3 ms·
Assuming you use Apache. For many, it's simply not a fast enough web server without reverse proxies in front of it. Still crossing fingers for full nginx suppo
by jqueryin 11y ago
Assuming you use Apache. For many, it's simply not a fast enough web server without reverse proxies in front of it.
Still crossing fingers for full nginx support soon.
- creshal 11y agoAnd, of course, there's other services than web servers that benefit from LE certificates. Mail, FTP, chat, etc. …
- nkuttler 11y agoI don't know, I don't want letsencrypt to touch my config files. It just works fine without that "magic" anyway if you're willing to add a few lines to a config file.
- ptaffs 11y agoI agree, but i think the LE target audience is not you. Their whole thing is to be easy and use the "magic", to get the people who don't want to buy a certificate or deal with the config files, onto good encryption. I'm their audience and now my low-power volunteer run FM radio station website has HTTPS with a recognised CA.
- pde3 11y agoIf you use the letsencrypt python client with "certonly --webroot", it will never touch your config files at all. You can add "-n" to make everything non-interactive and command line-only. If you use letsencrypt with "certonly --apache" (or --nginx, when the nginx plugin is released) it will make only transient changes to your config in order to obtain the cert, and then restore it to the original state before exiting. If you use letsencrypt with "run" (which is the default command) it will make config changes if those appear to be necessary for installing the cert. One challenge we've had is how to design the command line interface to ensure that the users who want maximum automation get it, and the users who want maximum manual control also get that. Both set of behaviour are available.
- Ao7bei3s 11y agoNo, actually not. "letsencrypt-auto renew" uses the same settings you've used with "letsencrypt-auto run/certonly". If you're using nginx, that's probably the --webroot method. Which works for renewals too.
- ascorbic 11y agoUse webroot auth and it's fine with nginx. I just ran my first set of renewals with half a dozen domains on nginx. All fine apart from one which hadn't used webroot when I first set it up. Edited the config and it then worked fine.