The end of self-signed certificates
I decided to deploy a Let's Encrypt certificate on my Unifi Dream Router. Since I own a domain and Active24 is one of the providers that supports API access for domain management, I wanted to take advantage of it. What I needed was DNS validation — DNS-01. After a bit of digging I used the following project. You won't find Active24 listed there, but the official Active24 client supports it. All you need are the variables _ACTIVE24_APIKEY and _ACTIVE24SECRET. The DNS provider is set to active24.
The primary motivation was the UDR block page that pops up when a user browses where they shouldn't. For the same reason I have a Let's Encrypt certificate on AdGuard Home. But more on that next time.
