3 ms·
I was responding to OP regarding non-trivial, which, I dare say, your reply agrees with. I mean, geez, you've resorted to Bash in OpenBSD. The Arc Language app
by generalpass 6y ago
I was responding to OP regarding non-trivial, which, I dare say, your reply agrees with. I mean, geez, you've resorted to Bash in OpenBSD.
The Arc Language app that this forum runs on doesn't support HTTPS, so wherever the cert comes from, accessing the site is through a reverse proxy.
- hedora 6y agoWell, that was before they added acme-client, which works out of the box, more or less: https://man.openbsd.org/acme-client.1 https://man.openbsd.org/acme-client.1 I chose the bash client over the python client because I didn’t want to use pip to pull unvetted software from randos on the Internet. (Also, I hate python, and eliminating use cases for it makes me happy.) Anyway, the bash script is still quite popular, and is extremely reliable. Since I used it, they eliminated the bash dependency, and now it is unix shell compliant: https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh I would definitely use it in the future if I was configuring a Linux box to renew certificates. The breakages I encountered were all on the Let’s Encrypt side, and broke all the clients, including the official one. Anyway, it has been trivial to use Let’s Encrypt with OpenBSD for many years.
- generalpass 6y agoIn my searching, I had not come acress acme.sh and I am not aware of using acme-client for wild card certs.