3 ms·
Like I said, I haven't used the their client, just going off what I've come across in researching it briefly. Something must have changed then, there are multip
by jalami 10y ago
Like I said, I haven't used the their client, just going off what I've come across in researching it briefly. Something must have changed then, there are multiple ways to configure it, or what I read previously was just wrong.
I thought that was why repos like https://github.com/diafygi/letsencrypt-nosudo https://github.com/diafygi/letsencrypt-nosudo existed for a time.
That's good news nonetheless.
- pde3 10y agoYes, there are definitely multiple ways to configure it. We focused first on working successfully for as many people as possible, which meant shipping the letsencrypt-auto wrapper script which requires sudo. But with some extra work you can definitely run Certbot as a non-root user, and we're working with the OSes that package us to have Certbot operate with something like ssl-cert group privileges in many situations in the future.
- jalami 10y agoI understand and had that idea when I heard it needed sudo initially. It makes sense for a reference-ish implementation to make it quick and easy for the large userbase to adopt. If I had to trust an org to run their code as sudo on my rig, EFF would probably be it. HTTPS needs to be adopted universally first and foremost. I just chose Acme-tiny because it was tiny and didn't have many of the bells and whistles like wrapping revocation or a DNS verification that I didn't need. Neat and nifty features for certain, but I try to keep it stupid simple. I wanted something with a small footprint I could understand and domesticate. Thanks for all your work, the EFF is awesome and so is Certbot. Letsencrypt has been a lifesaver. Keep up the good work!