11 ms·
Free SSL on Github Pages with a custom domain: Part 2 – Let's Encrypt
- sideproject 8y agoPerhaps I missed, but is it possible for anyone to use this "agent" to offer this type of service?
- tialaramex 8y agoAre you asking whether Github is offering their agent software for others to use? Or just whether, in general, there are agents which can make use of Let's Encrypt? The answer to the latter is yes, of course, a wide variety of suitable software exists, including shell scripts like https://acme.sh/ https://acme.sh/ the "official" Certbot Python code and software like Caddy which implements this feature right inside a web server.
- bartdegoede 8y agoMailinabox (https://mailinabox.email/guide.html#admin https://mailinabox.email/guide.html#admin) uses it to get SSL certificates too; you can see it in action here https://github.com/mail-in-a-box/mailinabox/blob/master/management/ssl_certificates.py#L156 https://github.com/mail-in-a-box/mailinabox/blob/master/mana...
- teolandon 8y agoI'm hosting my webpage on GitHub Pages, with a custom domain. Back when I set it up, Let's Encrypt would not work with GitHub Pages so instead I simply put my page on Cloudflare. Should I spend the time and set it up again but with Let's Encrypt? I've heard people say bad stuff about Cloudflare, but dismissed it since my page is really just a blog.
- Ajedi32 8y agoUnless you personally have something against Cloudflare I'd say there's really no reason to bother changing anything. But yeah, if you point your domain directly at GitHub Pages instead of at Cloudflare then GitHub should just issue you a cert and start using it automatically.
- mrkurt 8y agoOpen IP the cert you're using and see what other sites are listed on it. It probably includes a lot of sites that aren't yours. GitHub + Let's Encrypt gives you a clean cert for just your hostnames.
- ReverseCold 8y agoJust curious, why does that matter? It works and is secure, right?
- michaelbuckbee 8y agoAn interesting alternative is Fly.io - you can setup everything to go through them with a backend that's your Github Page and they'll spin out LE certs on the fly for it.
- scrollaway 8y agoIt doesn't really matter for a blog without auth, but when you are using cloudflare's https, the connection is not encryptes between CF and GitHub, so it's not end to end encrypted. I recommend simply migrating even if you keep the DNS itself on cloudflare. It's a good exercise if nothing else.
- icebraining 8y agoIt can be encrypted if you're using Full SSL on Cloudflare[1], but it's not authenticated, meaning anyone actively MITMing the connection between CF and GH could easily read and change the traffic. That said, it's not any script-kiddie who can MITM a connection between two DCs, so I think it's hardly a grave threat. I think the only real gain is not allowing CF itself to see who is accessing your blog. [1] https://support.cloudflare.com/hc/en-us/articles/200170416-What-do-the-SSL-options-mean- https://support.cloudflare.com/hc/en-us/articles/200170416-W...
- scrollaway 8y agoYou can't use full ssl with let's encrypt, which is fundamentally incompatible with proxying. But yes as I said it doesn't matter for a blog in practice.
- icebraining 8y agoYou can't use full ssl with let's encrypt, which is fundamentally incompatible with producing. I don't understand this statement, sorry.
- scrollaway 8y agoPhone autocorrected :) I meant proxying.
- icebraining 8y agoAh, ok. But how so? You can get a LE cert as long as you can serve a file in the correct URL, or set a certain DNS record. I don't see why proxying would prevent that.
- negativegate 8y agoDoes anyone have this working for both the www subdomain and the root domain? I have the www subdomain working fine, but I get an invalid cert error when attempting to access the root domain with HTTPS. The cert it's attempting to use is for www.github.com .
- Jayschwa 8y agoI'm having problems with it too. I plugged in the new IP addresses for my root A records yesterday, and then deleted and re-added the CNAME file in the repository. GitHub support said they manually started the certificate provisioning process several hours ago, but I'm still getting certificate errors.
- lukebaker 8y agoI was having trouble with that yesterday, as well. On the settings page for my repository, I switched from www.example.com to example.com and then back again to www.example.com. I noticed it is now working for my site, though I don't know for sure that my changes fixed it. https://help.github.com/articles/troubleshooting-custom-domains/#https-errors https://help.github.com/articles/troubleshooting-custom-doma...
- saagarjha 8y agoYou may not have had a certificate issued for your domain yet. The steps I went through for this were changing the CNAME, which made GitHub go try to get a new certificate for me.
- negativegate 8y agoIt issued a certificate for the www subdomain which is working fine. I need it to issue one for the root domain too.
- RyanShook 8y agoIs it possible to set up SSL thru GitHub and also use Cloudflare?
- dayvidwhy 8y agoyeah you could setup the github ssl as per their instructions, then put cloudflare in front of it. See their options here https://support.cloudflare.com/hc/en-us/articles/200170416-What-do-the-SSL-options-mean- https://support.cloudflare.com/hc/en-us/articles/200170416-W... I was previously using the partial ssl option and am quite happy that I don't have to continue with this pseudo ssl that has an unsecure link.
- blaze33 8y agoInteresting, as it wasn't possible to have https and a custom domain in the past, I'm using Cloudflare with the flexible https & enforce https settings. Though in github, the "enforce https" is greyed out and says: "Unavailable for your site because your domain is not properly configured to support HTTPS (lab.openbloc.fr)". Does anyone knows what isn't actually "properly configured"? I have a CNAME file in the repo containing "lab.openbloc.fr". The help says "If you're updating an existing custom domain, first remove and then re-add your custom domain to your GitHub account to trigger the process of enabling HTTPS." but the option is still disabled.
- dayvidwhy 8y agoIn your position I did these things; - Removed the CNAME record; - Changed my A records to point to githubs https ip's - Deleted the site from cloudflare - Purged my cache for the site in chrome (chrome appears to remember who your site has its cert with for a bit?) - Profit
- isaack 8y agoYou need to turn off CloudFlare proxying for your domain. Instructions here: [1]. (Can't find an official help page, sorry). Also make sure that you are using a CNAME record pointing to `YOUR-USERNAME.github.io.`. [1]: https://webmasters.stackexchange.com/a/71922 https://webmasters.stackexchange.com/a/71922 [2]: https://help.github.com/articles/setting-up-a-www-subdomain/ https://help.github.com/articles/setting-up-a-www-subdomain/
- scrollaway 8y agoI had to contact support. They nudged the system for me.
- hdra 8y agoI had to put remove the CNAME file, push, add it back, and push it again to trigger the check again (You can do this with the domain textbox on your settings page as well).
- codedokode 8y agoI've tested, it works awesomely. But does it mean that anyone who got temporary access to your DNS can issue certificates and MITM your traffic? It should not be this way.
- mpnordland 8y agoIt was always that way. Let's encrypt actually improves this by only handing out short lived certs.
- theden 8y agoI just recently decided to move my GitHub pages with custom domains to netlify (https://www.netlify.com/ https://www.netlify.com/), since it offered free out of the box SSL (let's encrypt). Kinda wish I waited, but it's good that they finally support it.
- coleschifer 8y agoI did the same thing with about 5 websites.
- bernardino 8y agoThe best play is to host on Github and deploy Netlify. I’ve previously used to do Cloudfare for SSL, but someone on here convinced me on Netlify.
- icebraining 8y agoNow that GH supports SSL natively, why use Netlify?
- forcemajeure 8y agoNetlify is designed for hosting so has richer functionality. https://www.netlify.com/github-pages-vs-netlify/ https://www.netlify.com/github-pages-vs-netlify/
- cdancette 8y agoThe only thing that annoys me about github pages or netifly is the lack of traffic analytics (number of visits, location..). There isn't a single metric we can have access to. Cloudflare gives minimal but useful analytics
- delta1 8y agoWhy not use Google (or other) analytics?
- deafcalculus 8y agoHuge percent of the audience blocks GA.
- cdancette 8y agoFirst, I would prefer not to use a third party analytics that tracks user behavior and downloads / uploads things to their server while users are browsing. Especially to Google servers. All the info I need is already in the http server logs. That's a shame we can't have access to analytics on them.