4 ms·
> "HTTPS is difficult to set up and maintain." > It just works if Caddy is your web server. I wonder what percentage of people who thinks HTTPS is difficult t
by RKearney 5y ago
> "HTTPS is difficult to set up and maintain."
> It just works if Caddy is your web server.
I wonder what percentage of people who thinks HTTPS is difficult to set up and maintain are able to run their own VPS and properly install and configure caddy.
- floatboth 5y agoIf you're not running your own VPS, HTTPS should already be handled for you by your hosting provider?
- KennyBlanken 5y agoFor most web hosting providers, enabling HTTPS is a button click, if not enabled by default, thanks to ACME and LetsEncrypt et al.
- ipaddr 5y agoLetsencrypt is a godsend compared to what we had before. But it can be difficult depending on what you run and after a few hundred domains things pile up. You just purchase a domain. You decide to host on apache. You first have to setup http get the letsencrypt to perform the challenge. Once that's done you can install ssl. The letsencrypt auto renewer is great until you run a version of linux unsupported. The extra cost per request does add up as well. The cost to support ssl isn't free but the certificate is and pretty seemless all things considered
- francislavoie 5y agoCaddy replaces both Apache and certbot (or whatever ACME client you picked), and runs on any platform Go can compile for (because it's pure-Go).
- MatthiasPortzel 5y agoI've had issues with certbot in the past as well. Modern versions of Apache have mod_md[0], which implements AMCE, replacing certbot. Configuration looks like adding 2 lines to your Apache configuration file. [0]: https://httpd.apache.org/docs/trunk/mod/mod_md.html https://httpd.apache.org/docs/trunk/mod/mod_md.html
- throw0101a 5y ago> The letsencrypt auto renewer is great until you run a version of linux unsupported. Consider using an ACME client written in shell: * https://github.com/dehydrated-io/dehydrated https://github.com/dehydrated-io/dehydrated * https://github.com/acmesh-official/acme.sh https://github.com/acmesh-official/acme.sh There's a minor change for the pre/post-scripts to restart your web server, and telling the web server where "/.well-known/acme-challenge/" should be served from, e.g.,: * https://salsa.debian.org/letsencrypt-team/dehydrated/-/blob/debian/master/debian/dehydrated.conf https://salsa.debian.org/letsencrypt-team/dehydrated/-/blob/... But otherwise I find there are a lot fewer moving parts (and dependencies) than ACME clients written in other languages.
- solarkraft 5y agoMust be a lot! I'm definitely one of them. Even the allegedly simplest to configure server behind Caddy (Traefik) makes https unnecessarily hard to configure. Caddy is the long-missing counterpart to Let's encrypt.
- jeppesen-io 5y agoClose to zero