3 ms·
I think your criticisms were pretty fair of the earliest releases of the Let's Encrypt client, but they seem to be less accurate now. We see the client (aka Cer
by pde3 10y ago
I think your criticisms were pretty fair of the earliest releases of the Let's Encrypt client, but they seem to be less accurate now. We see the client (aka Certbot) being used successfully by many hundreds of thousands of site operators. In terms of full automation, the Apache plugin has gone from "experimental" to "works for most people automatically". We'll be working on delivering similar features for Nginx next.
But if lego works for you; that's great!
- niij 10y agoDoes Certbot have the ability to only output the signed certs to a specified directory and nothing more?
- pde3 10y agoAt the moment you can get that behaviour with "certonly --csr". You'll need to make a CSR file yourself. It'll drop your cert and chain files in the current directory. You'll still have an account key and some other ACME protocol housekeeping state in /etc/letsencrypt. https://github.com/certbot/certbot/issues/2373 https://github.com/certbot/certbot/issues/2373 will track implementation a nicer version of that functionality; it'll probably be --no-lineages (lineages are Certbot's notion of a succession of renewed or updated certificates that replace each other; they live in /etc/letsencrypt/live, though you can put them somewhere else with the --config-dir option)