4 ms·
I'm curious how renewals will be handled. According to https://github.com/icing/mod_md/wiki#no-auto-restart-when-started-as-root https://github.com/icing/mod_md
by cholmon 9y ago
I'm curious how renewals will be handled. According to https://github.com/icing/mod_md/wiki#no-auto-restart-when-started-as-root https://github.com/icing/mod_md/wiki#no-auto-restart-when-st...
"...you have to manually restart httpd for any certificate changes to take effect."
It's easy enough to have a daily cronjob that just reloads Apache unconditionally, but that feels dirty.
- jimminy 9y agoThe same thing is required of nginx. I personally have a cron script set up on my domain gateway to update certificates once a month and reload nginx, at the end. Total unavailability is about .5 sec once a month.
- askz 9y agoReload process in nginx isn't graceful?
- gtirloni 9y agoIt certainly is. http://nginx.org/en/docs/beginners_guide.html#control http://nginx.org/en/docs/beginners_guide.html#control
- jimminy 9y agoIt is. I hadn't even looked into it, because I set the job to off hours and the domains have low enough volume even a non-graceful reload wouldn't effect anything. Thanks for asking, because now I know. I was just assuming the same lag I see in the CLI.
- deleted 9y ago[deleted]
- ridruejo 9y agoApache supports graceful restarts, in which new children processes are spawned and old ones replaced without dropping existing connections
- Ajedi32 9y agoHuh, that's a rather interesting limitation. I guess internally mod_md must be changing the configuration of the server with every renewal? Otherwise I'm not sure why a restart would be needed; the server should just start using the new cert for new connections.