dns-01 allow the use of CNAME to delegate the challenges to be check in another record, and in another zone. This is very useful to setup an independent zone, independent update key which only useful for acme-challenge record, instead of granting acmebot to manipulate all records in the target zone.
Currently, acmebot does not honor this CNAME record, nor is there anyway to force acmebot to nsupdate another record, and check the correct record/zone in "wait for DNS propagation".
dns-01 allow the use of CNAME to delegate the challenges to be check in another record, and in another zone. This is very useful to setup an independent zone, independent update key which only useful for acme-challenge record, instead of granting acmebot to manipulate all records in the target zone.
Currently, acmebot does not honor this CNAME record, nor is there anyway to force acmebot to nsupdate another record, and check the correct record/zone in "wait for DNS propagation".