6 ms·
Indeed. As I understand it, *BSD users are currently left out of wildcard certs from Let's Encrypt. HN runs behind an nginx proxy because the forum software doe
by generalpass 6y ago
Indeed. As I understand it, *BSD users are currently left out of wildcard certs from Let's Encrypt. HN runs behind an nginx proxy because the forum software doesn't support HTTPS.
- cpach 6y agoWhat is the issue with *BSD and LE wildcard certs? Would be interesting to hear more about that.
- generalpass 6y agohttps://certbot.eff.org/lets-encrypt/opbsd6-other https://certbot.eff.org/lets-encrypt/opbsd6-other
- cpach 6y agoCertbot is just one of many ACME clients. AFAICT acme.sh can do wildcard certs, and it’s not dependent on Bash. https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh
- anthk 6y agoWhat? OpenBSD works just fine.
- hedora 6y agoThere are a few certbot clients for openbsd, at least. I’m using one that was written in bash with httpd, and I think they added a new one to the base image. Using the script was a bit annoying because I had to install bash from ports. As on my Linux and Synology machines, the bash script has broken once or twice because it’s against modern best practices to define and stick with stable protocols. Sometimes I think it would be easier to rewind to the 90’s web and build a sane ecosystem on top of that. Every aspect of the web that I interact with has gotten worse in the last decade. (Also, HN’s is using a non-wildcard cert from digicert, at least according to my web browser).
- generalpass 6y agoI was responding to OP regarding non-trivial, which, I dare say, your reply agrees with. I mean, geez, you've resorted to Bash in OpenBSD. The Arc Language app that this forum runs on doesn't support HTTPS, so wherever the cert comes from, accessing the site is through a reverse proxy.
- hedora 6y agoWell, that was before they added acme-client, which works out of the box, more or less: https://man.openbsd.org/acme-client.1 https://man.openbsd.org/acme-client.1 I chose the bash client over the python client because I didn’t want to use pip to pull unvetted software from randos on the Internet. (Also, I hate python, and eliminating use cases for it makes me happy.) Anyway, the bash script is still quite popular, and is extremely reliable. Since I used it, they eliminated the bash dependency, and now it is unix shell compliant: https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh I would definitely use it in the future if I was configuring a Linux box to renew certificates. The breakages I encountered were all on the Let’s Encrypt side, and broke all the clients, including the official one. Anyway, it has been trivial to use Let’s Encrypt with OpenBSD for many years.
- generalpass 6y agoIn my searching, I had not come acress acme.sh and I am not aware of using acme-client for wild card certs.