Skip to content

Caddy seems to be open for arbitrary hostnames DNS challenges #4882

Answered by szaimen
Surfict asked this question in Questions
Discussion options

You must be logged in to vote

It seems that the way Caddy is currently configured "anyone across the internet can craft an SNI request for arbitrary hostnames on your server and prompt an ACME challenge from your Caddy instance. Upstream ACME providers will have rate limits to mitigate your server abusing theirs, but you may find yourself with cluttered logs and have your renewal attempts rejected later due to said rate limit abuse."

Yes, this is by design.

As I answered already in #4820, if you do not want such things to be logged anymore, I would recommend putting the aio interface behind a vpn and/or not exposing it publicly.

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@Surfict
Comment options

@szaimen
Comment options

@Surfict
Comment options

@devnoname120
Comment options

Answer selected by szaimen
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants
Converted from issue

This discussion was converted from issue #4881 on June 24, 2024 09:12.