6 ms·
Do their certificates still expire in only 90 days? That makes them very unappealing to me :/ Edit: I understand and agree on why they made it like this. But a
by pingec 11y ago
Do their certificates still expire in only 90 days? That makes them very unappealing to me :/
Edit: I understand and agree on why they made it like this. But automating it is not an option in my use case, oh well... I agree it's for the better in the grand scheme of things :).
- throwaway7767 11y agoYes. I think they do that on purpose to get people to automate the certificate renewal. Their default client of course messes with all sorts of configuration to make auto-renew work "out of the box". Many people (myself included) aren't fans of their client getting so much access, but there are other clients out there that don't need it. I use acme-tiny[0] in a small shell cronjob once a month. It lets acme-tiny request a renewed certificate. Then it checks that the new certificate is valid, copies it to the right places and reloads the relevant services. Honestly, I couldn't be happier about not having to manually change certificates again. [0] https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny
- Ao7bei3s 11y agoStop spreading FUD: it does not "mess with all sorts of configuration". _Renewal doesn't touch any config files at all._ "letsencrypt-auto" puts the certs/keys under /etc/letsencrypt/keys. On renewal, new files get added. Old files are never touched. /etc/letsencrypt/live contains symlinks to the most recent files. Your webserver config uses these => its config does not need to be changed for renewal. What you're talking about is only the initial certificate installation with "letsencrypt-auto run", and it makes a very targeted change in your Apache config. Use etckeeper if you don't trust it. If you still don't want that, use "letsencrypt-auto certonly". (Note on server restarts: It also supports multiple methods, one of which is the webroot method, with which letsencrypt-auto does the challenge by putting a file under .well-known/acme-challenge/ of your webroot and lets your webserver handle the request, so it doesn't need to restart/replace your webserver itself.) And about all these "minimalistic tools": I've seen one that literally did "new-cert.sh > $cert-file". If it failed (e.g. due to ratelimit, no internet connectivity, ...), it would null your old cert! Written and used by very smug people.
- throwaway7767 11y agoIt wasn't intended to be FUD. The letsencrypt client needs to change the configuration of other services. This is a fact. Not everyone is happy about that, so I pointed out an alternative. If you're happy with the official client, by all means, use it! There's nothing inherently wrong with that approach, it's just not compatible with the way I and some others prefer to do things. EDIT in response to your edit: > And about all these "minimalistic tools": I've seen one that literally did "new-cert.sh > $cert-file". If it failed (e.g. due to ratelimit, no internet connectivity, ...), it would null your old cert! Written and used by very smug people. Absolutely, the minimal tools are not for people who don't know what they're doing. You absolutely would not run acme-tiny for example with write access to your actual cert that the web server is using, because any number of failure scenarios would result in downtime. That's why I specifically addressed that in the initial post you're replying to when I said: "Then it checks that the new certificate is valid, copies it to the right places and reloads the relevant services".
- nkuttler 11y agoThe official letsencrypt client never touched any of my config files, it doesn't have to if you prefer to do it yourself.
- detaro 11y ago> The letsencrypt client needs to change the configuration of other services. This is a fact. Not everyone is happy about that, so I pointed out an alternative. No, it doesn't NEED to. It's the most commonly discussed option, but it is not necessary. It can do the exact same "write to a folder in the webroot" mode most of the alternatives use. (I'm not saying that there is no reason to use an alternative client, but that's not it)
- ceejayoz 11y ago> Stop spreading FUD: it does not "mess with all sorts of configuration". It does more than you'd expect, IMO. > letsencrypt-auto is a wrapper which installs some dependencies from your OS standard package repositories (e.g. using apt-get or yum), and for other dependencies it sets up a virtualized Python environment with packages downloaded from PyPI. http://letsencrypt.readthedocs.org/en/latest/using.html http://letsencrypt.readthedocs.org/en/latest/using.html I was certainly a bit surprised when apt-get ran.
- mike-cardwell 11y agoI haven't fully automated mine yet, but I get alerts when any of my certs are getting close to expiry and I just have to run "/etc/letsencrypt/process.sh" now and it handles everything automatically at that point. I'd rather run that script manually 4 times a year than go through the pain of renewing all of my certs by logging in to websites and pasting CSR's and Certs around every 1 or 2 years. Once I'm comfortable with the process I'll just cron it and forget about it.
- feld 11y agoDon't forget this[1] gem which is my favorite way to use letsencrypt. It will let me run it by cron (or periodic on FreeBSD) plus I can have my own post-run script that takes my certificates and keys and puts them in the format I need for Hitch (SSL termination for Varnish), push those changes, restart the service _inside_ a FreeBSD jail automatically. It's advanced setups like this where LetsEncrypt fails out of the box, but it's nice we have tools like this at our disposal now. [1] https://github.com/lukas2511/letsencrypt.sh https://github.com/lukas2511/letsencrypt.sh
- Ao7bei3s 11y agoYou're supposed to automate renewal. Since v0.4.0 all it takes is a "letsencrypt renew && apachectl graceful" in a daily cronjob (or, preferably, systemd timer), it handles the rest. Tweak as you like.
- jqueryin 11y agoAssuming you use Apache. For many, it's simply not a fast enough web server without reverse proxies in front of it. Still crossing fingers for full nginx support soon.
- creshal 11y agoAnd, of course, there's other services than web servers that benefit from LE certificates. Mail, FTP, chat, etc. …
- nkuttler 11y agoI don't know, I don't want letsencrypt to touch my config files. It just works fine without that "magic" anyway if you're willing to add a few lines to a config file.
- ptaffs 11y agoI agree, but i think the LE target audience is not you. Their whole thing is to be easy and use the "magic", to get the people who don't want to buy a certificate or deal with the config files, onto good encryption. I'm their audience and now my low-power volunteer run FM radio station website has HTTPS with a recognised CA.
- pde3 11y agoIf you use the letsencrypt python client with "certonly --webroot", it will never touch your config files at all. You can add "-n" to make everything non-interactive and command line-only. If you use letsencrypt with "certonly --apache" (or --nginx, when the nginx plugin is released) it will make only transient changes to your config in order to obtain the cert, and then restore it to the original state before exiting. If you use letsencrypt with "run" (which is the default command) it will make config changes if those appear to be necessary for installing the cert. One challenge we've had is how to design the command line interface to ensure that the users who want maximum automation get it, and the users who want maximum manual control also get that. Both set of behaviour are available.
- nly 11y agoGo get a free 3 year cert for up to 5 domains from WoSign then. https://buy.wosign.com/free/ https://buy.wosign.com/free/
- kcbanner 11y agoWhy?
- ubergesundheit 11y agoMay I point you to the awesome Caddy server of Matt Holt [0]. It automatically obtains and !renews! lets-encrypt certificates. [0] https://github.com/mholt/caddy https://github.com/mholt/caddy
- warrenm 11y ago>"automating it is not an option in my use case" Then you're doing it wrong - there is no reason you shouldn't be able to automate it that I can envision
- technion 11y agoThere are valid scenarios. Placing a certificate on something like an F5 or Citrix VPX appliance pretty well forces you down the email verification route. Then you've got those appliances that take a power cycle and 30 minute outage to install such a certificate. Five year certs are very attractive for this situation.