Let's Encrypt DNS-PERSIST-01 Support
Good day
We would like to request if at all possible, that Let's Encrypt DNS-PERSIST-01 support be considered in the development roadmap.
TS Plus Remote Access app already supports Let’s Encrypt HTTP-01, however the problem in this case is that we need to allow HTTP/S ports from any source on the internet as there is no Let’s Encrypt IP range and source IPs are dynamic.
This creates a security concern as it bypasses perimeter access lists which is common practice considering this is a terminal application.
We could get around this normally by installing a publicly signed certificate, however the validation dates for this type of cert is expected to shorten to 47 days by 2029 (currently at 200 days now). This is to force automated certificate generation and management.
The Let's Encrypt DNS-PERSIST-01 service would rely on a single DNS record that does not need to change during the lifecycle of the renewal and is catered for scenarios where admins do not which to leave ports 80 & 443 open to the world just for the cert renewal process.
Your consideration here is appreciated and I am sure this would help with everyone who uses your product as well as yourselves as this would enable your customers to further secure your product.
Thanks,
Alick

Log in to comment and vote
Comments2
Eléana Pace
Apr 16
Hi Alick,
Thank you for your suggestion. We will study the feasibility of this feature. Which steps would you like us to automate in this procedure?
We will also consider TLS-ALPN-01 that seems more adapted to our automated procedure. Could this work for you?
alickm
Apr 20
Hi Eléana
Thanks for getting back to me.
Regarding TLS-ALPN-01, unfortunately this won’t work as this seems to be related to a reverse proxy workflows where port 80 isn’t available, but still has the flaw where we need to have open ports in a secure environment.
Regarding automation and if I understand your question correctly, your application would just need to support the new DNS verification method that relies on a single static DNS record and I would imagine that Let’s Encrypt would supply their own documentation for how this could be leveraged.
In saying that, this method is still being developed by Let’s Encrypt and they expect to have this in production in Q2 this year so hoping you could match the development pipeline on your side.
More information can be found in the below link:
https://letsencrypt.org/2026/02/18/dns-persist-01
Thanks,
Alick