September 2026 - Google Trust Services Supports ACME DNS-PERSIST-01 Challenge

Date: September 28, 2026

Google Trust Services now supports the dns-persist-01 challenge type for Automated Certificate Management Environment (ACME) domain validation.

Defined in the IETF Internet-Draft draft-ietf-acme-dns-persist-01, this validation method allows a Certification Authority (CA) to verify control over a domain by confirming the presence of a persistent DNS TXT record containing CA and account identification information.

What is DNS-PERSIST-01?

In other ACME validation methods like dns-01, a client must provision a new, short-lived challenge token in DNS for every validation or certificate renewal. In many environments, constantly updating DNS records can be impractical, fragile, or operationally prohibitive.

dns-persist-01 creates a persistent authorization linking a domain name to a specific ACME account and CA. Once the persistent DNS TXT record is established, the CA can validate issuance requests without requiring clients to update DNS records on every renewal.

Key features include:

  • Persistent Authorization: Creates an ongoing authorization in DNS, enabling fully automated, unattended renewals.
  • Multiple CA Support: You can have multiple records for different CAs at the same domain label (e.g., _validation-persist.example.com). Each CA queries DNS and processes only the record matching its own Issuer Domain Name while ignoring records for other CAs.
  • Wildcard and Subdomain Support: The record can include policy=wildcard to authorize certificate issuance not only for the validated domain, but also for its subdomains and wildcard certificates (such as *.example.com).
  • Validity Capping (persistUntil): You can cap how long the record is valid by including the optional persistUntil parameter containing a UNIX timestamp (seconds since epoch). CAs will not consider the record valid for new validations after that time.

Configuring DNS-PERSIST-01 for Google Trust Services

To allow GTS to issue certificates for example.com and subdomains for the user with the AccountURI https://pki.goog/acct/12345678, create the following record:

  • Host/Name: _validation-persist.example.com.
  • Type: TXT
  • TTL: Set to a standard value, like 3600 (1 hour).
  • Value: Combine the CA's name, your Account URI, and policy=wildcard.
  • Format: [CA]; accounturi=[Your-URI]; policy=wildcard
  • Example: pki.goog; accounturi=https://pki.goog/acct/12345678; policy=wildcard