!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

102 Members
Another day, another cert renewal41 Servers

Load older messages


SenderMessageTime
8 Jan 2022
@m1cr0man:m1cr0man.comm1cr0mannot I'm not assuming the acme group was used for the cert, even. I can imagine someone assigning a group at some stage, later needing to use the certs for another service, and assigning that new service's user to whatever group was assigned to the cert (aka, being lazy and not standardising on the acme group)16:15:59
@winterqt:nixos.devWinter (she/her)Oh, that’s… much simpler than what I was thinking.16:18:27
@winterqt:nixos.devWinter (she/her)I have absolutely no clue how I didn’t think of that 🤦‍♀️16:18:41
@winterqt:nixos.devWinter (she/her)Sorry about that16:18:49
@winterqt:nixos.devWinter (she/her)* Oh, that’s… much simpler than what I was thinking (and much more obvious).16:19:18
@winterqt:nixos.devWinter (she/her)* Sorry about that!16:19:27
@m1cr0man:m1cr0man.comm1cr0manHah no bother! 😅 I mean, it's not that simple really, there's a lot of nesting there, and a lot of background info required17:01:36
@m1cr0man:m1cr0man.comm1cr0man Winter (she/her) sorry meant to approve that earlier in the night but done now, nice job 23:04:53
@winterqt:nixos.devWinter (she/her)you did half of the work tbh, but thanks!23:05:18
9 Jan 2022
@m1cr0man:m1cr0man.comm1cr0manAaaand I'm finally using wildcard certs for my own domain, lol. It sounds kinda bad given I maintain it, but really I was maintaining a much larger system using acme + DNS challenges up until last year01:20:40
10 Jan 2022
@m1cr0man:m1cr0man.comm1cr0manwhOOOps. I was today years old when I learned that a wildcard cert would not actually cover the root of the domain :P Matrix synapse silently broke overnight, since everyone started rejecting my domain19:24:44
@winterqt:nixos.devWinter (she/her)Oh yeah I learned that too lol, I just changed to adding the wildcard to extraDomains and keeping it named the root domain19:40:37
@winterqt:nixos.devWinter (she/her)Very fun19:40:43
@hexa:lossy.networkhexa
In reply to @m1cr0man:m1cr0man.com
whOOOps. I was today years old when I learned that a wildcard cert would not actually cover the root of the domain :P Matrix synapse silently broke overnight, since everyone started rejecting my domain
you mean … the origin?
20:11:18
@hexa:lossy.networkhexafwiw, *.example.com cannot be the common name, and therefore not the only SAN20:11:41
@hexa:lossy.networkhexaso I added example.com20:11:51
@hexa:lossy.networkhexahow did you get around that limitation?20:12:01
@winterqt:nixos.devWinter (she/her)
In reply to @hexa:lossy.network
how did you get around that limitation?
are you asking about a certificate whose only domain is a wildcard?
20:13:24
@hexa:lossy.networkhexayep20:13:35
@winterqt:nixos.devWinter (she/her)i’m not sure — it just worked for me until i realized I needed to also add the root domain20:14:09
@m1cr0man:m1cr0man.comm1cr0manYeah, it just worked for me too20:14:57
@m1cr0man:m1cr0man.comm1cr0manit wasn't until I tried to browse to my root domain did I realise it wasn't working. I did the same as winter..but also the opposite :P I put my root domain in the SANs20:15:32
@hexa:lossy.networkhexasecurity.acme.certificates."*.example.com" worked for you?20:15:54
@m1cr0man:m1cr0man.comm1cr0manfwiw, this is what I've document as "the way" on the nixos manual, so I gotta fix that20:15:56
@hexa:lossy.networkhexa * security.acme.certificates."*.example.com" worked for you? 20:16:01
@m1cr0man:m1cr0man.comm1cr0manno :) I did it the way it it is in the manual20:16:08
@hexa:lossy.networkhexawho the hell reads the manual20:16:14
@m1cr0man:m1cr0man.comm1cr0manso the key is "m1cr0man.com", but I manually set the domain attr to "*.m1cr0man.com"20:16:28
@hexa:lossy.networkhexahaha okay20:16:35
@m1cr0man:m1cr0man.comm1cr0man... you know swapping the SAN and domain makes a lot of sense now winter lol20:16:39

Show newer messages


Back to Room ListRoom Version: 6