einklappen
-
E-Mail
-
- Email does not reach me and the sender did not receive an error message
- Error "Client host rejected: cannot find your hostname"
- Gmail is blocking mails
- I get an error message when I send an email.
- I'm on a blacklist
- MacMail Problem: Required mailbox name to create ImapMailbox for (null)
- Proper DNS records
- Request emergency service
- weitere Artikel ( 3 ) Einklappen
-
- keine Artikel vorhanden
-
- keine Artikel vorhanden
-
- Change email password
- Create email address
- Create Email Forwarding
- Difference mailbox types
- DNSSEC
- Email Ports for IMAP, POP3, SMTP
- Emails using external provider
- Emails using external provider
- Exchange Konto übertragen
- Message "mailbox for user is full"
- Send e-mails
- Transfer Email
- Webmail Link
- What is DKIM?
- weitere Artikel ( 9 ) Einklappen
-
- keine Artikel vorhanden
- Are our e-mails encrypted?
- Automatic e-mail reply
- Backup emails locally
- Change password
- Customize e-mail addresses in the Microsoft Portal
- E-Mail Signature
- E-Mail-Transfer Outlook (PST-File)
- external name servers
- Gmail is blocking mails
- Important SPF entries
- JUNK Mail in Outlook
- Mail Log
- Newsletter Server important questions
- Office365 Logout and Setup
- OfficeMail Account Settings
- Report SPAM Mails
- Restriction forwarding
- Send e-mails
- Send email as attachment
- Set up email alias
- Setting up an email account in Thunderbird
- SPF entry
- Using OfficeMail
- Webmail Link
- Webmail Login does not work
- What is DANE/TLSA?
- What is DKIM?
- What is MagicDANE?
- weitere Artikel ( 23 ) Einklappen
-
-
Einrichtung
-
Server
-
-
- Add module PGSQL in PHP
- Change IP at Confixx
- Confixx 3.1 End User Manual
- Confixx 3.1 Special Edition Manual for Administrators
- Confixx Server DBD::mysql or other PERL module displays error message
- Release Confixx database
- Setting up Apache server compression in Debian
- Setting up Apache server compression in SuSE
- Swap Confixx license
- weitere Artikel ( 4 ) Einklappen
-
- Add PHP version to chrooted
- Apache2 does not start
- Automatic detection with Plesk Server (Linux)
- Create customer in reseller hosting
- Install Node.JS version
- LINUX: Apache Crash at log rotation at UBUNTU
- LINUX: MySQL Upgrade von 5.5 auf 5.6 mit Ubuntu
- Linux: Restart Network Interface
- Linux: Too many open files in Ubuntu
- List storage space from Reseller
- Plesk can't start PHP-fpm
- Plesk DNS Manager Extension
- Plesk ELS
- Plesk Linux: Enable NGINX and HTTP/2
- Plesk Log Files
- PostgreSQL Update
- Repairing databases
- Special character problems
- Upgrade MSSQL Server
- Use PHP version
- weitere Artikel ( 15 ) Einklappen
- Allow Support Team Access
- Backup setup
- Convert Ubuntu MBR to GPT
- Empty directory quickly
- Empty Mailq
- Enlarge partition at Ubuntu 16.04
- How do I log in via SSH?
- Monitoring of RAID controllers
- MySQL with Docker
- Optimize your server
- Plesk ELS
- Proxmox installation problem: Fix Black Screen
- Questions about the root servers
- Reinstallation
- Remove Ubuntu old kernels
- Repair Mysql / MariaDB databases
- repair quota
- Resetting Windows password
- restore very old website
- Server does not boot
- Set up Mysql replication server
- Set up Remote Desktop licence
- Setting up Jitl
- SNF filter does not start
- Start NGINX manually
- Websites sporadically unavailable
- Windows Server 2019 Change language
- WordPress installieren
- weitere Artikel ( 23 ) Einklappen
-
-
-
ShopDesigner
-
- 1.00 The most important questions about ShopDesigner
- 1.01 Set up your online shop
- 1.02 Add products to your online shop
- 1.05 Product categories and keywords
- 1.06 Inventory and Inventory Tracking
- 1.07 Shipping options
- 1.08 Tax rates
- 1.09 Importing products from a CSV file
- 1.10 product variants
- 1.11 AGB for your OnlineShop
- 1.13 Set currency
- 1.16 OnlineShop Analysis
- Add Google Calendar
- Booking and calendar tool for SiteDesigner
- SiteDesigner Backup
- weitere Artikel ( 10 ) Einklappen
-
-
SiteDesigner
-
- 01 Adding and moving content
- 02 Colors and fonts
- 03 Website designs
- 04 Use a stock image
- 05 change an image
- 06 Add page
- 07 Set up a store
- 09 Site analytics
- 1.01 SiteDesigner Quickstart
- 1.02 Add basic page information
- 1.03 Change the appearance of your page
- 1.04 Pictures, Galleries and Presentations
- 1.05 Text and headings
- 1.09 Hide incomplete pages
- 1.10 Forms, cards and other content
- 1.11 Setting Language, Currency and Units
- 1.14 Re-sort and rearrange pages
- 1.15 SiteDesigner Mobile and mobile phone quick start
- 1.16 SiteDesigner Tablet Quickstart
- 1.17 How does the Template Editor work?
- 1.20 Undo changes
- 1.22 Setting up a user-defined contact form
- 10 Setup a blog
- 12 Multiple language sites
- 15 Contact forms
- Add Google Analytics
- Add Google Calendar
- add more pages to SiteDesigner
- Add number of pages to my page
- Add type of content to my website
- Advantage of SiteDesigner
- Create a link to any page
- Definition SiteDesigner
- Edit Site Template CSS
- Edit SiteDesigner with HTML code
- Embed external website
- Export page from SiteDesigner and send it to another server via FTP
- good page ranking?
- pay by phone with credit card
- Request Backup
- Request emergency service
- SiteDesigner Move Package
- Take website offline
- Webhosting to the SiteDesigner?
- weitere Artikel ( 39 ) Einklappen
- 01 Adding and moving content
- 02 Colors and fonts
- 03 Website designs
- 04 Use a stock image
- 05 change an image
- 06 Add page
- 09 Site analytics
- 10 Setup a blog
- 12 Multiple language sites
- 15 Contact forms
- Add a Popup
- Change language
- Fixed menu in the SiteDesigner
- PopUp hinzufügen
- SiteDesigner access
- weitere Artikel ( 10 ) Einklappen
-
SMS Gateway
-
SSL Certificates
- Activate SSL certificate
- Activate SSL certificate for forwarding
- Browser is not supported
- Certification Requirement (CSR)
- Conditions to be fulfilled
- Creating a Certification Requirement (CSR) for Apache
- Definition SSL CERTIFICATE
- Difference Domain and Identity Certification
- Intermediate certificate
- Let's Encrypt does not work
- Requirements for issuing an SSL Certificate
- SiteSeal
- SSL in Java Keystore
- the right certificate
- Wildcard certificate
- weitere Artikel ( 10 ) Einklappen
-
Technical
-
- add a new node to the cluster
- Add LVM-Thin
- Cache Settings
- CloudInit set up
- Import Windows
- Important Proxmox commands
- Installation frozen
- LVM Rename
- Migration shows no progress
- Nested Virtualisation
- No Login Prompt on a VM
- Optimise performance
- Proxmox shutdown
- Proxmox with Highpoint does not boot
- Proxmox with question Mark
- Reinstalling Proxmox-Server in Cluster
- Remove Proxmox VM Disk
- Repair Proxmox Cluster
- Replace ZFS disk
- Run Proxmox with NVME RAID
- Run Proxmox with NVME RAID
- VM hangs: Booting from Harddisk
- weitere Artikel ( 17 ) Einklappen
-
-
Webhosting
-
-
- Bugfix: Wordpress does not work anymore
- Copy WordPress
- Customizing the domain of a Wordpress website
- Increase PHP timeout
- Increase WordPress file upload limit
- Installing Wordpress
- load-scripts.php 500 Internal server error
- Permalinks in Wordpress (Windows)
- Rename URL
- Switch off Wordpress maintenance mode
- Transfer Wordpress Website
- WordPress - Login button is not displayed
- Wordpress DSGVO Tools (GDPR) hacked
- Wordpress DSGVO Tools (GDPR) hacked
- Wordpress login doesn't work, password reset doesn't work either
- xml-rpc.php Forbidden
- weitere Artikel ( 11 ) Einklappen
-
- Adding email accounts
- Change email password
- Difference mailbox types
- Emails using external provider
- Emails using external provider
- I receive SPAM via my contact form
- Report SPAM Mails
- Set up e-mail
- Settings for Domains
- Spamfilter MagicSpam
- Spamfilter Plesk
- Transfer Email
- weitere Artikel ( 7 ) Einklappen
- Activate SSL certificate
- add another user
- Address book in Thunderbird
- Advantages of a website
- Backup Manager: restore your data yourself
- Blocking access for certain countries
- Browser Error Codes
- Change PHP version in Plesk
- Database user password change
- Disable Website Cache
- Enable Directory Listing
- external access to database server
- How to create a custom error page
- Log in to Plesk
- Moving Hosting Package
- NodeJS Setup
- PHP disabled functions
- PHP.ini configuration
- Planning tasks
- Plesk Backup Manager
- Protect Website
- Request Backup
- restore very old website
- Ruby einrichten
- Transfer Website
- weitere Artikel ( 20 ) Einklappen
-
-
Website-Builder
Let’s Encrypt with Cert Warden
Let’s Encrypt with Cert Warden (DNS-01 challenge)
Cert Warden is a self hosted certificate manager that orders and renews Let’s Encrypt certificates and distributes them to your servers. With the two scripts below, Cert Warden performs the validation through our DNS API, that is through the DNS-01 challenge. This works without an open port 80, for systems that cannot be reached from the internet at all, and for wildcard certificates such as *.yourdomain.ch.
Requirements
- The domain must point to our nameservers, so the DNS zone is hosted at FireStorm
- API access enabled in the customer area (
admin.firestorm.ch=> Account => Customer profile) - A running Cert Warden installation, usually as a Docker container
curlmust be available inside the container.jqis used when present, but is not required
1. Create an API key
Log in to the customer area and open Account => Customer profile.
Tick API access and click MANAGE API KEYS.
Create a new key:
- Label: for example
certwarden - Domains: select the domains concerned
- Also allow full DNS management: tick this box
Write down the API key. It is shown only once.
2. Install the scripts
Place both scripts on the persistent storage of your Cert Warden container, for example under /app/data/scripts/:
curl -o /app/data/scripts/firestorm_dns01_challenge_add.sh https://api.firestorm.ch/downloads/firestorm_dns01_challenge_add.txt curl -o /app/data/scripts/firestorm_dns01_challenge_del.sh https://api.firestorm.ch/downloads/firestorm_dns01_challenge_del.txt chmod 755 /app/data/scripts/firestorm_dns01_challenge_add.sh /app/data/scripts/firestorm_dns01_challenge_del.sh
If you download the files on a Windows machine, make sure they are saved with Unix line endings. Otherwise the container reports bad interpreter when the script starts.
3. Create the challenge provider in Cert Warden
Open the Providers section in Cert Warden and create a New Challenge Provider.
| Field | Value |
|---|---|
| Provider Type | DNS-01 Manual Script |
| Domains | Your domain, for example yourdomain.ch |
| Post Provision Wait | 300 |
| Environment Variables | FIRESTORM_API_KEY=YOUR-API-KEY |
| Path to DNS Record Create Script | /app/data/scripts/firestorm_dns01_challenge_add.sh |
| Path to DNS Record Delete Script | /app/data/scripts/firestorm_dns01_challenge_del.sh |
Save with SUBMIT. You can then order a certificate. Cert Warden sets the TXT record on its own and clears it away again after the validation.
Further settings
The scripts are controlled through environment variables. Only the API key is required, everything else is optional:
| Variable | Meaning |
|---|---|
FIRESTORM_API_KEY |
Your API key. The only mandatory entry |
FIRESTORM_ZONE_ID |
Fixed zone ID. If left empty, the script looks up the matching zone itself through the zone list. With a zone restricted key that may not see the zone list, enter the ID here |
FIRESTORM_TTL |
Lifetime of the TXT record, default 60 |
FIRESTORM_TIMEOUT |
Timeout for the API call in seconds, default 180 |
FIRESTORM_DEBUG |
1 writes requests and answers to the log, the key stays masked |
This call returns the zone ID:
curl -H "X-Api-Key: YOUR-API-KEY" https://api.firestorm.ch/dns/v1/zones
Testing by hand
Both scripts can be called directly, also from other ACME clients. A dry run changes nothing and only shows what would be sent:
FIRESTORM_API_KEY=YOUR-API-KEY ./firestorm_dns01_challenge_add.sh --dry-run "_acme-challenge.test.yourdomain.ch" "testvalue"
Without --dry-run the record is really set and removed again:
FIRESTORM_API_KEY=YOUR-API-KEY ./firestorm_dns01_challenge_add.sh "_acme-challenge.test.yourdomain.ch" "testvalue" FIRESTORM_API_KEY=YOUR-API-KEY ./firestorm_dns01_challenge_del.sh "_acme-challenge.test.yourdomain.ch" "testvalue"
With --help the scripts print their full description.
Troubleshooting
Creating the record takes one to two minutes
That is intended. For challenge records our API waits until all of our nameservers know the value, and only then answers. So the script is not stuck, it is waiting.
«Authentication failed»
Check the API key and whether API access is enabled in the customer profile. After several failed attempts our protection blocks the IP address temporarily.
«Access denied»
The key is restricted to certain domains and the requested zone is not among them, or full DNS management was not allowed when the key was created.
«No matching zone found»
The domain does not exist as a zone in your account, or the key is not allowed to see it. In that case set FIRESTORM_ZONE_ID explicitly.
«bad interpreter» when the script starts
The file has Windows line endings. Save it with Unix line endings, or run sed -i 's/\r$//' firestorm_dns01_challenge_add.sh inside the container.
Validation fails although the record is set
Increase the value of Post Provision Wait in Cert Warden.
Further instructions on our interface can be found in the article DNS API. The scripts were kindly provided to us by one of our customers.




