3 ms·
Question: Does anyone have a good solution for renewing letsencrypt certificates for websites hosted on multiple servers? Right now, I have one master server th
by trothamel 1y ago
Question: Does anyone have a good solution for renewing letsencrypt certificates for websites hosted on multiple servers? Right now, I have one master server that the others forward the well-known requests too, and then I copy the certificate over when I'm done, but I'm wondering if there's a better way.
- pornel 1y agoI copy the same certbot account settings and private key to all servers and they obtain the certs themselves. It is a bit funny that LetsEncrypt has non-expiring private keys for their accounts.
- nullwarp 1y agoI use DNS verification for this then the server doesn't even need to be exposed to the internet.
- magicalhippo 1y agoAnd if changing the DNS entry is problematic, for example the DNS provider used doesn't have an API, you can redirect the challenge to another (sub)domain which can be hosted by a provider that has an API. I've done this and it works very well. I had a Digital Ocean droplet so used their DNS service for the challenge domain. https://letsencrypt.org/docs/challenge-types/#dns-01-challenge https://letsencrypt.org/docs/challenge-types/#dns-01-challen...
- samgranieri 1y agoI use dns01 in my homelab with step-ca. works like a charm, and it's my private certificate authority
- deleted 1y ago[deleted]
- navigate8310 1y agoHave you tried certbot? Or if you want a turnkey solution, you may try Caddy or Traefik that have their own automated certificate generation utility.
- dboreham 1y agoDNS verification.
- bayindirh 1y agoThere's a tool called "lsyncd" which watches for a file and syncs the changed file to other servers "within seconds". I use this to sync users between small, experimental cluster nodes. Some notes I have taken: https://notes.bayindirh.io/notes/System+Administration/Syncing+Files+between+Systems+Using+lsyncd https://notes.bayindirh.io/notes/System+Administration/Synci...
- hangonhn 1y agoWe just use certbot on each server. Are you worried about the rate limit? LE rate limits based on the list of domains. So we send the request for the shared domain and the domain for each server instance. That makes each renew request unique per server for the purpose of the rate limit.
- noinsight 1y agoOrchestrate the renewal with Ansible - renew on the "master" server remotely but pull the new key material to your orchestrator and then push them to your server fleet. That's what I do. It's not "clean" or "ideal" to my tastes, but it works. It also occurred to me that there's nothing(?) preventing you from concurrently having n valid certificates for a particular hostname, so you could just enroll distinct certificates for each host. Provided the validation could be handled somehow. The other option would maybe be doing DNS-based validation from a single orchestrator and then pushing that result onto the entire fleet.
- throw0101b 1y agogetssl was written with a bit of a focus on this: > Get certificates for remote servers - The tokens used to provide validation of domain ownership, and the certificates themselves can be automatically copied to remote servers (via ssh, sftp or ftp for tokens). The script doesn't need to run on the server itself. This can be useful if you don't have access to run such scripts on the server itself, e.g. if it's a shared server. * https://github.com/srvrco/getssl https://github.com/srvrco/getssl