3 ms·
You're supposed to automate renewal. Since v0.4.0 all it takes is a "letsencrypt renew && apachectl graceful" in a daily cronjob (or, preferably, systemd timer
by Ao7bei3s 11y ago
You're supposed to automate renewal.
Since v0.4.0 all it takes is a "letsencrypt renew && apachectl graceful" in a daily cronjob (or, preferably, systemd timer), it handles the rest. Tweak as you like.
- jqueryin 11y agoAssuming you use Apache. For many, it's simply not a fast enough web server without reverse proxies in front of it. Still crossing fingers for full nginx support soon.
- creshal 11y agoAnd, of course, there's other services than web servers that benefit from LE certificates. Mail, FTP, chat, etc. …
- nkuttler 11y agoI don't know, I don't want letsencrypt to touch my config files. It just works fine without that "magic" anyway if you're willing to add a few lines to a config file.
- ptaffs 11y agoI agree, but i think the LE target audience is not you. Their whole thing is to be easy and use the "magic", to get the people who don't want to buy a certificate or deal with the config files, onto good encryption. I'm their audience and now my low-power volunteer run FM radio station website has HTTPS with a recognised CA.
- pde3 11y agoIf you use the letsencrypt python client with "certonly --webroot", it will never touch your config files at all. You can add "-n" to make everything non-interactive and command line-only. If you use letsencrypt with "certonly --apache" (or --nginx, when the nginx plugin is released) it will make only transient changes to your config in order to obtain the cert, and then restore it to the original state before exiting. If you use letsencrypt with "run" (which is the default command) it will make config changes if those appear to be necessary for installing the cert. One challenge we've had is how to design the command line interface to ensure that the users who want maximum automation get it, and the users who want maximum manual control also get that. Both set of behaviour are available.
- Ao7bei3s 11y agoNo, actually not. "letsencrypt-auto renew" uses the same settings you've used with "letsencrypt-auto run/certonly". If you're using nginx, that's probably the --webroot method. Which works for renewals too.
- ascorbic 11y agoUse webroot auth and it's fine with nginx. I just ran my first set of renewals with half a dozen domains on nginx. All fine apart from one which hadn't used webroot when I first set it up. Edited the config and it then worked fine.
- pingec 11y agoI understand and agree on why they made it like this. But automating it is not an option in my use case, oh well... I agree it's for the better in the grand scheme of things :).
- dingaling 11y agoBe sure to have a script that checks the results of your cronjobs, though: "It is possible to hit the rate limit using letsencrypt renew and have it fail or partially fail for that reason." https://community.letsencrypt.org/t/help-us-test-renewal-with-letsencrypt-renew/10562?source_topic_id=4393 https://community.letsencrypt.org/t/help-us-test-renewal-wit... They launched with 90-day expiry but without a robust renewal process.
- Kadin 11y agoTrue. Although if you run it daily, you'll have multiple opportunities for the renewal to go through before it actually expires. It'll survive a couple of unsuccessful tries in the default/recommended configuration, at least if I'm understanding everything correctly.
- ris 11y agoSince v0.4.0 all it takes is a "letsencrypt renew && apachectl graceful" in a daily cronjob" I'm glad your setup is so simple.