!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

111 Members
Another day, another cert renewal50 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
30 Dec 2021
@m1cr0man:m1cr0man.comm1cr0man You do need to set the group explicitly when using useACMEHost. We can't assume that the cert is being used for other purposes in that scenario, thus it would be unsafe to set the group automatically 15:01:20
@m1cr0man:m1cr0man.comm1cr0man * You do need to set the group explicitly when using useACMEHost. We can't assume that the cert is being used for only ngnix/apache in that scenario, thus it would be unsafe to set the group automatically 15:01:37
@winterqt:nixos.devWinter (she/her)

Got it. I feel like that can definitely be documented better, I’ll PR if I can think of adequate wording.

Question: why can’t we assume, though? In what scenario would someone be using one certificate across multiple HTTP servers? idk, just seems unlikely, it’s definitely best not to assume but i can’t think of an actual practical use case unless I’m just missing something obvious…

20:05:16
@winterqt:nixos.devWinter (she/her)maybe something something different ports something something?20:07:50
@m1cr0man:m1cr0man.comm1cr0manone wildcard for mail and web is a use case I used to maintain for a deployment21:14:33
@m1cr0man:m1cr0man.comm1cr0manI added nginx + dovecot + postfix users to acme group21:14:56
@winterqt:nixos.devWinter (she/her)Redacted or Malformed Event23:18:59
31 Dec 2021
@m1cr0man:m1cr0man.comm1cr0manwoohoo finally nixos-unstable is updated :)13:28:55

Show newer messages


Back to Room ListRoom Version: 6