[Pdns-users] Prevent external lookup of (private) subdomains

informant at trinaxab.se informant at trinaxab.se
Fri Jul 9 14:29:20 UTC 2021


Specifically, the intention is to use a single wildcard certificate *.intra.example.com rather than one for each subdomain. I don't know if that changes anything.

(also I'm new to this mailing list business)

July 9, 2021 4:03 PM, "Brian Candler" <b.candler at pobox.com (mailto:b.candler at pobox.com?to=%22Brian%20Candler%22%20<b.candler at pobox.com>)> wrote:
On 09/07/2021 14:43, informant--- via Pdns-users wrote:  I intend to set up a PowerDNS authoritative server and recursor, where a few subdomains will be forwarded to the auth server for internal use only. (local IP addresses) We do not wish to allow lookups for these domains by any external host. So far, so good.

Now, additionally, I would like to employ Let’s Encrypt certificates for these private services by using DNS wildcard challenge. This, of course, requires that the DNS server be public. My question, then, is can I set up PowerDNS in such a way that the DNS server allows the necessary lookups required to complete the DNS challenge, but prevents lookups for any subdomains by any external host?  

	You have a domain like "int.example.com" where you don't want any names to be visible to the outside world, but you want to be able to obtain certificates for them. Correct?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mailman.powerdns.com/pipermail/pdns-users/attachments/20210709/c18df3c2/attachment.htm>


More information about the Pdns-users mailing list