8 ms·
Show HN: Lescript – Simple PHP client library for Let's encrypt
- mei0Iesh 11y agoI was going to star it, until I saw the advertisement in the README.md.
- efesak2 11y agoIs it problem? I am author of poste.io too. Edit: To be precise lescript.php was developed only and because of LE implementation to Poste.io
- TazeTSchnitzel 11y agoPutting a line or two about why you developed a library doesn't seem unreasonable.
- Vendan 11y agoI'm actually happy about it in most cases, as it shows that it's likely to be maintained, as it has a existing use outside of "Hey, I wrote some code!"
- sschueller 11y agoThanks, seems like every day we get a shorter version. This is actually quite useful since I have PHP on most system but not all the dependencies that some of the python versions require. I'm hoping to see a single file bash script at some point :)
- efesak2 11y agoActually there is single bash file client https://github.com/lukas2511/letsencrypt.sh https://github.com/lukas2511/letsencrypt.sh :)
- adolfoabegg 11y agoFrom README: If you prefer more robust and clean library see excellent https://github.com/kelunik/acme https://github.com/kelunik/acme
- efesak2 11y agoHuge obstacle from using kelunik lib is PHP7 and need of external libraries.
- TazeTSchnitzel 11y agoWhat's wrong with external libraries? They're a mere `composer install` away.
- efesak2 11y agoNothing in general, its about choice...
- TazeTSchnitzel 11y agoSo this is a solution looking for a problem, then?
- Kiro 11y agoWhat is Let's encrypt exactly? I thought it was just free SSL so why do I need to touch my code at all?
- Hytosys 11y agoLet's Encrypt has a public API for managing certificates. One use case where this is handy is for creating/modifying certificates for each customer-controlled domain/subdomain of your multi-tenant web service.
- onion2k 11y agoLet's Encrypt certificates expire after 30 days. The reason for that is to mitigate problems with old certs and to encourage automation so there's less danger of a server being left unsecured because an admin forgotten to update something. This sort of library is aimed at [sys|web|dev]ops rather than developers per se. Ultimately services like LE will get to the point where certificates will expire in hours rather than days, so a problem like Heartbleed will 'self-heal' because certificates can be fixed and servers will automatically get the patch within a day.
- akerro 11y ago90 days.
- jnardiello 11y agoMate, seriously, use composer and packagist.
- TazeTSchnitzel 11y agoAlso maybe a namespace. I doubt they're the only person to have ever made a class called `\Client` :) http://phptherightway.com/ http://phptherightway.com/ Though I notice that the README states "[i]ts goal [is] to have one easy to use PHP file without dependencies", and they point out there's already a proper package out there, kelunik/acme. If the goal is a single file with no dependencies, I can understand the lack of Composer, as it's not really targeted at that audience.
- Raed667 11y agoThank you for the great link.
- jnardiello 11y agoIf the target audience are those developers manually including everything, then it's not a package for me. Using composer is completely unrelated to having (or rather not) dependencies. It's actually pretty much the opposite: a way of distributing your package to projects who wish to use it. So again: please use composer. Completely agree with the namespace. You HAVE to namespace it :) Hope it helps
- efesak2 11y agoComposer is awesome, but this is not a package ready to use! (at least not now). Valid point for namespace.
- mschuster91 11y agoWell, composer needs to be installed and present on the system. As the author states, minimal dependencies. Hell why doesn't everyone follow this? Instead I see projects with five or more build tools needed to deploy a website. A single small website depending on... PHP/MySQL (obviously), Symfony, composer, npm, grunt, bower, ant, vagrant, docker. And well, language dependencies not needed by the website itself, just for the buildtools: python, nodejs, ruby, java plus virtualbox for vagrant! All of this for a setup that can be (with proper documentation) replicated by hand and from scratch in <10 minutes (Debian, not RPM-based crap). The fuck are you smoking, people? Took me even WITH documentation about all those build tools 30min to get running where a simple git clone should be all that's needed. Bonus side effect: if you need to hack stuff in your deps, it's easier to ship them in your repo than if you use composer and friends. I'd coin a new term for this: tool-sturbation.
- TazeTSchnitzel 11y ago> public function signDomains($domains) Should this have an `array` type declaration? You used it on another function.
- fu86 11y agoWhy is this crap on the frontpage?
- deleted 11y ago[deleted]
- vitro 11y agoWhy is this comment here?
- c_prompt 11y agoHow is this used to renew? I don't see a function related to renewals.
- deleted 11y ago[deleted]
- dangrossman 11y agoWhat would be the difference between "renewing" and running the script twice? There's no distinction made when I buy certificates from another CA.
- c_prompt 11y agoThis is probably my misunderstanding of how it works. Pardon what's probably a silly question, but do all certs work the same way (i.e., certs are never "renewed" but just reissued with new dates)?
- 286c8cb04bda 11y ago> certs are never "renewed" but just reissued with new dates This is correct.
- cosecantt 11y agoThe question arises. How Letsencrypt handle reissued certificates under one domain? Guess if I reissue million times for a specific domain, does this override the previous certificates on their database or does it create valid certificates each time I reissue? Thanks for the script.
- ewams 11y agoThanks, nice looking code that is pretty darn clean. It is always refreshing to see an application that is as self contained as possible without all the multitude of required dependencies.