When you request a certificate from Let’s Encrypt, our servers validate that you control the hostnames in that certificate using ACME challenges. For subscribers who need wildcard certificates or who prefer not to expose infrastructure to the public Internet,…
DNS-Persist-01: A New Model for DNS-Based Challenge Validation
Let's Encrypt's DNS-based challenge validation process may expose infrastructure to potential attacks, affecting wildcard certificate subscribers.