Docs › Certificates

Wildcard certificates with Nginx Proxy Manager

Choose ACME-DNS as the DNS provider. NPM drives certbot's dns-acmedns plugin, which reads two things: the credentials box below, and a registration file you place in the container yourself.

Where the configuration lives

SSL Certificates ▸ Add Certificate ▸ Use a DNS Challenge

Configuration

Nginx Proxy Manager: DNS challenge credentials
# in the credentials box
dns_acmedns_api_url = https://api.home.network/acmedns
dns_acmedns_registration_file = /etc/letsencrypt/acmedns.json

# the file at that path, which you create inside the container
{"alice.home.network":{"username":"<your username>",
 "password":"<your key>","fulldomain":"_acme-challenge.alice.home.network",
 "subdomain":"<your subdomain>","allowfrom":[]}}

The username, password and subdomain come from the setup wizard, which shows them once. They are stored hashed, so a lost set is replaced rather than recovered.

Worth knowing. The registration file is never created for you, and NPM gives no error when it is missing beyond a failed issuance. Create it inside the container at the path above, keyed by the base domain. Request the wildcard and the bare label together in the Domain Names field. Note the plugin keys take no certbot_dns_acmedns: prefix, which older READMEs still show from before certbot 1.7.

Ask for both names

A wildcard does not cover the name it sits under, so a certificate for *.alice.home.network alone leaves alice.home.network without one. Request both in a single certificate.

Check it worked

verify
# the challenge value your client published
dig +short TXT _acme-challenge.alice.home.network @ns1.home.network

# what the certificate ended up covering
echo | openssl s_client -servername nas.alice.home.network \
  -connect nas.alice.home.network:443 2>/dev/null \
  | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"

Why only wildcards

Challenge records are writable only at your label apex, so the only certificates obtainable are the wildcard and the label itself. Your individual device names never reach Certificate Transparency logs, which is a consequence of the design rather than a setting to remember.

← All documentation