4 ms·
I deal with multiple enterprise applications where idea of scripting a renewal involves playing with scripting headless Chrome. I'm really not a fan of it but
by technion 2y ago
I deal with multiple enterprise applications where idea of scripting a renewal involves playing with scripting headless Chrome.
I'm really not a fan of it but I'm happier paying for a one year cert than doing that
- yurishimo 2y agoSorry if this is a dumb question, but why? If I'm not mistaken, Let's Encrypt supports validation via DNS now so you don't even need to have a working webserver to issue a certificate. Automating a script to perform a renewal should be much simpler than headless Chrome! If your DNS provider doesn't have an API, that seems like a separate issue but one that is well worth your organization's time if you're working in the enterprise!
- patrakov 2y agoI guess it is not about renewal but about certificate deployment.
- blipvert 2y agoYou can set up the _acme-challenge (or whatever it is)as a CNAME to point to a domain which does support an API for automating the renewal (looking in to setting this up for a bunch of domains at work)
- technion 2y agoObtaining a certificate via dns doesn't help you install it via a Web interface that takes 20+ clicks and a 15 minute reboot to apply .
- pastage 2y agoAnd open a ticket on a suppliers website, click through four pages with free text input, then send certificate via email. Lets not talk about key delivery. We will get back the admin cost and of all that in a year if we tunnel them through one of our LBs.