4 ms·
I wrote some shell scripts a while back [0] for almost this purpose. I have a backup MX that does not run any Web services, but I wanted TLS anyway for the SMTP
by zyberzero 8y ago
I wrote some shell scripts a while back [0] for almost this purpose. I have a backup MX that does not run any Web services, but I wanted TLS anyway for the SMTP.
It uses the let's encrypt client (certbot) and nsupdate so I can use any RFC2136 compatible DNS server, in my case, Bind. This has been running on the backup MX since I wrote it, without any hickups so far.
This can also be used for. Internal services, since you do not expose anything to the internal machine.
[0] https://github.com/zyberzero/certbot-rfc2136 https://github.com/zyberzero/certbot-rfc2136