5 ms·
I use acme-tiny[0] and it was pretty simple to setup. The letsencryptclient requires running as root and quite a few dependencies if I remember correctly. I ha
by jalami 10y ago
I use acme-tiny[0] and it was pretty simple to setup. The letsencryptclient requires running as root and quite a few dependencies if I remember correctly.
I have acme-tiny run with its own private user privilages monthly in a cron job and it's pretty slick. Only has access to the account key and writing to the http challenges and cert directories, no private key access.
[0] https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny
Edit: clarification
- majewsky 10y agoThe letsencryptclient does not need to run as root. I run it below its own user and group, and add that group to the http user to allow it to read the certificates and keys. Configuration at https://github.com/majewsky/system-configuration/blob/master/hologram-letsencrypt.pkg.toml https://github.com/majewsky/system-configuration/blob/master... and https://github.com/majewsky/system-configuration/blob/master/hologram-nginx.pkg.toml https://github.com/majewsky/system-configuration/blob/master... Permissions are more granular on your setup, though, as far as I can see.
- jalami 10y agoLike I said, I haven't used the their client, just going off what I've come across in researching it briefly. Something must have changed then, there are multiple ways to configure it, or what I read previously was just wrong. I thought that was why repos like https://github.com/diafygi/letsencrypt-nosudo https://github.com/diafygi/letsencrypt-nosudo existed for a time. That's good news nonetheless.
- pde3 10y agoYes, there are definitely multiple ways to configure it. We focused first on working successfully for as many people as possible, which meant shipping the letsencrypt-auto wrapper script which requires sudo. But with some extra work you can definitely run Certbot as a non-root user, and we're working with the OSes that package us to have Certbot operate with something like ssl-cert group privileges in many situations in the future.
- jalami 10y agoI understand and had that idea when I heard it needed sudo initially. It makes sense for a reference-ish implementation to make it quick and easy for the large userbase to adopt. If I had to trust an org to run their code as sudo on my rig, EFF would probably be it. HTTPS needs to be adopted universally first and foremost. I just chose Acme-tiny because it was tiny and didn't have many of the bells and whistles like wrapping revocation or a DNS verification that I didn't need. Neat and nifty features for certain, but I try to keep it stupid simple. I wanted something with a small footprint I could understand and domesticate. Thanks for all your work, the EFF is awesome and so is Certbot. Letsencrypt has been a lifesaver. Keep up the good work!
- Flimm 10y agoThe letsencryptclient (now renamed to certbot) runs `sudo apt-get install ...` even when running `--help`. I have a pull request that aims to fix that particular surprise: https://github.com/certbot/certbot/pull/2790 https://github.com/certbot/certbot/pull/2790
- illumen 10y agoWow. That's a backdoor. Trying to install stuff without the users permission, and using sudo without the users intent is really not right. How can we trust this if they do such things? It looks like it is running a sudo command with a python script with scripts under a non-root user. This means that anyone who can write data to that non-root user folder can then run things as root. ie. I can drop in a .py file and execute whatever code I want. Code run with sudo should not allow this.
- laumars 10y agoThe backdoor is `sudo` and if you allow passwordless `sudo` then any program you execute has permissions to run code as root. If you require a password to `sudo` then there's less of an issue as even the LetsEncrypt client would require you to grant permissions to `apt-get`. That all said, it's still bad form to `apt-get -y` when run with a `--help` flag. Particularly with the `-y flag`. Even if you trust LetsEncrypt (and most of us would), it's still unexpected / non-idiomatic behavior and the `-y` flag means users don't get much time to cancel the operation should any output concern them.
- pde3 10y agoThis is a discussion about letsencypt-auto, not the underlying letsencrypt/certbot program. Here's what the docs said about letsencrypt-auto: "Because not all operating systems have packages yet, we provide a temporary solution via the letsencrypt-auto wrapper script, which obtains some dependencies from your OS and puts others in a python virtual environment: <instructions to download and run letsencrypt-auto>" If users don't read the label before downloading and running a script, they might be surprised by what it does. But we've learned that users don't read those instructions and get upset anyway, so cerbot-auto now asks for additional interactive permission before installing things.