!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

110 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
26 Mar 2026
@hexa:lossy.networkhexawoah17:14:46
@k900:0upti.meK900YESSSSSSSSS19:13:23
@arianvp:matrix.orgArianFinally 21:07:21
@hexa:lossy.networkhexaDNS-PERSIST-01 should land in staging end of Q1 and prod somewhere Q223:38:54
@hexa:lossy.networkhexaI expect widespread interest and will probably suggest nixos-mailserver users to use that instead of standing up nginx.23:39:30
@sandro:supersandro.deSandro 🐧nice23:42:44
@hexa:lossy.networkhexaThe setup guide has instructions to modify DNS entries already anyway.23:43:54
@hexa:lossy.networkhexaI'm just wondering what our integration will look like.23:44:08
@hexa:lossy.networkhexahttps://github.com/go-acme/lego/pull/287123:44:38
@hexa:lossy.networkhexa

Given the manual-only nature of DNS-PERSIST-01 I’ve also intentionally de-prioritized it in favor of DNS-01 when both challenge types are provided.

23:46:08
@hexa:lossy.networkhexa:think23:46:09
@hexa:lossy.networkhexaRedacted or Malformed Event23:46:15
@hexa:lossy.networkhexahttps://letsencrypt.org/2026/02/18/dns-persist-01#dns-persist-01-authorizes-persistently23:47:37
@hexa:lossy.networkhexa ok, so basically you create an account and tie the _validation-persist record to the account url 23:48:01
27 Mar 2026
@sandro:supersandro.deSandro 🐧well, for running a local Bind...00:28:37
@sandro:supersandro.deSandro 🐧add a shell script to print out the dns record that people need to set?00:28:56
@sandro:supersandro.deSandro 🐧or put it into a file like mailserver, sothat it is easy to find and copy?00:29:10
28 Mar 2026
@m1cr0man:m1cr0man.comm1cr0manhuge16:21:13
2 Apr 2026
@hexa:lossy.networkhexaright, this can simpliy the acme module a lot14:44:59
@hexa:lossy.networkhexaI have an idea how to keep it complicated though: delaying activation of a new certificate for time/condition14:45:45
@hexa:lossy.networkhexathis could allow for proper DANE support14:46:09
@hexa:lossy.networkhexa * 15:02:36
10 Apr 2026
@emilazy:matrix.orgemilyhttps://letsencrypt.org/2026/04/10/test-sites.html can we deploy this for everyone on April 1?19:00:42
@arianvp:matrix.orgArianAll the revoked certs work fine for me on chrome for android20:51:09
@arianvp:matrix.orgArianI guess it's because chrome only pushes revoked certs through updates?20:51:53
@thinkchaos:matrix.orgThinkChaos

Yeah only Firefox has good (i.e. functional) revocation support ATM thanks to the mentioned CRLite.
This blog post explains how it works nicely: https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/

You should consider using FF on Android just for extensions: it supports standard WebExts like uBlock Origin!

23:02:19
11 Apr 2026
@rasmata:matrix.org@rasmata:matrix.org joined the room.19:17:38
@rasmata:matrix.org@rasmata:matrix.org left the room.19:17:40
12 Apr 2026
@leona:leona.isleona changed their profile picture.12:15:37
13 Apr 2026
@alesya-h:nixos.devAlesya changed their display name from Alesya Huzik to Alesya.01:44:34

There are no newer messages yet.


Back to Room ListRoom Version: 6