3 ms·
Personally, yes? I'd had it silently fail for a few weeks (I misconfigured the expiration alerts somewhere, or maybe the mailer daemon wasn't set up right on th
by technobabbler 5y ago
Personally, yes? I'd had it silently fail for a few weeks (I misconfigured the expiration alerts somewhere, or maybe the mailer daemon wasn't set up right on that particular vhost, or some package it relied on failed, and it couldn't renew for several weeks but I didn't hear about it until the cert expired and the page failed). On more than one occasion it was an issue.
And when you need wildcards, it gets even more complicated.
Obviously I'm not a very good sysadmin, but that's the point... I don't want to be and don't need to be, not when someone else can do it better and faster.
It's not an ideological thing, just a personal preference for making user-facing features as opposed to tinkering with the backend. Some people enjoy that sort of work. But users don't see it or care about it unless it breaks, which it often does in my experience as a mediocre full-stack dev with increasingly front-end leanings.
Edit: And on newer-generation serverless/Jamstack hosts (Cloudflare, Vercel, Netlify, etc.) you might never even get a shell to tinker with Certbot on. Which is arguably a good thing, especially compared to the bad old days of having to quadruple-configure HTTPS across your CDN, Varnish, Nginx/Apache, Certbot, and maybe cPanel or similar too. Yikes. Every single part of the intermediary chain was prone to frequent breakage. HTTPS these days isn't for authentication anyway, just for preventing drive-by MITM. Even EV certs aren't a good guarantee. So why do it yourself?
- rahimnathwani 5y agoThat's an understandable perspective. But if someone can't reliably self-host HTTPS with certbot, I'd advise them not to self-host anything, as they likely don't have sufficient sysadmin skill to keep their servers safe. Just use Heroku, Netlify etc.
- technobabbler 5y agoYeah, exactly. I am so grateful hosts like that exist :)