Which ACME Challenge Type Should I Use? HTTP-01 or DNS-01?

Which ACME Challenge Type Should I Use? HTTP-01 or DNS-01?

Andrew Johnson

Every SSL Certificate issued through the Automatic Certificate Management Environment (ACME) protocol needs proof that you control the domain. That proof comes from a validation challenge, and the two you will use most often are HTTP-01 and DNS-01. Learn About The Validation Procedure 🔗

Both reach the same result in different ways. The right one depends on how your servers are reached and what you need to cover, rather than on any difference in security between them.

Understanding HTTP-01 ACME Challenges

The HTTP-01 challenge proves control by serving a file. Your ACME client places a token at a fixed path on your web server, under /.well-known/acme-challenge/, and the Certificate Authority (CA) fetches it over Hypertext Transfer Protocol (HTTP) to confirm you control the domain.

It is the simplest method to set up when you have direct access to the web server and its document root, and validation is quick, because the check is a single request. The catch is reach : the Certificate Authority (CA) connects on port 80, so the server has to be reachable from the public internet.

HTTP-01 also cannot cover a wildcard. A single file sits on one server and cannot prove control of a whole class of subdomains, so a wildcard SSL Certificate rules this method out.

Exploring DNS-01 ACME Challenges

The DNS-01 challenge proves control through the Domain Name System (DNS) rather than the web server. Your ACME client publishes a temporary TXT record under your domain, and the Certificate Authority (CA) reads that record to confirm control.

Because the check happens in the Domain Name System (DNS), it works no matter how the target server is exposed. It suits load balancers, cloud services, and internal hosts that a public connection would never reach, and it is the only method that can issue a wildcard SSL Certificate.

The one thing to plan for is propagation. A change to a Domain Name System (DNS) record can take from a few minutes to a few hours to become visible, so DNS-01 can be slower to complete than HTTP-01.

Choosing Between Challenge Types

The decision usually comes down to how your servers are reached and what you need to cover.

For a single site on a standard web server with port 80 open, HTTP-01 is the quickest route and needs no Domain Name System (DNS) changes. For a wildcard, a server behind a firewall, or a host with no public web server, DNS-01 is the method that works.

At scale, DNS-01 is often easier to manage. Handling validation through the Domain Name System (DNS) gives you one place to control it, rather than a file on every server, and that consistency matters more as reissues grow more frequent.

The DNS-01 method also frees the ACME client from the servers that use the SSL Certificate. A single client on a separate machine can complete validation and pass each SSL Certificate to the servers that need it, which helps where those servers cannot validate on their own. Learn About Running Your Client Anywhere 🔗

Practical Security Considerations

Neither challenge is more secure than the other, but each asks you to protect something different.

With HTTP-01, the challenge path on your web server is reachable for a short time, so keep the server patched and limit what else is open on port 80. With DNS-01, your client needs permission to change records, so treat those credentials, whether an Application Programming Interface (API) key or an account login, as carefully as any other secret.

Whichever you choose, test a reissue from time to time rather than assuming it works. A quick check that a scheduled reissue completes catches problems long before an SSL Certificate is due to expire. Both work with a Trustico® Certificate as a Service (CaaS) license, whichever suits your setup. Learn About Supported ACME Clients 🔗

Back to Blog

Most Popular Questions

Frequently asked questions covering the HTTP-01 and DNS-01 ACME challenge types, which method suits a Wildcard SSL Certificate, Domain Name System (DNS) propagation delays, load balancer scenarios, and the security considerations for each method

HTTP-01 Compared With DNS-01 Challenges

HTTP-01 places a token file in your web server's /.well-known/acme-challenge/ directory, while DNS-01 adds a TXT record in your domain's Domain Name System (DNS). HTTP-01 is faster but needs port 80 open, while DNS-01 works regardless of server accessibility and can issue a Wildcard SSL Certificate.

Wildcard SSL Certificate Validation Requirements

A Wildcard SSL Certificate can be validated only through DNS-01. It proves control through the Domain Name System (DNS), the only method that can cover a whole class of subdomains, so HTTP-01 cannot be used for a wildcard.

DNS-01 Propagation Delays

DNS-01 can be slower because of Domain Name System (DNS) propagation. A change to a Domain Name System (DNS) record can take from a few minutes to a few hours to become visible, which extends validation compared with the faster HTTP-01 method.

HTTP-01 With Load Balancers

HTTP-01 can be awkward behind a load balancer, because the Certificate Authority (CA) must reach the exact challenge file on the right server. DNS-01 is usually the better choice for load balancers, cloud services, and internal networks, since it validates through the Domain Name System (DNS) instead.

Protecting Each Challenge Method

With HTTP-01, the challenge path on your web server is public for a short time, so keep the server patched and limit what else is open on port 80. With DNS-01, protect the credentials that let your client change records, whether an Application Programming Interface (API) key or an account login.

DNS-01 Within Larger Deployments

For teams managing many domains, DNS-01 is often easier to run at scale, because validation is handled through the Domain Name System (DNS) in one place rather than a file on every server. That consistency matters more as reissues grow more frequent.

Stay Updated - Our RSS Feed

There's never a reason to miss a post! Subscribe to our Atom/RSS feed and get instant notifications when we publish new articles about SSL Certificates, security updates, and news. Use your favorite RSS reader or news aggregator.

Subscribe via RSS/Atom