4 ms·
Letsencrypt implemented as a shell script
- phyzome 11y agoI thought one of the big intended advantages of letsencrypt was the apache and nginx integrations.
- SwellJoe 11y agoIt is one of the big intended advantages, but the way it is implemented in the official client is not very flexible, and has a huge dependency list. We just added some support for Let's Encrypt to Virtualmin, and the official client proved clumsy to work with. The smaller clients that have been discussed here lately would have been simpler to integrate (and we may end up with our own Perl implementation before long, so it can be used in Webmin without adding a big stack of dependencies).
- pmlnr 11y agounless you need letsencrypt in, for example, in puppet.
- StavrosK 11y agoI just need something that can do: ./something.py account.key domain.key domain.csr -o fullcert.pem acme-tiny is 95% of the way there, but it doesn't output the full chain. I may just fork it and add the extra step, but I prefer it in the official client.
- normalfaults 11y agoCfssl?
- kbaker 11y agoYou may also want to look at https://github.com/kuba/simp_le https://github.com/kuba/simp_le . Written by the same developer as the official client. Really easy to set up and run from a cron job. Outputs the full chain as well. https://news.ycombinator.com/item?id=10672006 https://news.ycombinator.com/item?id=10672006
- StavrosK 11y agoI tried that as well, but installation wasn't trivial. I think the author pushed it to PyPI yesterday, so I'll give it another shot, thanks!
- metafex 11y agoNow that's something one can use on a server w/o python. It's obviously harder to use than a fire and forget service, but it broadens the use-cases to simple gear where you don't want to run everything (or can't).
- thwd 11y agoAppreciate the effort. Just skimmed through the code, it seems to depend on perl. It was also a quick refresher on how god damn ugly bash's syntax is.
- SwellJoe 11y agoI think I would have just written it in Perl, and remove the bash dependency (since bash is not installed, by default, on some minimal distros...Perl is also missing in such a case, but depending on both is certainly not better).
- umaguma 11y agoIs the lure of letsencrypt that 1 it's accepted without warning in browsers or 2 it lets users ignore learning how to use the openssl binary (or writing their own tools with libssl, polarssl, etc.) to generate ca and site keys, certs, csr's, crl's, etc., or 3 both? Here, the author appears to benefit mainly from 1. Assuming letsencrypt does not do any sort of commercial CA-type "verification" then why do they need to be a CA? Why does one need an account? Answer: browsers clinging to CA system. Why not just get browsers to drop the warnings for self-signed certs? The goal here, I thought, is to facilitate encrypted traffic, not to give a false sense of "authentication", correct? Encryption and authentication are two different things. Every user should understand that.
- nly 11y agoThe allure over other DV CAs is that it's gratis, and, soon, that it'll be deployable at the push of a button. DANE-TA or DANE-EE still would have been better than any and all of this DV public CA nonsense. A DV cert from a public CA proves that someone on the other end of the connection momentarily controlled either the DNS records for your domain, or your web server, at some point in the near past. That's it. DV is an extremely weak proof of identity, and provides no authentication at all (as in, proof that the issue was actually authorised by the domain owner).
- Jasper_ 11y agoDoesn't LetsEncrypt require that you have DNSSEC enabled on your domain, as a first step? DV is a valid proof of identity, assuming DNSSEC, right?
- nly 11y agoNo, DNSSEC isn't required. LetsEncrypt supports a bunch of DV methods right now[0], but the bottom line is that if someone can control either your DNS server or your web server (any web server on an IP at which your domain points) then they can always get a certificate for your domain. This applies to all DV cert issuance from most CAs afaik. Full DNSSEC verification by the issuing CA (LetsEncrypt) still wouldn't mitigate attacks against the "Simple HTTP" method. [0]https://letsencrypt.github.io/acme-spec/#rfc.section.7 https://letsencrypt.github.io/acme-spec/#rfc.section.7
- lukas2511 11y agoHey there, author of this thingy here, nice to see that some people like what i'm wasting my time on ;) Just wanted to let you know that I just pushed a few updates, the code now no longer requires perl, uses the more generic shasum tool, uses base64 in openssl instead of the systems base64 binary, and some more stuff. There are a few more dependencies I want to get rid of, like 'sed'. But 'openssl' and 'curl' will stay as depdencies. I also want to expand this script with the ability to detect changes in the domain config and with a check if a certificate is about to expire so that it can be renewed in a cron-job or something similar. Revocation is another thing that I kinda should look at, for now you'll have to do that with one of the other clients that has this option. And thanks to the author of acme-tiny, which kinda inspired me to write this.
- chengiz 11y agoWhy do you care about the sed dependency? It's a basic unix command that everyone has. Unless there's some strong time penalty, it'd be better to use sed over some weirdass bash syntax.
- lukas2511 11y agoWell, i'll have to check if the syntax i used works under BSD sed, because that seems to differ slightly and I ran into problems in the past.
- 0x0 11y agoA shellscript... and a perl script and the openssl command line binary!