3 ms·
I'd start by ignoring Letsencrypt's advice to start with Certbot (which I think was used here given the description). Instead look for something like lego[1] or
by rnijveld 6y ago
I'd start by ignoring Letsencrypt's advice to start with Certbot (which I think was used here given the description). Instead look for something like lego[1] or even simpler clients, something like Acme.sh[2] or acme-tiny[3]. At least for me certbot has way to many moving parts and makes the acme protocol feel more complicated than it is.
[1]: https://github.com/go-acme/lego https://github.com/go-acme/lego
[2]: https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh
[3]: https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny
- corford 6y agoCouldn't agree more. For a person that runs/admins their own DNS and mailserver infra, I'm surprised they didn't immediately gravitate towards one of the lightweight clients. Been a while since I last needed to get involved with letsencrypt stuff but I've always used and liked: https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh Ansible's letsencrypt module was also not bad last time I used it: https://docs.ansible.com/ansible/latest/modules/acme_certificate_module.html#acme-certificate-module https://docs.ansible.com/ansible/latest/modules/acme_certifi...
- jacquesm 6y agoMailinabox comes with its own pre-installed client that apparently does not upgrade unless you upgrade the whole machine. The upgrade instructions for that particular operation start with: take a newly installed Unbuntu machine. Which isn't always an option.
- corford 6y agoRight, that makes things less fun indeed :(
- jacquesm 6y agoHaving issued the certificate manually I now have 90 days to fix this. I'm sure I'll get around to it before the end of September, but even so I am very hard at work to get a project ready for release and this ate up time that I didn't really have (and then of course I did find time to blog about it ;) ).
- gertrunde 6y agoIn the mailinabox case - I suspect this refers to the jump from v0.3x to v0.4x? Which was the point that they moved to Ubuntu 18.04, I think somewhere around the beginning of 2019? Admittedly I'm somewhat slack about maintenance on my own mailinabox system, so it took me ~12 months to get around to going through the upgrade process, which was pretty painless. It was just a case of backup/re-image/setup/restore on the same machine, took maybe an hour? (But yes, it would have been nicer to have a better rollback point than that).
- jacquesm 6y agoThat change happened about a week after I installed it the first time, just after migrating many (way too many) imap stores to it. I figured it should be good for a while at least. My mistake I guess. Or maybe two years counts as enough? Wonder what the lower border is for an operation like that.
- bigiain 6y agoOnce I'm told I need to start evaluating ad selecting alternative automation software to the one provided by the certificate provider to keep my 90 day expiry "free" certs alive - I'm just gonna tell the boss "Fuck that, lets just buy a 12 month cert again and add this onto the calendar like all the other annual updating crap we've always dealt with." I'm with the OP here. They claimed they were going to simplify and solve a problem I had "OMG, remembering to renew certs every year???". They've replaced it with a three tier set of new unknown problems that fingerpoint at each other claiming not our fault!" and potentialy explode in my face at least four times as often. Sorry, but "free" is too expensive for that.
- swinglock 6y agoDepending on what you need, yet another option is to switch to a web server handles all of this for you. Caddy comes to mind.
- maple3142 6y agoI initially used Certbot on my server, then tried to switch to acme.sh, but eventually switch back to Certbot because it is the most painless way for my setup(Debian+Nginx). The problems I have with acme.sh are mostly permission related. Also, Certbot can update nginx configs for me automatically, so I only have to copy and paste commands from official website, then everything are done.
- throw0101a 6y agoCheck out dehydrated: * https://github.com/dehydrated-io/dehydrated https://github.com/dehydrated-io/dehydrated The hook.sh allows for a lot of flexibility.
- maple3142 6y agoIt looks similar to acme.sh too, providing lightweight and flexibility. In contrast, Certbot can modify Nginx config automatically to pass verification and install certificate for me. I personally prefer tools to handle there things for me. Don't like writing script manually to achieve them.
- throw0101a 6y ago> I personally prefer tools to handle there things for me. Don't like writing script manually to achieve them. That's what configuration management (Ansible, Chef, etc) is for.
- throw0101a 6y agoSee also: * https://github.com/dehydrated-io/dehydrated https://github.com/dehydrated-io/dehydrated All you need is Bash/Zsh, OpenSSL, and cURL.
- nickjj 6y agoI've used acme-tiny for years to manage about 10 certificates and it's great for what it is. But it has 1 problem in that you can't do DNS based validation with it, which means no wildcard certs. Generally speaking I prefer DNS validation even without wildcard certs too because it means your web server only ever has to think about serving the certificates. Your web server doesn't even need to be up to do a challenge request when you use DNS challenges. I've moved onto using acme.sh and it's been very good. It supports a lot of DNS host APIs too (DigitalOcean, Cloudflare and like 50 others).
- theandrewbailey 6y agoI've been using acme.sh for years, and in that time, I've had to update it once (maybe last year) due to the move to ACMEv2. The interface stayed the same, at least as far as my use cases, but I spent an hour in the docs reading about new features. I've got a wildcard cert now! Reading Jacques' post made me wonder WTF was going on, especially "The machine that this is all running on will need a much more recent version of its OS." Oh, right, the reference ACME client written in Python.
- jniedrauer 6y agoI'm a huge fan of acme.sh. You can easily automate its use in an infrastructure pipeline, set up some simple alerts for failure cases, and then more or less forget about it.