4 ms·
That's a great start. But in a non-technical organisation, who should those messages go to? Often the initial LetsEncrypt setup will be handled, correctly, by
by omh 7y ago
That's a great start.
But in a non-technical organisation, who should those messages go to?
Often the initial LetsEncrypt setup will be handled, correctly, by some IT staff.
Then it might break several months or years later for some odd reason.
The organisational challenge is to get the message through to someone who understands it and will act on it.
- outworlder 7y ago> The organisational challenge is to get the message through to someone who understands it and will act on it. Yes, and to keep a very infrequently used channel working and up-to-date.
- brongondwana 7y agoThis is why letsencrypt very sensibly creates short-lived certificates, meaning that the channel is not infrequently used.
- inimino 7y agoThe channel only needs to be used when the automated process breaks.
- brongondwana 7y agoOh right - yeah, that sucks. Rarely used processes often break. Hence efforts like https://tools.ietf.org/html/rfc8701 https://tools.ietf.org/html/rfc8701 - designed to make sure extensibility options don't get messed up.
- ryandrake 7y agoYes, and: fix bugs so the setup doesn’t break. I’m constantly babysitting LetsEncrypt. It’s always failing in some stupid way, and all it can go is Email me with: “Ive been silently failing for the last couple of months and now your certificate is going to expire if you don’t drop everything and comb through my logs now LOL!” This time the problem was LE all of a sudden decided to start storing my certificate in a directory called mydomain.com-0001 instead of mydomain.com, breaking the rest of the setup that relies on things being in the right directory. Automation is only useful when the software behaves predictably and consistently.
- somehnguy 7y agoComforting to know I'm not the only one who constantly has random problems with Let's Encrypt. You're on point about the silently failing bit too.
- omh 7y agoLetsEncrypt issues for 3 months by default and then tries to renew after 2 months. So if renewal fails you should have ~30 days to fix it. But this does work best if your tools try the 2-month renewal. (I'm looking at you, wpengine!)
- daxelrod 7y agoWhich client are you using? Certbot?