5 ms·
Wildcards were one of the two big blockers for Let's Encrypt adoption at a lot of organizations. The second blocker, the operational discipline to automatically
by madsushi 9y ago
Wildcards were one of the two big blockers for Let's Encrypt adoption at a lot of organizations. The second blocker, the operational discipline to automatically refresh the cert and restart services every <90 days, will likely be the only excuse left.
- djstein 9y agoWhile I do not know the full potential of this, apparently certbot is the way to go for refresh services: https://certbot.eff.org/ https://certbot.eff.org/ In our prod we use https://github.com/GUI/lua-resty-auto-ssl https://github.com/GUI/lua-resty-auto-ssl to generate over 1k lets encrypt certs that refresh as they expire. Hope these can help
- quintin 9y agoSaved me a lot of time. Thanks!
- pricechild 9y agoI've really enjoyed using https://github.com/hlandau/acme https://github.com/hlandau/acme and we use it in prod. I'm not sure how up to date https://github.com/hlandau/acme#comparison-list-of-client-implementations https://github.com/hlandau/acme#comparison-list-of-client-im... is.
- tokenizerrr 9y agoJust use any of the dozens of tools to manage this automatically through cron. You don't even have to restart services, just reload them.
- madsushi 9y agoThere are lots of organizations where certificates are "managed" by a recurring Outlook meeting on a 2-year cycle, where you hope that employee is still around. Moving to an automated system like certbot (which I use and love) with proper logging and email alerts is the right way to go! But that can require a lot of communication between the server teams, web teams, IT teams, etc. There are plenty of places where it seems more convenient (true or not) to just deal with $100 every couple of years than spend the time to implement new processes.
- tokenizerrr 9y agoYou can of course always choose to shoot yourself in the foot.
- cortesoft 9y agoThere is no technical solution to that problem.
- stephenr 9y agoSurely it just needs the server team to install certbot (or similar), and configure it to register the domains currently in use. How exactly do the other people need to be involved - there is no purchasing/responding to email for proof/etc required.
- cdubzzz 9y agoFor me, your second blocker has boiled down to a simple weekly cronjob: 0 9 * * 0 certbot renew --renew-hook "service nginx restart" I'm sure there are cases where restarting nginx willy-nilly won't fly, but for non-mission critical it's wonderfully simple. Cerbot is also great for the initial setup. I just add the non-SSL entry, run `certbot --nginx` and follow the simple prompts.
- pfg 9y agoYou can use "service nginx reload" for a graceful reload with zero downtime.
- X-Istence 9y agoThis does not reload the certificates if the new cert is in the same place as the old.
- pfg 9y agoIt does. "service nginx reload" (and similar commands, like systemctl reload nginx in systemd territory) sends SIGHUP to the nginx master process on all distributions I'm aware of, and that will cause the certificate and key files to be re-read. I've been using this in production for more than a year now, and if you google around a bit, most guides for automating renewal on nginx[1] will use that command. [1]: https://www.digitalocean.com/community/tutorials/how-to-secure-nginx-with-let-s-encrypt-on-ubuntu-16-04 https://www.digitalocean.com/community/tutorials/how-to-secu...
- cdubzzz 9y agoAh, thanks for the reference. I only did restart because I had a vague recollection of reading that reload doesn't do the trick.
- twothamendment 9y agoAt work, we use handful of SAN certs from Let's Encrypt. We have a few wildcard certs too, we obviously had to buy those. I'm glad to see LE offer wildcards, but I don't know that it held back too many people. As for large organizations and the 90 limit, I find dealing with it at work isn't a big deal. We have so many they have to be automated anyway. Even if we only had a few, the process is much easier/faster than it used to be to have someone in the company buy a cert and figure out what files to get to us. Now we can just take care of it, no credit card required. An easy cert every 90 days or so or one that is much more work once a year? Let's Encrypt has my vote and people who want to make excuses will never run out of them.