3 ms·
I’m not shy to say that if acme-client can be modified to not require access to private keys at all, that would be a welcome improvement. But you described pri
by anjbe 6y ago
I’m not shy to say that if acme-client can be modified to not require access to private keys at all, that would be a welcome improvement.
But you described privilege separation as “real men programming,” and that’s off base.
I am (sincerely!) interested in what Let’s Encrypt clients you suggest that use http-01 and don’t require access to private keys.
- unilynx 6y agoI haven’t looked at the OpenBSD code but have built a system that uses a separate server to actually perform the certbot http challenge. The server needing the certificate just forwards the port 80 acme requests to the certbot server CSRs were sufficient for that, at no point was it necessary to ship private keys. And this was using just the standard ubuntu certbot for the actual requests.