-
Bug
-
Resolution: Done
-
Normal
-
4.13, 4.12, 4.14, 4.15, 4.16
-
None
-
Important
-
No
-
2
-
OSDOCS Sprint 261
-
1
-
False
-
-
N/A
-
Release Note Not Required
Document URL:
Describe the issue:
Make a note about: HTTP-01 solver requires the letsencrypt server can access the cluster's route to issue certificate.
It means:
1 If users are using company internal/private clusters which are behind proxy to access, users should know it is expected that http01 would fail to issue the Certificate.
2 Port 80 must be allowed for the cluster. See https://letsencrypt.org/docs/challenge-types/#http-01-challenge: "The HTTP-01 challenge can only be done on port 80. Allowing clients to specify arbitrary ports would make the challenge less secure, and so it is not allowed by the ACME standard."
Suggestions for improvement:
Make note as above description with explanations.