4 ms·
Personally, I'm a fan of https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny. 200 lines of python without any additional python requiremen
by dividuum 4y ago
Personally, I'm a fan of https://github.com/diafygi/acme-tiny https://github.com/diafygi/acme-tiny. 200 lines of python without any additional python requirements and only the openssl binary as external dependency.
- frutiger 4y agoI will plug my own Python program https://github.com/frutiger/concorde https://github.com/frutiger/concorde, which does depend on `requests` and `cryptography`.
- ori_b 4y agoIf we're plugging implementations, I tend to use the single-file implementation that ships with 9front. I wrote the first cut, but it's been improved heavily by others: http://man.9front.org/8/acmed http://man.9front.org/8/acmed http://git.9front.org/plan9front/plan9front/HEAD/sys/src/cmd/auth/acmed.c/f.html http://git.9front.org/plan9front/plan9front/HEAD/sys/src/cmd... It works quite well, and if you mount your unix machines via sshfs, it's pretty easy to dump the certs into the right place with them. And unlike most ACME clients, it works seamlessly with DNS authentication, which allows you to easily grab wildcard certs.
- yonrg 4y agoThis! Thanks for also mentioning it. So plain easy and just does what I need! Thanks to the author for publishing it. I maintain my own patch, so tiny-acme supports an '--outfile' option (it originally only writes to stdout). This comes in handy when it is run by systemd service/timer. The pull request is on hold, because the code then exceeds then 200 lines threshold :shrug:
- Klasiaster 4y agoYou can directly redirect the service's output to a file: https://www.freedesktop.org/software/systemd/man/systemd.exec.html#StandardOutput= https://www.freedesktop.org/software/systemd/man/systemd.exe...
- yonrg 4y agoThanks! That's tempting to drop the patch and just stay with the upstream.