3 ms·
Yes, there are definitely multiple ways to configure it. We focused first on working successfully for as many people as possible, which meant shipping the letse
by pde3 10y ago
Yes, there are definitely multiple ways to configure it. We focused first on working successfully for as many people as possible, which meant shipping the letsencrypt-auto wrapper script which requires sudo.
But with some extra work you can definitely run Certbot as a non-root user, and we're working with the OSes that package us to have Certbot operate with something like ssl-cert group privileges in many situations in the future.
- jalami 10y agoI understand and had that idea when I heard it needed sudo initially. It makes sense for a reference-ish implementation to make it quick and easy for the large userbase to adopt. If I had to trust an org to run their code as sudo on my rig, EFF would probably be it. HTTPS needs to be adopted universally first and foremost. I just chose Acme-tiny because it was tiny and didn't have many of the bells and whistles like wrapping revocation or a DNS verification that I didn't need. Neat and nifty features for certain, but I try to keep it stupid simple. I wanted something with a small footprint I could understand and domesticate. Thanks for all your work, the EFF is awesome and so is Certbot. Letsencrypt has been a lifesaver. Keep up the good work!