3 ms·
As already noted on this thread, you can't use certbot today to get an IP address certificate. You can use lego [1], but figuring out the exact command line too
by ivanr 9mo ago
As already noted on this thread, you can't use certbot today to get an IP address certificate. You can use lego [1], but figuring out the exact command line took me some effort yesterday. Here's what worked for me:
lego --domains 206.189.27.68 --accept-tos --http --disable-cn run --profile shortlived
[1] https://go-acme.github.io/lego/ https://go-acme.github.io/lego/
- Svoka 9mo agoI wonder if the support made it to Caddy yet (seems to be WIP https://github.com/caddyserver/caddy/issues/7399 https://github.com/caddyserver/caddy/issues/7399)
- deleted 9mo ago[deleted]
- btown 9mo agoWork for this in Certbot is ongoing here, with some initial work already merged, but much to go. https://github.com/certbot/certbot/issues/10346 https://github.com/certbot/certbot/issues/10346 https://github.com/certbot/certbot/pull/10370 https://github.com/certbot/certbot/pull/10370 showed that a proof of concept is viable with relatively few changes, though it was vibe coded and abandoned (but at least the submitter did so in good faith and collaboratively) :/ Change management and backwards compatibility seem to be the main considerations at the moment.
- certchecksh 9mo agoThank you for posting the lego command! It allowed me to quickly obtain a couple of IP certificates to test with. I updated my simple TLS certificate checker (https://certcheck.sh https://certcheck.sh) to support checking IP certificates (IPv4 only for now).
- AI-love 9mo ago[dead]