5 ms·
Last time I checked, those wildcard LetsEncrypt certs take more work to get, like passing a DNS-based TXT record challenge. Then once you have the wildcard cert
by esbeeb 3y ago
Last time I checked, those wildcard LetsEncrypt certs take more work to get, like passing a DNS-based TXT record challenge. Then once you have the wildcard certs, they only last 3 months. Once obtained, they can manually be copied into the LAN using a tool like wormhole. There's a lot of manual steps here which are far harder than how certbot will auto-renew certs when in the cloud - usually requiring no manual intervention, once you succeed that first time.
- deleted 3y ago[deleted]
- 8organicbits 3y agoOne of my inspirations for getlocalcert is a tool to make DNS-01 easier. acme-dns let's you add a CNAME to another DNS zone, which let's you issue certificates for the former domain name using a convenient API for the latter zone. Seriously read about it, it's awesome. https://github.com/joohoi/acme-dns/ https://github.com/joohoi/acme-dns/ That tool is open source and self-hostable. getlocalcert also provides this feature, but as a hosted service. Choose the method you prefer. https://docs.getlocalcert.net/tips/validation-domain/ https://docs.getlocalcert.net/tips/validation-domain/ Once DNS-01 is easy, wildcard certs are easy. Here's the docs for setting up a wildcard cert via getlocalcert: https://docs.getlocalcert.net/acme-clients/lego/ https://docs.getlocalcert.net/acme-clients/lego/
- esbeeb 3y agoThanks for the explanations! Great links.
- bruce511 3y agoAll the steps are automatable though. I know cause I built it into my own server engine. This service looks like the same thing. I guess if you're limited to certain then you can only do what it does, but I'm guessing there's lots of alternative software that'll do the DNS challenge if you look.
- Humphrey 3y ago> Once obtained, they can manually be copied into the LAN using a tool like wormhole. We haven't needed to copy the certs around the LAN. It works fine with dev's just individually running certbot renew as needed. Yes, it tooks us a fair bit of fiddling around to work out how to do it, but final result is super simple. So I definitely would have considered a project like this in the past, but now we've got the scripts for it, it's pretty simple.