Get the SSL certificate before you move the DNS record
A DNS challenge proves a domain without it pointing at the new server, so the certificate is ready before the switch and no visitor sees an error.
The gap every migration has
The usual order is: copy the site, move the DNS record, then ask for a certificate. Between the second step and the third, the new server is receiving visitors and has no certificate for them.
How bad that is depends on what sits in front. With plain DNS, visitors get a browser warning for a few minutes. Behind Cloudflare in Full or Full (strict) mode they get error 525 or 526, because Cloudflare insists on HTTPS to the server and the server has nothing to offer.
The order exists because of how the common proof works. With the HTTP challenge, the certificate authority fetches a file from the domain over port 80. That only succeeds once the domain points at the server asking. So the certificate cannot come first.
The other proof does not need the domain to point anywhere
There is a second way to prove you control a name: the DNS challenge. The certificate authority gives you a value, you publish it as a TXT record at _acme-challenge.example.com, and it looks the record up. No request is ever made to the web server.
That has one consequence that matters here. The A record can keep pointing at the old server the whole time. The certificate is issued to the new server while the old one is still serving every visitor.
The cost is that something has to be able to write to the zone. By hand that is a record to add and remove for every issue and every renewal, which is why few people do it. With an API token for the DNS provider, it is automatic.
The order that leaves no gap
- Copy the site to the new server and check the copy there.
- Issue the certificate on the new server through the DNS challenge.
- Confirm the new server answers over HTTPS for the name. This asks the new server directly, whatever the DNS says:
curl -sv -o /dev/null --resolve example.com:443:203.0.113.10 https://example.com/
- Move the A record. Behind Cloudflare, leave the proxy as it is and change only the address.
From the visitor's side nothing happens at step 4 except that the answers start coming from a different machine. There is no minute in which the name points at a server without a certificate.
How KLYRN does it
Connect the DNS provider once. For Cloudflare that is an API token that can edit DNS for the zone:
KLYRN_DNS_TOKEN=your-token klyrn dns connect --label "Cloudflare"
klyrn dns providers
From then on, a site whose zone KLYRN can write does not wait for its DNS. Since 1.0.6 the certificate is proven through DNS when the domain does not arrive at the server yet. Since 1.0.7 nobody has to ask: a site that is waiting for DNS gets its certificate on the scheduler's next pass, within ten minutes of the site being created or the account being connected. A domain with no record at all is covered the same way.
To ask for it at once, and to see the result:
klyrn site ssl example.com
klyrn site show example.com
Then the switch itself, which changes the address and leaves Cloudflare's proxy as its owner had it:
klyrn dns point example.com
What it does not cover
A zone KLYRN cannot write gets no early certificate. Those sites wait for the record to move, as before, and are issued automatically once requests arrive.
A DNS proof that fails is tried again every six hours, not every ten minutes. Certificate authorities limit failed attempts per name, and a zone that is broken at noon is usually still broken ten minutes later.
And the certificate is only half of a clean switch. Lower the record's TTL a day ahead, so the old address is forgotten in minutes and not hours.