2 ms·
I use acme.sh with DNS challenges on an external machine. Then I push up (rsync) the certs and reload Nginx. Here’s a blog post https://blog.uxtly.com/isolated
by efortis 2y ago
I use acme.sh with DNS challenges on an external machine. Then I push up (rsync) the certs and reload Nginx.
Here’s a blog post
https://blog.uxtly.com/isolated-tls-certificate-creation https://blog.uxtly.com/isolated-tls-certificate-creation
- martinbaun 2y agoThanks eFortis? I guess this mainly for security and separation of concerns?
- efortis 2y agoYes, the certificate renewal and the server are more hardened this way.
- martinbaun 2y agoCool! Do you do other things to hardend the servers like Knockerd?