# DNS-Zertifikat von Let's Encrypt über DynDNS bei deSEC (DNS-Challenge)

Im folgenden wird beschrieben, wie man mit Hilfe einer DynDNS bei deSEC ein DNS-Challenge hinbekommt, wnn der Domainanbieter dieses auf seinen DNS-Servern direkt nicht anbietet.

In meinem Fall ist der Anbieter "alldomains".

Der Inhalt wurde durch die KI von google generiert.

#### Schritt 1: Kostenlose deSEC-Subdomain &amp; Token erstellen

- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Öffnen Sie die Website **<span class="" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 600; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-inited="2" data-sfc-root="ep">[desec.io](https://desec.io/)</span>** und klicken Sie auf **Sign Up**.</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Registrieren Sie sich ganz einfach mit Ihrer **E-Mail-Adresse**. Sie erhalten einen Bestätigungs-Link.</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Nach dem Login erstellen Sie eine kostenlose Subdomain, die auf `.dedyn.io` endet (z. B. `thomass-itwiki-acme.dedyn.io`).</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Generieren Sie in den Einstellungen Ihres deSEC-Kontos einen **API-Token** (Geheimschlüssel) und kopieren Sie diesen.</span>

#### <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Schritt 2: Den CNAME-Eintrag bei alldomains setzen</span>

Jetzt verknüpfen wir Ihre Hauptdomain mit deSEC, damit Let's Encrypt weiß, wo es suchen muss.

- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Loggen Sie sich im Kundencenter von **alldomains.hosting** ein und öffnen Sie den DNS-/Zonen-Editor für Ihre Domain.</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Erstellen Sie einen neuen DNS-Eintrag mit diesen Werten:</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Typ:** `CNAME`</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Name / Host:** `_acme-challenge.iobroker`</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Wert / Ziel:** `thomass-itwiki-acme.dedyn.io.` *(Wichtig: Eventuell verlangt alldomains einen Punkt am Ende des Ziels)*</span>

#### <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Schritt 3: Zoraxy (Reverse Proxy) füttern</span>

- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Öffnen Sie **Zoraxy** -&gt; **TLS / SSL** -&gt; **ACME Tool**.</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Tragen Sie die Daten wie folgt ein:</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Domain(s):** Ihre echte Domain `iobroker.thomass-itwiki.de`</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Validation Method:** `DNS-01`</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**DNS Provider:** Wählen Sie **deSEC** aus der Liste aus.</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**API Token / Credentials:** Fügen Sie hier den **API-Token** aus Schritt 1 ein.</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Den Alias eintragen**:</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Suchen Sie das Feld **"Challenge Alias"** (manchmal auch *DNS Domain Alias Mode* oder *ACME DNS*).</span>
    - <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Tragen Sie dort Ihre deSEC-Adresse ein: `thomass-itwiki-acme.dedyn.io`</span>
- <span aria-owns="action-menu-parent-container" class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">Klicken Sie auf **Get Certificate**</span>

#### <span aria-owns="action-menu-parent-container" class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Weitere Subdomains in gleicher Weise hinzufügen:**</span>

<div class="n6owBd awi2gc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 12px 0px 16px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-hveid="CAAIAhAA" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-sie-k%C3%B6nnen-all-ihre-" jsaction="" jscontroller="TDBkbc#Ml18Xb" jsuid="BJKer_i">Sie können all Ihre weiteren Subdomains über genau dieselbe eine Adresse bei deSEC absichern. Sie müssen dafür **kein** neues deSEC-Konto erstellen und auch **keine** neue Subdomain bei deSEC anlegen.</div><div class="n6owBd awi2gc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 12px 0px 16px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-hveid="CAAIAxAA" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-die-einzige-adresse-" jsaction="" jscontroller="TDBkbc#Ml18Xb" jsuid="BJKer_r">Die einzige Adresse `thomass-itwiki-acme.dedyn.io` dient ab jetzt als universeller „Briefkasten“ für all Ihre Zertifikatsprüfungen.</div><div class="n6owBd awi2gc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 12px 0px 16px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-hveid="CAAIBBAA" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-alles%2C-was-sie-tun-m" jsaction="" jscontroller="TDBkbc#Ml18Xb" jsuid="BJKer_x">Alles, was Sie tun müssen, um eine neue Subdomain (zum Beispiel `nextcloud.thomass-itwiki.de`) hinzuzufügen, sind diese zwei Schritte:</div><div class="Fsg96" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 14px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-inited="2" data-sfc-root="ep" id="bkmrk-" jsaction="rcuQ6b:&BJKer_13|npT2md" jscontroller="KHhJQ#U8DOt" jsuid="BJKer_13"></div><div aria-level="3" class="otQkpb" data-animation-nesting="" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 20px; font-weight: 600; margin: 24px 0px 12px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-processed="true" data-sae="" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-schritt-1%3A-den-cname" jsaction="" jscontroller="a7qCn#ZxCkTb" jsuid="BJKer_14" role="heading">Schritt 1: Den CNAME-Eintrag bei alldomains erweitern</div><div class="n6owBd awi2gc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 12px 0px 16px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-hveid="CAAIBhAA" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-sie-m%C3%BCssen-bei-alldo" jsaction="" jscontroller="TDBkbc#Ml18Xb" jsuid="BJKer_19">Sie müssen bei alldomains für jede neue Subdomain einen eigenen CNAME-Eintrag anlegen. Das Prinzip ist immer dasselbe – der Name ändert sich, das Ziel bleibt exakt gleich.</div>- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Typ:** `CNAME`</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Name / Host:** `_acme-challenge.nextcloud` *(bzw. passend zu Ihrer neuen Subdomain)*</span>
- <span class="T286Pc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep">**Wert / Ziel:** `thomass-itwiki-acme.dedyn.io.` *(Wichtig: Eventuell wieder mit dem Punkt am Ende).*</span>

<div class="Fsg96" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 14px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-inited="2" data-sfc-root="ep" id="bkmrk--1" jsaction="rcuQ6b:&BJKer_1x|npT2md" jscontroller="KHhJQ#U8DOt" jsuid="BJKer_1x"></div><div aria-level="3" class="otQkpb" data-animation-nesting="" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 20px; font-weight: 600; margin: 24px 0px 12px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-processed="true" data-sae="" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-schritt-2%3A-in-zoraxy" jsaction="" jscontroller="a7qCn#ZxCkTb" jsuid="BJKer_1y" role="heading">Schritt 2: In Zoraxy das Zertifikat anfordern</div><div class="n6owBd awi2gc" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 16px; font-weight: 400; margin: 12px 0px 16px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-hveid="CAAICRAA" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-root="ep" id="bkmrk-gehen-sie-in-zoraxy-" jsaction="" jscontroller="TDBkbc#Ml18Xb" jsuid="BJKer_23">Gehen Sie in Zoraxy wieder in das **ACME Tool** und tragen Sie die Daten für die neue Subdomain ein.</div><div class="Fsg96" data-complete="true" data-copy-service-computed-style="font-family: "Google Sans", Arial, sans-serif; font-size: 14px; font-weight: 400; margin: 0px; text-decoration: none; border-bottom: 0px rgb(230, 232, 240);" data-processed="true" data-sfc-cb="" data-sfc-cp="" data-sfc-inited="2" data-sfc-root="ep" id="bkmrk--2" jsaction="rcuQ6b:&BJKer_1x|npT2md" jscontroller="KHhJQ#U8DOt" jsuid="BJKer_1x"></div>