5 ms·
You can use Caddy to automatically fetch certs and keep them renewed without much hassle[0]. Disclaimer: I'm affiliated with Caddy [0]: https://caddy.communit
by m_sahaf 4y ago
You can use Caddy to automatically fetch certs and keep them renewed without much hassle[0].
Disclaimer: I'm affiliated with Caddy
[0]: https://caddy.community/t/using-caddy-to-keep-certificates-renewed/7525 https://caddy.community/t/using-caddy-to-keep-certificates-r...
- MatthiasPortzel 4y agoApache also provides a 1-at party ACME client in the form of a module, mod_md.
- mccorrinall 4y agoNot affiliated with caddy, but caddy is awesome! I use it all the time.
- qbasic_forever 4y agoYeah IMHO this is the way to go. Individual web apps managing their own SSL certs is a longterm mess. Only your proxy or HTTP gateway/router should ever touch or know about SSL certs.
- lapser 4y agoCaddy is great for web servers, but it's still not possible to have it run commands post certificate provisioning. So it's kind of a non-starter for anything but web-servers as there is no way to tell a different system to reload certs.
- francislavoie 4y agoWe're working on this! Hoping to have our new event dispatching system ready in the next few months. This'll let you hook into the post-issuance event and do whatever you want afterwards.
- lapser 4y agoYeah! I saw the PR. Looking forward!
- goodpoint 4y agoI'd rater use Nginx. At least it's not a statically linked blob.
- francislavoie 4y agoStatic linking is a huge advantage. I don't understand the point you're trying to make.