19 ms·
Nginx introduces native support for ACME protocol
- breadwinner 1y agoBut can it generate self-signed certificate for intranet use? Often on the intranet you want to encrypt traffic, to prevent casual snooping using Wireshark.
- johnisgood 1y agoFor now I will stick to what works (nginx + certbot), but I will give this a try. Anyone tried it? Caddy sounds interesting too, but I am afraid of switching because what I have works properly. :/
- roywashere 1y agoI like it!!! I am using Apache mod_md on Debian for personal project. That is working fine but when setting up a new site it somehow required two Apache restarts which is not super smooth
- KronisLV 1y agoIt's interesting that mod_md is so unknown: https://httpd.apache.org/docs/2.4/mod/mod_md.html https://httpd.apache.org/docs/2.4/mod/mod_md.html But also hey, now we have built-in ACME support in all the mainstream web servers: Nginx, Caddy and Apache2! Ofc Caddy will be the most polished, since that is one of its main selling points.
- orphea 1y agoCaddy has been great for me. I don't think you should switch if your current setup works but give it a try in a new project.
- bityard 1y agoI grew up on Apache and eventually became a wizard with its configuration and myriad options and failures modes. Later on, I got semi-comfortable with nginx which was a little simpler because it did less than Apache but you could still get a fairly complex configuration going if you're running weird legacy PHP apps for example. When I tried using Caddy with something serious for the first time, I thought I was missing something. I thought, these docs must be incomplete, there has to be more to it, how does it know to do X based on Y, this is never going to work... But it DID work. There IS almost nothing to it. You set literally the bare minimum of configuration you could possibly need, and Caddy figures out the rest and uses sane defaults. The docs are VERY good, there is a nice community around it. If I had any complaint at all, it would be that the plugin system is slightly goofy.
- dizhn 1y agoThis is pretty big. Caddy had this forever but not everybody wants to use caddy. It'll probably eat into the user share of software like Traefik.
- elashri 1y agoWhat I really like about Caddy is their better syntax. I actually use nginx (via nginx proxy manager) and Traefik but recently I did one project with Caddy and found it very nice. I might get the time to change my selfhosted setup to use Caddy in the future but probably will go with something like pangolin [1] because it provides alternative to cloudflare tunnels too. [1] https://github.com/fosrl/pangolin https://github.com/fosrl/pangolin
- kstrauser 1y agoI agree. That, and the sane defaults are almost always nearly perfect for me. Here is the entire configuration for a TLS-enabled HTTP/{1.1,2,3} static server: something.example.com { root * /var/www/something.example.com file_server } That's the whole thing. Here's the setup of a WordPress site with all the above, plus PHP, plus compression: php.example.com { root * /var/www/wordpress encode php_fastcgi unix//run/php/php-version-fpm.sock file_server } You can tune and tweak all the million other options too, of course, but you don't have to for most common use cases. It Just Works more than any similarly complex server I've ever been responsible for.
- pgug 1y agoI find the documentation for the syntax to be a bit lacking if you want to do anything that isn't very basic and how they want you to do it. For example, I want to use a wildcard certificate for my internal services to hide service names from certificate transparency logs, and I can't get the syntax working. Chatgpt and gemini also couldn't.
- cpach 1y agoThis integration doesn’t support the dns-01 challenge. So wildcard certs are out of the question at this point.
- cobbzilla 1y agoThere’s a section on renewals but no description of how it works. Is there a background thread/process? Or is it request-driven? If request-driven, what about some hostname that’s (somehow) not seen traffic in >90 days?
- adontz 1y agocertbot has an plugin for nginx, so I'm not sure why people think is was hard to use LetsEncrypt with nginx.
- orblivion 1y agoFrom a quick look it seems like a command you use to reconfigure nginx? And that's separate from auto-renewing the cert, right? Maybe not hard, but Caddy seems like even less to think about.
- orblivion 1y agoI guess I should compare to this new Nginx feature rather than Caddy. It seems like the benefit of this feature is that you don't have a tool to run, you have a config to put into place. So it's easier to deploy again if you move servers, and you don't have to think about making sure certbot is doing renewals.
- creshal 1y agoCertbot is a giant swiss army chainsaw that can do everything middlingly well, if you don't mind vibecoding your encryption intrastructure. But a clean solution it usually isn't. (That said, I'm not too thrilled by this implementation. How are renewals and revocations handled, and how can the processes be debugged? I hope the docs get updated soon.)
- jeroenhd 1y agoCertbot always worked fine for me. It autodetects just about everything and takes care of just about everything, unless you manually instruct it what to do (i.e. re-use a specific CSR) and then it does what you tell it to do. It's not exactly an Ansible/Kubernetes-ready solution, but if you use those tools you already know a tool that solves your problem anyway.
- jddj 1y agoFrom the seeming consensus I was dreading setting let's encrypt up on nginx, until I did it and it was and has been... Completely straightforward and painless. Maybe if you step off the happy path it gets hairy, but I found the default certbot flow to be easy.
- do_not_redeem 1y agoIt looks like this isn't included by default with the base nginx, but requires you to install it as a separate module. Or am I wrong? https://github.com/nginx/nginx-acme https://github.com/nginx/nginx-acme
- bhaney 1y agoNginx itself is mostly just a collection of modules, and it's up to the one building/packaging the nginx distribution to decide what goes in it. By default, nginx doesn't even build the ssl or gzip modules (though thankfully it does build the http module by default). Historically it only had static modules, which needed to be enabled or disabled at compile time, but now it has dynamic modules that can be compiled separately and loaded at runtime. Some older static modules now have the option of being built as dynamic modules, and new modules that can be written as dynamic modules generally are. A distro can choose to package a new dynamic module in their base nginx package, as a separate package, or not at all. In a typical distro, you would normally expect one or more virtual packages representing a profile (minimal, standard, full, etc) that depends on a package providing an nginx binary with every reasonable static-only module enabled, plus a number of separately packaged dynamic modules.
- timw4mail 1y agoYes, that is correct.
- Shank 1y ago> The current preview implementation supports HTTP-01 challenges to verify the client’s domain ownership. DNS-01 is probably the most impactful for users of nginx that isn't public facing (i.e., via Nginx Proxy Manager). I really want to see DNS-01 land! I've always felt that it's also one of the cleanest because it's just updating some records and doesn't need to be directly tethered to what you're hosting.
- samgranieri 1y agoI use dns01 in my homelab with step-ca with caddy. It's a joy to use
- reactordev 1y ago+1 for caddy. nginx is so 2007.
- supriyo-biswas 1y agoOnly if they'd get the K8s ingress out of the WIP phase; I can't wait to possibly get rid of the cert-manager and ingress shenanigans you get with others.
- reactordev 1y agoYup. I can’t wait for the day I can kill my caddy8s service. The best thing about caddy is the fact you can reload config, add sites, routes, without ever having to shutdown. Writing a service to keep your orchestration platform and your ingress in sync is meh. K8s has the events, DNS service has the src mesh records, you just need a way to tell caddy to send it to your backend. The feature should be done soon but they need to ensure it works across K8s flavors.
- 01HNNWZ0MV43FF 1y agoI think you can that with Nginx too, but the SWAG wrapper discourages it for some reason
- aorth 1y agoOh this is exciting! Caddy's support is very convenient and it does a lot of other stuff right out of the box which is great. One thing keeping me from switching to Caddy in my places is nginx's rate limiting and geo module.
- deleted 1y ago[deleted]
- stego-tech 1y agoThe IT Roller Coaster in two reactions: > Nginx Introduces Native Support for Acme Protocol IT: “It’s about fucking time!” > The current preview implementation supports HTTP-01 challenges to verify the client’s domain ownership. IT: “FUCK. Alright, domain registrar, mint me a new wildcard please, one of the leading web infrastructure providers still can’t do a basic LE DNS-01 pull in 2025.” Seriously. PKI in IT is a PITA and I want someone to SOLVE IT without requiring AD CAs or Yet Another Hyperspecific Appliance (YAHA). If your load balancer, proxy server, web server, or router appliance can’t mint me a basic Acme certificate via DNS-01 challenges, then you officially suck and I will throw your product out for something like Caddy the first chance I get. While we’re at it, can we also allow DNS-01 certs to be issued for intermediate authorities, allowing internally-signed certificates to be valid via said Intermediary? That’d solve like, 99% of my PKI needs in any org, ever, forever.
- 0xbadcafebee 1y ago> allowing internally-signed certificates to be valid via said Intermediary By design, nothing is allowed to delegate signing authority, because it would become an immediate compromise of everything that got delegated when your delegated authority got compromised. Since only CAs can issue certs, and CAs have to pass at least some basic security scrutiny, clients have assurance that the thing giving it a cert got said cert from a trustworthy authority. If you want a non-trustworthy authority... go with a custom CA. It's intentionally difficult to do so. > If your load balancer, proxy server, web server, or router appliance can’t mint me a basic Acme certificate via DNS-01 challenges, then you officially suck and I will throw your product out for something like Caddy the first chance I get. I mean, that's a valid ask. It will become more commonplace once some popular corporate offering includes it, and then all the competitors will adopt it so they don't leave money on the table. To get the first one to adopt it, be a whale of a customer and yell loudly that you want it, then wait 18 months.
- stego-tech 1y ago> If you want a non-trustworthy authority... go with a custom CA. It's intentionally difficult to do so. This is where I get rankled. In IT land, everything needs a valid certificate. The printer, the server, the hypervisor, the load balancer, the WAP’s UI, everything. That said, most things don’t require a publicly valid certificate. Perhaps Intermediate CA is the wrong phrase for what I’m looking for. Ideally it would be a device that does a public DNS-01 validation for a non-wildcard certificate, thus granting it legitimacy. It would then crank out certificates for internal devices only, which would be trusted via the Root CA but without requiring those devices to talk to the internet or use a wildcard certificate. In other words, some sort of marker or fingerprint that says “This is valid because I trust the root and I can validate the internal intermediary. If I cannot see the intermediary, it is not valid.” The thinking goes is that this would allow more certificates to be issued internally and easily, but without the extra layer of management involved with a fully bespoke internal CA. Would it be as secure as that? No, but it would be SMB-friendly and help improve general security hygiene instead of letting everything use HTTPS with self-signed certificate warnings or letting every device communicate to the internet for an HTTP-01 challenge. If I can get PKI to be as streamlined as the rest of my tech stack internally, and without forking over large sums for Microsoft Server licenses and CALs, I’d be a very happy dinosaur that’s a lot less worried about tracking the myriad of custom cert renewals and deployments.
- andrewmcwatters 1y agoIt seems like if you commit your NGINX config with these updates, you can have one less process to your deployment if you're doing something like: # https://certbot.eff.org/instructions?ws=other&os=ubuntufocal sudo apt-get -y install certbot # sudo certbot certonly --standalone ... # https://certbot.eff.org/docs/using.html#where-are-my-certificates # sudo chmod -R 0755 /etc/letsencrypt/{live,archive} So, unfortunately, this support still seems more involved than using certbot, but at least one less manual step is required. Example from https://github.com/andrewmcwattersandco/bootstrap-express https://github.com/andrewmcwattersandco/bootstrap-express
- thaumaturgy 1y agoGood to see this. For those that weren't aware, there's been a low-effort solution with https://github.com/dehydrated-io/dehydrated https://github.com/dehydrated-io/dehydrated, combined with a pretty simple couple of lines in your vhost config: location ^~ /.well-known/acme-challenge/ { alias <path-to-your-acme-challenge-directory>; } Dehydrated has been around for a while and is a great low-overhead option for http-01 renewal automation.
- andrewmcwatters 1y agoThis is really cool, but I find projects that have thousands of people depending on it not cutting a stable release really distasteful. Edit: Downvote me all you want, that's reality folks, if you don't release v1.0.0, the interface you consume can change without you realizing it. Don't consume major version 0 software, it'll bite you one day. Convince your maintainers to release stable cuts if they've been sitting on major version 0 for years. It's just lazy and immature practice abusing semantic versioning. Maintainers can learn and grow. It's normal. Dehydrated has been major version 0 for 7 years, it's probably past due. See also React, LÖVE, and others that made 0.n.x jumps to n.x.x. (https://0ver.org https://0ver.org) CalVer: "If both you and someone you don't know use your project seriously, then use a serious version." SemVer: "If your software is being used in production, it should probably already be 1.0.0." https://0ver.org/about.html https://0ver.org/about.html
- nothrabannosir 1y agoDistasteful by whom, the people depending on it? Surely not… the people providing free software at no charge, as is? Surely not… Maybe not distasteful by any one in particular, but just distasteful by fate or as an indicator of misaligned incentives or something?
- yjftsjthsd-h 1y ago> Distasteful by whom, the people depending on it? Surely not… Why not?
- 1y ago
- samgranieri 1y agoThis is a good first start. One less moving part. They should match caddy for feature parity on this, and also add dns01 challenges as well. I'm not using nginx these days because of this.
- ankit84 1y agoWe have been using Caddy for many years now. Picked just because it has automatic cert provisioning. Caddy is really an easier alternative, secure out of the box.
- josegonzalez 1y agoThis is great. Dokku (of which I am the maintainer) has a hokey solution for this with our letsencrypt plugin, but thats caused a slew of random issues for users. Nginx sometimes gets "stuck" reloading and then can't find the endpoint for some reason. The fewer moving knobs, the better. That said, its going to take quite some time for this to land in stable repositories for Ubuntu and Debian, and it doesn't (yet?) have DNS challenge support - meaning no wildcards - so I don't think it'll be useful for Dokku in the short-term at least.
- ctxc 1y agoHey! Great to see you here. I tried dokku (and still am!) and it is so hard getting started. For reference, - I've used Coolify successfully where it required me to create a Github app to deploy my apps on pushes to master - I've written GH actions to build and deploy containers to big cloud This page is what I get if I want to achieve the same, and it's completely a reference book approach - I feel like I'm reading an encyclopedia. https://dokku.com/docs/deployment/methods/git/#initializing-from-private-repositories https://dokku.com/docs/deployment/methods/git/#initializing-... Contrast it with this, which is INSTANTLY useful and helps me deploy apps hot off the page: https://coolify.io/docs/knowledge-base/git/github/integration https://coolify.io/docs/knowledge-base/git/github/integratio... What I would love to see for Dokku is tutorials for popular OSS apps and set-objective/get-it-done style getting started articles. I'd LOVE an article that takes me from baremetal to a reverse proxy+a few popular apps. Because the value isn't in using Dokku, it's in using Dokku to get to that state. I'm trying to use dokku for my homeserver. Ideally I want a painless, quick way to go from "hey here's a repo I like" to "deployed on my machine" with Dokku. And then once that works, peek under the hood.
- josegonzalez 1y agoWe have an official action that does exactly what you're asking for. https://github.com/dokku/github-action https://github.com/dokku/github-action
- miggy 1y agoIt seems HAProxy also added ACME/DNS-01 challenge support in haproxy-3.3-dev6 very recently. https://www.mail-archive.com/haproxy@formilux.org/msg46035.html https://www.mail-archive.com/haproxy@formilux.org/msg46035.h...
- owenthejumper 1y agoIt added ACME in 3.2, the DNS challenge is coming next: https://www.haproxy.com/blog/announcing-haproxy-3-2#acme-protocol https://www.haproxy.com/blog/announcing-haproxy-3-2#acme-pro...
- RagnarD 1y agoAfter discovering Caddy, I don't use Nginx any longer. Just a much better development experience.
- andrewstuart 1y agoIt was this that sent me from nginx to caddy. But I’m not going back. Nginx was a real pain to configure with so many puzzles and surprises and foot guns.
- tialaramex 1y agoIt's good to see this, it surprised me that this didn't happen to basically everything, basically immediately. I figured either somehow Let's Encrypt doesn't work out, or, everybody bakes in ACME within 2-3 years. The idea that you can buy software in 2025 which has TLS encryption but expects you to go sort out the certificate. It's like if cars had to be refuelled periodically by taking them to a weird dedicated building which is not useful to anything else rather than just charging while you're asleep like a phone and... yeah you know what I get it now. You people are weird.
- deleted 1y ago[deleted]
- zaik 1y agoIs there a way to notify other services, if renewal has succeed? My XMPP server also needs to use the certificate.
- smarx007 1y agoWhen will this land in mainline distros (no PPAs etc)? Given that a new stable version of Debian was released very recently, I would imagine August 2027 for Debian and maybe April 2026 for Ubuntu? In this very thread some people complain that certbot uses snap for distribution. Imagine making a feature release and having to wait 1-2 years until your users will get it on a broad scale.
- Saris 1y agoI assume they're complaining that it's a snap vs flatpak, not so much vs the distro package repos.
- giancarlostoro 1y agoNginx maintains their own repository from which you can install nginx on your Ubuntu / Debian systems. I looked at Arch and they're a version behind, which surprised me. Must not be a heavily maintained arch package.
- jonnybarnes 1y agonginx has a stable release and a mainline release, which are packaged in Arch respectively as `nginx` and `nginx-mainline`. Both look up-to-date to me.
- thway15269037 1y agoDoes nginx still lock prometheus metrics and active probing behind $$$$$ (literal hundreds of thousands)? Forgot third most important thing. I think is was re-resolving upstreams. Anyway, good luck staying competitive lol. Almost everyone I knew either jumped to something more saner or in process of migrating away.
- aoe6721 1y agoIt was introduced long time ago in Angie fork with much better support.
- cnst 1y agoHere's the docs for the Angie's version of the http_acme module: https://en.angie.software/angie/docs/configuration/modules/http/http_acme/ https://en.angie.software/angie/docs/configuration/modules/h... The original announcement of Angie ACME: Angie, fork of Nginx, supports ACME - https://news.ycombinator.com/item?id=39838228 https://news.ycombinator.com/item?id=39838228 - March 27, 2024 (1 comment) Per above, it looks like ACME support was released with Angie 1.5.0 on 2024-03-27. BTW, if you don't care about ACME, and want the original nginx, then there's also the freenginx fork, too: Freenginx: Core Nginx developer announces fork - https://news.ycombinator.com/item?id=39373327 https://news.ycombinator.com/item?id=39373327 - (1131 points) - Feb 14, 2024 (475 comments)
- ugh123 1y agoHow does something like this work for a fleet of edge services, load balancing in distinct areas, but all share a certificate. Does each nginx instance go through the same protocol/setup steps?
- philsnow 1y agoYou'd get rate limited pretty hard by Let's Encrypt, but if you're rolling your own acme servers you could do it this way. If you wanted to use LE though, you could use a more "traditional" cert renewal process somewhere out-of-band, and then provision the resulting keys/certs through whatever coordination thing you contrive (and HUP the nginxs)
- placatedmayhem 1y agoThey don't need to share a single cert. Multiple certificates can be, and possibly should, issued for the same address (or set of addresses). This means that one front door server that gets popped doesn't expose all connections to the larger service. Downside is obviously certificate maintenance increases, but ACME automated the vast majority of that work away.
- burnt-resistor 1y agoYeah, I don't want my webserver to turn into systemd and changing certificates. This is excessive functionality for something that should be handled elsewhere and drive the coordination of rolling certs.
- ilaksh 1y agoJust to check, this means we can use some extra lines in the nginx configuration as an alternative to installing and running certbot, right? Also does it make it easier for there to be alternatives to Let's Encrypt?
- pointlessone 1y agoYes, a few lines in the config and you don’t need certbot any more. You can specify any ACME API base URL. It’s not just Let’s Encrypt.
- ExoticPearTree 1y agoIt is a start. Maybe this will serve as a proof of concept that it can be done and then other protocols could be implemented. Probably like many others here, I would very much like to see Cloudflare DNS support.
- idoubtit 1y agoA little mistake with this release: they packaged the ngx_http_acme_module for many Linux distributions, but "forgot" Debian stable. Oldstable and oldoldstable are listed in https://nginx.org/en/linux_packages.html https://nginx.org/en/linux_packages.html (packages built today) but Debian 13 Trixie (released 4 days ago) is not there.
- triknomeister 1y agoThat's Debian's fault I guess
- sjmulder 1y agoHow is that? These are vendor packages
- thresh 1y agoI'm currently working on getting the Trixie packages uploaded. It'll be there this week. As you've said Debian 13 was released 4 days ago - it takes some time to spin up the infrastructure for a new OS (and we've been busy with other tasks, like getting nginx-acme and 1.29.1 out). (I work for F5)
- metafunctor 1y agoI never saw it as a problem for nginx to just serve web content and let certbot handle cert renewals. Whatever happened to doing one thing well and making it composable? Fat tools that try to do everything inevitably suck at some important part.
- SchemaLoad 1y agoIt's kind of annoying to set up. Last I remember certbot could try to automatically configure things for you but unless you had the most default setup it wouldn't work. Just having Nginx do everything for you seems like a better solution.
- account42 1y agoCertbot can just as easily work with a directory you have nginx set up to point .well-known/acme-challenge/ to. No automatic configuration magic needed.
- idoubtit 1y agoThis optional module makes simple cases simpler. Having distinct tools for serving content and handling certs is not a problem, and nothing changes on this side. Moreover, the module won't cover every need. BTW, cerbot is rather a "fat tool" compared to other acme tools like lego. I've had bad experiences with certbot in the past because it tried to do too much automatically and it's hard to diagnose – though I think certbot has been rewritten since then, since it has no more dependency on python zope.
- pointlessone 1y agoNginx with certbot is annoying to setup. Especially with HTTP challenge. Mostly because of a circular dependency. You need nginx to clear the challenge and once verboten gets a cert you need to reload nginx. I switched to Lego because it has out of the box support for my domain registrar so I could use DNS instead of HTTP challenge. It’s also a single go binary which is much simpler to install than certbot.
- 1y ago
- arjie 1y agoNeat, that'll be nice to have. Currently I just use certbot and it does a pretty damn good job. I just set the HTTP:80 configuration and certbot will migrate it to HTTPS:443 and take care of the certificates and so on. For the moment, I'll probably stick to that till this is mature.
- drchaim 1y agoI’ve already migrated to caddy ;)
- kocial 1y agoThe problem with the big open-source companies is that they are always very late to understand and implement the most basic innovations that come out. Caddy & Traefik did it long, long ago (half a decade ago), and after half a decade, we finally have ngxin supporting it too. Great move though, finally I won't have to manually run certbot :pray:
- winter_blue 1y agoCaddy did it almost a decade ago. IIRC it had some form of automatic Let’s Encrypt HTTPS back in 2016. So Nginx is just about 9 to 10 years late. Lol
- mholt 1y ago2015 in fact. A decade ago.
- squigz 1y agoAnd the brilliant thing about open source projects is that if someone felt it was so important to have it built-in, they could have done so many years ago.
- stephenr 1y agoGiven that Caddy has a history that includes choices like "refuse to start if LE cannot be contacted while a valid certificate exists on disk" I'm pretty happy to keep my certificate issuance separate from a web server. I need a tool to issue certs for a bunch of other services anyway, I don't really see how it became such a thing for people to want it embedded in their web server.
- francislavoie 1y agoAs we repeat every time this comes up, this was literally 8 years ago when the project was in its infancy and the project author was in the middle of exams, and it has not been true since. Caddy has been rewritten from the ground up since then, and comparing it to those old versions is dishonest.
- st3fan 1y agoBasically the only reason I install Caddy instead of Nginx as a reverse proxy is the one-liner to get TLS & ACME going. Maybe this will change that? Not sure.
- vivzkestrel 1y agoNot gonna lie, setting up Nginx, Certbot inside docker is the biggest PITA ever. you need certificates to start the NGINX server but you need the NGINX server to issue certificates? see the problem? It is made infinitely worse by a tonne of online solutions and blog posts none of which I could ever get to work. I would really appreciate if someone has documented this extensively for docker compose. I dont want to use libraries like nginx-proxy as customizing that library is another nightmare alltogether
- atomicnumber3 1y agoI personally just terminate TLS at nginx, run nginx directly on the metal, and all the services are containerized behind it. I suspect if I had nginx then proxying to remote nodes I'd probably just use an internal PKI for that.
- mythz 1y agoWhat's the issue with nginx-proxy? We've used it for years to handle CI deploying multiple multiple Docker compose Apps to the same server [1] without issue, with a more detailed writeup at [2]. This served us well for many years before migrating to use Kamal [3] for its improved remote management features. [1] https://docs.servicestack.net/ssh-docker-compose-deploment https://docs.servicestack.net/ssh-docker-compose-deploment [2] https://servicestack.net/posts/kubernetes_not_required https://servicestack.net/posts/kubernetes_not_required [3] https://docs.servicestack.net/kamal-deploy https://docs.servicestack.net/kamal-deploy
- vivzkestrel 1y agothe issue with nginx proxy is that i am not in control of the nginx script https://github.com/nginx-proxy/nginx-proxy/discussions/2523 https://github.com/nginx-proxy/nginx-proxy/discussions/2523
- vivzkestrel 1y agoi can write a simple rate limit block easily in raw nginx config but look at this mess when using nginx-proxy https://github.com/nginx-proxy/nginx-proxy/discussions/2524 https://github.com/nginx-proxy/nginx-proxy/discussions/2524
- themafia 1y agoWe had about 100 domains or so that needed to be redirected to their new homes. The previous person in my position set it all up using GoDaddy domains and redirects. I was gobsmacked at how much effort it took, and when browsers switched to HTTPS first, how badly it broke the setup. That's when I found "golang.org/x/crypto/acme/autocert" and then I built a custom redirect server using it. It implements TLS-ALPN-01 which works fantastically with Let's Encrypt. Now we can just add a domain to our web configuration, setup it's target and redirect style, and then push the configuration out the EC2 instance providing the public facing service. As soon as the first client makes a request, they're effectively put "on hold," while the server then arranges for the certificate in the background. As soon as it's issued and installed on the server the server continues with the original client. It's an absolute breeze and it makes me utterly detest going backwards to DNS-01 or HTTP-01 challenges.
- makaking 1y agoThe fact that certificate management is still evolving makes me realize how young the web still is in the big scheme of things.
- Humphrey 1y agoAnybody know how this would work for multiple nginx backends or failover machines - as I assume it's only possible to auto-fetch certificates for the live machine. Is it expected that you would use scp or similar to copy certs from the live machine to the failover / new server?
- pointlessone 1y agoYou don’t need exactly the same cert for failover. You only need a valid certificate. You don’t even need the same cert for every entry in your load balancer. Client will pick a single IP address when resolved, then connect to it and will keep using that TLS connection for the whole session.
- account42 1y agoBut you do need Let's Encrypt (or whatever ACME provider you use) to connect to the same server you are trying to set up the cert on. And they intentionally try to fetch the challenge response from multiple geographically distinct locations.
- account42 1y ago> Support for other challenges (TLS-ALPN, DNS -01) is planned in future. Looking forward to this. HTTP-01 already works well enough for me with certbot (which I need for other services anyway and gives me more control over having multiple domains in one cert) but for wildcard certs there are not as many good solutions.
- kelvinjps10 1y agoActually this was the reason I started using caddy, and easier config too!
- Arch-TK 1y agokind of feels unnecessary honestly... Automating webroot is trivial and I would rather use an external rust utility to handle it than a module for nginx. I guess if you _only_ need certs for your website then this helps but I have certs for a lot of other things too, so I need an external utility anyway. And no dns-01 support yet.
- cpach 1y agoI have no use for this either, but I’m sure a lot of people will enjoy not having to install a separate ACME client.
- crest 1y agoFINALLY!!!
- blessedcavapoo1 1y ago[dead]
- CannoloBlahnik 1y agoOnce Nginx gets support for DNS-01, does that mean we'll be able to use wildcards for SSL using Let's Encrypt?
- cpach 1y agoYes. If you need it earlier you will have to use a separate ACME client.
- jedisct1 1y agoYikes, why introduce a dependency on Rust just for that?
- bestspharma 1y ago[dead]