Let's Encrypt - Which challenge used

Hello MIAB Team,
i hope you are well and safe.

I have “hardened” my MIAB servers by opening only mandatory ports to the world : 25 and 80, all others ports are behind restrictive IP (smtp, imap, ssh, https), since their creations. This drastically reduced CPU workload for fail2ban.

1 month ago, I installed crowdsec (free licensed used) on my servers to secure them more.
I can see in reports that there are more 70.000 attacks blocked by this tool : http scan + http Bruteforce (this is only coming from port 80).

Could you please confirm which Challenge is used by MIAB for SSL Certificate creation/renew with Let’s Encrypt ? is it DNS-01 or HTTP ?

if DNS-01 challenge (i hope but have doubt), there are no reason to expose port 80 to the world.
if HTTP Challenge used, is it plane to update to DNS-01 ?


Best regards
François