3 ms·
Thanks for making it all so painless. It's so good I forget it's even there. Easily the best piece of infrastructure tech I've ever used. Also, to folks who wi
by hashhar 7y ago
Thanks for making it all so painless. It's so good I forget it's even there. Easily the best piece of infrastructure tech I've ever used.
Also, to folks who wish to "pay" for the certs, you can do so at https://letsencrypt.org/donate/ https://letsencrypt.org/donate/.
A yearly recurring donation for the avg price of an SSL cert is what I do.
- LoSboccacc 7y agowe still can't certify on an alternative port, DNS is not always an option and so there's people stuck with having to shut down servers while certbot does it's thing
- __float 7y agowhat practical situation do you encounter that DNS isn't an option? why are you shutting down servers to rotate certificates? a reload should be totally possible!
- closeparen 7y agoI think it refers to stopping the main service so that certbot can bind port 80 during the verification process.
- ohyeshedid 7y agoThe person you're responding to is asking about verification through dns, which is an option that avoids the need for http verification.
- tinus_hn 7y agocertbot can host the verification files on most webservers people would already be running (like Apache and nginx) so this isn’t necessary.
- ShakataGaNai 7y agoWell, if you're running something on a non-standard port then you could just use a tool (like certbot) on the standard ports and copy over the certificates when you're done?
- tialaramex 7y agoLet's Encrypt would be allowed by the Baseline Requirements to offer ports 22, 25 as well as 80 and 443. But realistically only port 80 makes sense for the http-01 and only port 443 makes sense for tls-alpn-01. Why would you speak HTTP on port 25? [[ Ha, they got around to removing 115 from the list at some point, that was always funny. It got on the list because port 115 is in IANA's list as SFTP, but that's because IANA thinks SFTP means "Simple File Transfer Protocol" a long obsolete protocol like TFTP whereas the SFTP we know today uses port 22 because it's just SSH ]] There's no intention to add more ports to the Authorized Ports list in the Baseline Requirements AFAIK. Control over other ports doesn't have a very strong connection to control over the whole named machine.
- lathiat 7y agoI have solved that problem by putting Nginx in front to redirect the .well-known and pass everything else through to the application.
- arendtio 7y agoDid you try something like acme-dns[1]? It is pretty universal. The installation instructions aren't the best, but it allows you to use DNS authentication without the need for a specific adapter for your DNS provider. https://github.com/joohoi/acme-dns#dns-records https://github.com/joohoi/acme-dns#dns-records
- LoSboccacc 7y ago> DNS is not always an option
- arendtio 7y agoThat is why I am suggesting acme-dns. It is different from the normal DNS option. Normally, you require an adapter for your DNS provider and for many DNS providers there are no adapters out there. But with acme-dns, you just set a static DNS entry once and host your own DNS server solely for acme-challenges. So yes, it uses the DNS protocol, but the implications are very different from the normal DNS challenge option.