!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

109 Members
Another day, another cert renewal47 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
5 Mar 2022
@winterqt:nixos.devWinter (she/her) * so is that for if the certificate doesn't have to be renewed, but the group changed?19:53:41
@m1cr0man:m1cr0man.comm1cr0manthat description might be a bit misleading I agree. It shuold maybe indicate that group will own the certs19:53:41
@m1cr0man:m1cr0man.comm1cr0manyeah exacrly19:53:46
@winterqt:nixos.devWinter (she/her)got it19:53:48
@m1cr0man:m1cr0man.comm1cr0man * yeah exactly19:53:49
@winterqt:nixos.devWinter (she/her)

Secondly there was in the past some concern raised around granting acme group to other services because it would grant that service access to more certs than you may want. You might get some backlash in that regard. In reality, this is hard to operate around and for wildcard certs you're likely to only have 1 cert shared across multiple services anyway.

so the thing about this point is that, like, if you set a specific group for a cert (that isn't acme), then its not like granting the acme group will give you access to those...

19:54:47
@winterqt:nixos.devWinter (she/her) it'll just give the acme owned ones 19:54:55
@winterqt:nixos.devWinter (she/her)like, i get the issue in theory, and i agree with it but not practically?19:55:08

Show newer messages


Back to Room ListRoom Version: 6