Which ACME Challenge Type Should I Use? HTTP-01 or DNS-01?
Andrew JohnsonShare
Every SSL Certificate issued through the Automatic Certificate Management Environment (ACME) protocol needs proof that you control the domain. That proof comes from a validation challenge, and the two you will use most often are HTTP-01 and DNS-01. Learn About The Validation Procedure 🔗
Both reach the same result in different ways. The right one depends on how your servers are reached and what you need to cover, rather than on any difference in security between them.
Understanding HTTP-01 ACME Challenges
The HTTP-01 challenge proves control by serving a file. Your ACME client places a token at a fixed path on your web server, under /.well-known/acme-challenge/, and the Certificate Authority (CA) fetches it over Hypertext Transfer Protocol (HTTP) to confirm you control the domain.
It is the simplest method to set up when you have direct access to the web server and its document root, and validation is quick, because the check is a single request. The catch is reach : the Certificate Authority (CA) connects on port 80, so the server has to be reachable from the public internet.
HTTP-01 also cannot cover a wildcard. A single file sits on one server and cannot prove control of a whole class of subdomains, so a wildcard SSL Certificate rules this method out.
Exploring DNS-01 ACME Challenges
The DNS-01 challenge proves control through the Domain Name System (DNS) rather than the web server. Your ACME client publishes a temporary TXT record under your domain, and the Certificate Authority (CA) reads that record to confirm control.
Because the check happens in the Domain Name System (DNS), it works no matter how the target server is exposed. It suits load balancers, cloud services, and internal hosts that a public connection would never reach, and it is the only method that can issue a wildcard SSL Certificate.
The one thing to plan for is propagation. A change to a Domain Name System (DNS) record can take from a few minutes to a few hours to become visible, so DNS-01 can be slower to complete than HTTP-01.
Choosing Between Challenge Types
The decision usually comes down to how your servers are reached and what you need to cover.
For a single site on a standard web server with port 80 open, HTTP-01 is the quickest route and needs no Domain Name System (DNS) changes. For a wildcard, a server behind a firewall, or a host with no public web server, DNS-01 is the method that works.
At scale, DNS-01 is often easier to manage. Handling validation through the Domain Name System (DNS) gives you one place to control it, rather than a file on every server, and that consistency matters more as reissues grow more frequent.
The DNS-01 method also frees the ACME client from the servers that use the SSL Certificate. A single client on a separate machine can complete validation and pass each SSL Certificate to the servers that need it, which helps where those servers cannot validate on their own. Learn About Running Your Client Anywhere 🔗
Practical Security Considerations
Neither challenge is more secure than the other, but each asks you to protect something different.
With HTTP-01, the challenge path on your web server is reachable for a short time, so keep the server patched and limit what else is open on port 80. With DNS-01, your client needs permission to change records, so treat those credentials, whether an Application Programming Interface (API) key or an account login, as carefully as any other secret.
Whichever you choose, test a reissue from time to time rather than assuming it works. A quick check that a scheduled reissue completes catches problems long before an SSL Certificate is due to expire. Both work with a Trustico® Certificate as a Service (CaaS) license, whichever suits your setup. Learn About Supported ACME Clients 🔗