Date: September 28, 2026
Google Trust Services now supports the dns-persist-01 challenge type for
Automated Certificate Management Environment (ACME) domain validation.
Defined in the IETF Internet-Draft
draft-ietf-acme-dns-persist-01,
this validation method allows a Certification Authority (CA) to verify control
over a domain by confirming the presence of a persistent DNS TXT record
containing CA and account identification information.
What is DNS-PERSIST-01?
In other ACME validation methods like dns-01, a client must provision a new,
short-lived challenge token in DNS for every validation or certificate renewal.
In many environments, constantly updating DNS records can be impractical,
fragile, or operationally prohibitive.
dns-persist-01 creates a persistent authorization linking a domain name to a
specific ACME account and CA. Once the persistent DNS TXT record is established,
the CA can validate issuance requests without requiring clients to update DNS
records on every renewal.
Key features include:
- Persistent Authorization: Creates an ongoing authorization in DNS, enabling fully automated, unattended renewals.
- Multiple CA Support: You can have multiple records for different CAs at
the same domain label (e.g.,
_validation-persist.example.com). Each CA queries DNS and processes only the record matching its own Issuer Domain Name while ignoring records for other CAs. - Wildcard and Subdomain Support: The record can include
policy=wildcardto authorize certificate issuance not only for the validated domain, but also for its subdomains and wildcard certificates (such as*.example.com). - Validity Capping (
persistUntil): You can cap how long the record is valid by including the optionalpersistUntilparameter containing a UNIX timestamp (seconds since epoch). CAs will not consider the record valid for new validations after that time.
Configuring DNS-PERSIST-01 for Google Trust Services
To allow GTS to issue certificates for example.com and subdomains for the user
with the AccountURI https://pki.goog/acct/12345678, create the following
record:
- Host/Name:
_validation-persist.example.com. - Type:
TXT - TTL: Set to a standard value, like 3600 (1 hour).
- Value: Combine the CA's name, your Account URI, and
policy=wildcard. - Format:
[CA]; accounturi=[Your-URI]; policy=wildcard - Example:
pki.goog; accounturi=https://pki.goog/acct/12345678; policy=wildcard