8 ms·
Native ACME support comes to Nginx
- btreecat 1y agoCongratulations to the folks involved. I'm sure this wasn't a trivial lift. And the improvement to free security posture is a net positive for our community. I have moved most of my personal stuff to caddy, but I look forward to testing out the new release for a future project and learning about the differences in the offerings. Thanks for this!
- momo_kong 1y ago[dead]
- KyleBerezin 1y agoHey, I just decided to run a DNS server and a couple of web services on my lan from a raspberry pi over the weekend. I used Nginx for the reverse proxy so all of the services could be addressable without port numbers. It was very easy to set up, it's funny how when you learn something new, you start seeing it all over the place.
- mikestorrent 1y agoThat's a great exercise in self-hosting. Nginx is definitely everywhere - probably 95%+ of SaaS and websites you hit are running it somewhere.
- endorphine 1y agoWhat took them so long? Honest question. I'd expect nginx to have this years ago. Is that so hard to implement for some reason?
- aaronax 1y agoSlow adoption of ACME by corporate customers that pay the bills. Must be a bigger effort than one would initially think, too.
- preisschild 1y agoWhat does this offer to you vs using a tool such as certbot/cert-manager, and then just referencing the path in nginx?
- aargh_aargh 1y agoOne less program to install, configure, upgrade, watch vulnerabilities in, monitor.
- benwilber1 1y agoAll of those things also apply to this module since it's an extra module that you have to install separate. It's not included with the nginx base distribution. You have to configure it specifically, you have to monitor it. You have to upgrade and watch for vulnerabilities.
- petre 1y agoNot needing a python interprter and setting up cron jobs? The sole reason for using Caddy really, because it's just install and forget. I never had an expired certificate with it. I don't want to mess with an entirely different webserver config either after having fully configured my nginx instances. Too bad they wrote it in rust instead of C, now I need another compiler to build it. Minor nuisance. Hopefully it will get packaged.
- lysace 1y agoNginx is now owned by F5. Big, expensive and amazingly slow in terms of development. Related notice: I really enjoy using haproxy for load balancing.
- senko 1y agoLooks like haproxy also doesn't support it natively. (unless I'm googlin' it wrong - all info points to using with acme.sh)
- jsheard 1y agoSee also: nginx's HTTP/3 support still being experimental, when pretty much every other server besides Apache shipped it years ago.
- deleted 1y ago[deleted]
- everfrustrated 1y agoYes tho the odds are anybody wanting http3 likely also using a cdn. There aren't too many cdns which support http3 back to origin. Heck most of them don't even support ipv6-only origins.
- Graphon1 1y agoNo love for caddyserver?
- deleted 1y ago[deleted]
- mholt 1y agoThere was quite a bit already, about a month ago: https://news.ycombinator.com/item?id=44889941 https://news.ycombinator.com/item?id=44889941
- otterley 1y agoWe discussed this about a month ago: https://news.ycombinator.com/item?id=44889941 https://news.ycombinator.com/item?id=44889941
- petcat 1y ago> the popular open source web server NGINX announced support for ACME with their official ngx_http_acme module (implemented with memory safe Rust code!). Why even bother calling out that it's written in "memory safe Rust code" when the code itself is absolutely riddled with unsafe {} everywhere. It seems to me that it's written in memory unsafe Rust code.
- rererereferred 1y agoPeople like bragging/advertising about their language of choice. Maybe others who like the language will get interested in collaborating, or employers who need developers for that language might get in contact with them. Also, unsafe rust is still safer than C.
- pjmlp 1y agoActually it isn't, because there are a few gotchas. Unsafe Rust, like unsafe code blocks in any language that offers them, should be kept to the bare minimum, as building blocks.
- johnisgood 1y ago> Also, unsafe rust is still safer than C. I highly doubt that, and developers of Rust have confirmed here on HN that when it comes to unsafe code within a codebase, it is not just the unsafe blocks that are affected, the whole codebase is affected by that.
- vsgherzi 1y agoUnsafe rust still enforces many of rust's rules. The only powers you get with unsafe rust are de-refrencing raw pointers, calling unsafe traits / functions, and the ability to access or modify mutable statics. You can read more about this here. https://doc.rust-lang.org/nomicon/what-unsafe-does.html https://doc.rust-lang.org/nomicon/what-unsafe-does.html Unsafe rust is definitely safer than normal C. All the unsafe keyword really means is that the compiler cannot verify the behavior of the code it's up to the programmer. This is for cases where 1. the programmer knows more than the compiler 2. we're interacting with hardware or FFI. When rust developers say unsafe effects the whole codebase what they mean is that UB in unsafe code could break guarantees about the whole program (even the safe parts). Just because something is unsafe dosen't inherently mean it's going to break everything it just needs more care when writing and reviewing just as C and C++ does.
- muppetman 1y agoThis idea we seem to have moved towards where every applications ALSO includes their own ACME support really annoys me actually. I much prefer the idea that there's well written clients who's job it is to do the ACME handling. Is my Postfix mailserver soon going to have an ACME shoehorned in? I've already seen GitHub issues for AdGuardHome (a DNS server that supports blocklists) to have an ACME client built in, thankfully thus far ignored. Proxmox (a VM Hypervisor!) has an ACME Client built in. I realise of course the inclusion of an ACME client in a product doesn't mean I need to use their implementation, I'm free to keep using my own independant client. But it seems to me adding ACME clients to everything is going to cause those projects more PRs, more baggage to drag forward etc. And confusion for users as now there's multiple places they could/should be generating certificates. Anyway, grumpy old man rant over. It just seems Zawinski's Law "Every program attempts to expand until it can read mail. Those programs which cannot so expand are replaced by ones which can." can be replaced these days with MuppetMan's law of "Every program attempts to expand until it can issue ACME certificates."
- atomicnumber3 1y agoI personally think nginx is the kind of project I'd allow to have its own acme client. It's extremely extremely widely used software and I would be surprised if less than 50% of the certs LE issues are not exclusively served via nginx. Now if Jenkins adds acme support then yes I'll say maybe that one is too far.
- muppetman 1y agoBut it's a webserver. I'm sure it farms out sending emails from forms it serves, I doubt it has a PHP library built in, surely it farms that out to php-fpm? It doesn't have a REDIS library or NodeJS built in. Why's ACME different?
- tuckerman 1y agoI get what you are saying but surely obtaining a certificate is much closer to being considered a core part of a web server related to transport, especially in 2025 when browsers throw up "doesn’t support a secure connection with HTTPS" messages left and right, than those other examples. I think there is also clearly demand: caddy is very well liked and often recommended for hobbyists and I think a huge part of that is the built in certificate management.
- aakkaakk 1y agoBe aware, nginx is developed by a Russian.
- dizlexic 1y agoNOT A RUSSIAN??!?!?!?
- petcat 1y agonginx has been owned and developed by an American company for a long time...
- deleted 1y ago[deleted]
- rererereferred 1y agoI own my copy of the code.
- TiredOfLife 1y agoThe last Russian quite loudly stopped working on it and released a fork
- themafia 1y agoThe "cold war" was one of the dumbest features of our world over the past century. It's amazing to me that people are still addicted to it.
- petre 1y agoYes, I'm aware. He also had his office raided by the Kremlin's minions. https://www.themoscowtimes.com/2019/12/13/russia-nginx-fsb-raid-a68606 https://www.themoscowtimes.com/2019/12/13/russia-nginx-fsb-r...
- mark_mart 1y agoDoes this mean we don’t need to use certbot?
- jaas 1y agoIf you are using Nginx, then likely yes.
- predmijat 1y agoCurrently it supports only HTTP-01 challenges (no wildcards, must be reachable).
- mikestorrent 1y agoWhat about with e.g. internal ACME endpoints like https://developer.hashicorp.com/vault/tutorials/pki/pki-acme-caddy https://developer.hashicorp.com/vault/tutorials/pki/pki-acme...
- jedisct1 1y agoNative, but requires Rust. No, thanks.
- johnisgood 1y agoAgreed. I have had my share of compiling Rust programs, pulling in thousands of dependencies. If people think it is good practice, then well, good for them, but should not sell Rust as a safe language when it encourages such unsafe practices, especially when there are thousands of dependencies and probably all of them have their own unsafe blocks (even this ACME support does), which affect the whole codebase. I am going to keep using certbot. No reason to switch.
- vsgherzi 1y agoThis is a problem I'm pretty invested in so let's take a look. If we add the list of dependencies from the modules this is what we get anyhow = "1.0.98" base64 = "0.22.1" bytes = "1.10.1" constcat = "0.6.1" futures-channel = "0.3.31" http = "1.3.1" http-body = "1.0.1" http-body-util = "0.1.3" http-serde = "2.1.1" hyper = { version = "1.6.0", features = ["client", "http1"] } libc = "0.2.174" nginx-sys = "0.5.0-beta" ngx = { version = "0.5.0-beta", features = ["async", "serde", "std"] } openssl = { version = "0.10.73", features = ["bindgen"] } openssl-foreign-types = { package = "foreign-types", version = "0.3" } openssl-sys = { version = "0.9.109", features = ["bindgen"] } scopeguard = "1" serde = { version = "1.0.219", features = ["derive"] } serde_json = "1.0.142" siphasher = { version = "1.0.1", default-features = false } thiserror = { version = "2.0.12", default-features = false } zeroize = "1.8.1" Now vendoring and counting the lines of those we get 2,171,685 lines of rust. Now this includes the vedored packages from cargo vendor so what happens when we take just the dependecies for our OS. Vendoring for just x86 linux chops our line count to 1,220,702 not bad for just removing packages that aren't needed, but still alot. Let's actually see what's taking up all that space. 996K ./regex 1.0M ./libc/src/unix/bsd 1.0M ./serde_json 1.0M ./tokio/src/runtime 1.1M ./bindgen-0.69.5 1.1M ./tokio/tests 1.2M ./bindgen 1.2M ./openssl/src 1.4M ./rustix/src/backend 1.4M ./unicode-width/src 1.4M ./unicode-width/src/tables.rs 1.5M ./libc/src/unix/linux_like/linux 1.5M ./openssl 1.6M ./vcpkg/test-data/no-status 1.6M ./vcpkg/test-data/no-status/installed 1.6M ./vcpkg/test-data/no-status/installed/vcpkg 1.7M ./regex-syntax 1.7M ./regex-syntax/src 1.7M ./syn/src 1.9M ./libc/src/unix/linux_like 1.9M ./vcpkg/test-data/normalized/installed/vcpkg/info 2.0M ./vcpkg/test-data/normalized 2.0M ./vcpkg/test-data/normalized/installed 2.0M ./vcpkg/test-data/normalized/installed/vcpkg 2.2M ./unicode-width 2.4M ./syn 2.6M ./regex-automata/src 2.7M ./rustix/src 2.8M ./rustix 2.9M ./regex-automata 3.6M ./vcpkg/test-data 3.9M ./libc/src/unix 3.9M ./tokio/src 3.9M ./vcpkg 4.5M ./libc/src 4.6M ./libc 5.3M ./tokio 12M ./linux-raw-sys 12M ./linux-raw-sys/src Coming in at 12MB we have linux raw sys which provides bindings to the linux userspace, a pretty reasonable requirement. LibC and tokio. Since this is async Tokio is a must have and is pretty much bound to rust at this point. This project is extremely well vetted and is used in industry daily. Removing those we are left with 671,031 lines of rust Serde is a well known dependecy that allows for marshalling of data types Hyper is the curl of the rust world allowing interaction with the network I feel like this is an understandable amount of code given the complexity of what it's doing. Of course to some degree I agree with you and often worry about dependencies. I have a whole article on it here. https://vincents.dev/blog/rust-dependencies-scare-me/ https://vincents.dev/blog/rust-dependencies-scare-me/? I think I'd be more satisfied if things get "blessed" by the foundation like rustls is being. This way I know the project is not likely to die, and has the backing of the language as a whole. https://rustfoundation.org/media/rust-foundation-launches-rust-innovation-lab-with-rustls-as-inaugural-project/ https://rustfoundation.org/media/rust-foundation-launches-ru... I think we can stand to write more things on our own (sudo-rs did this) https://www.memorysafety.org/blog/reducing-dependencies-in-sudo/ https://www.memorysafety.org/blog/reducing-dependencies-in-s... But to completely ignore or not interact with the language seems like throwing the baby out with the bathwater to me
- esher 1y agoWill that make local development setup easier? Like creating some certs on the fly?
- deleted 1y ago[deleted]
- ilaksh 1y agoWhat's the easiest way to install the newest nginx in Ubuntu 24? PPA or something?
- thresh 1y agoJust use the official packages from https://nginx.org/en/linux_packages.html#Ubuntu https://nginx.org/en/linux_packages.html#Ubuntu nginx-module-acme is available there, too, so you don't need to compile it manually.
- mikestorrent 1y agoDocker container?
- ku1ik 1y agoI wish they listed Caddy before Traefik there - Caddy pioneered this hands-free certificate automation in a webserver.