| 5 Mar 2022 |
m1cr0man | Okay, I have finished my essay of a comment 😅 I made some new points there | 20:35:33 |
m1cr0man | I hope it doesn't come across as me shutting down the idea btw, I'm really happy that someone is taking the time to be critical about the implementation in its current state.
I just had an idea though. What do you think of using users.users.${serviceUser}.extraGroups instead of SupplementaryGroups? That way it's easier for users to understand/see how their services can access the certs, and it avoids adding another layer to the cake of ACME permissions management. This is also what most users are going to do/doing to fix permission issues today.
| 20:44:27 |
Winter (she/her) | I have no issues with that at all! | 20:50:11 |
Winter (she/her) | I mainly brought up systemd because that's what Caddy did | 20:50:25 |
Winter (she/her) | Maybe we could switch Caddy over to that, then. | 20:50:34 |
Winter (she/her) | (Did you already propose that in the issue?) | 20:50:42 |
m1cr0man | No I will now though :) | 20:50:49 |
m1cr0man | There we go | 20:51:28 |
| 8 Mar 2022 |
| finn joined the room. | 16:06:50 |
| 30 Mar 2022 |
| Zach joined the room. | 01:30:17 |
| Zach changed their display name from zach to Zach. | 01:54:07 |
| Zach set a profile picture. | 01:54:10 |
| 12 Apr 2022 |
hexa | well, here I am and I can acknowledge that I dug myself into a hole by having a single certificate per host, where I crammed all required names into extraDomains like a moron | 00:29:38 |
hexa | because I was too lazy to repeat the dns provider config | 00:30:04 |
hexa | and of course now there is security.acme.defaults, the bad boy that is helping me out big time | 00:30:27 |
hexa | kudos! | 00:30:29 |
hexa | biggest cert has 11 SAN entries | 00:31:00 |
hexa | very flaky to renew, because validation sometimes goes wrong | 00:31:12 |
hexa | and trying 11 validations in one, boy. | 00:31:20 |
| 19 Apr 2022 |
| anthr76 joined the room. | 18:20:01 |
| 20 Apr 2022 |
| rh joined the room. | 18:59:58 |
| 21 Apr 2022 |
| An exploring bot joined the room. | 00:50:01 |
| An exploring bot left the room. | 00:50:02 |
| 23 Apr 2022 |
m1cr0man | In reply to @hexa:lossy.network and of course now there is security.acme.defaults, the bad boy that is helping me out big time :D This has really been a great value add feature. It's nice to see it getting a lot of use. | 16:46:02 |
| 27 Apr 2022 |
| anthr76 changed their profile picture. | 22:13:45 |
| 28 Apr 2022 |
| uny joined the room. | 23:41:44 |
| 4 May 2022 |
| An exploring bot joined the room. | 15:02:46 |
| An exploring bot left the room. | 15:02:47 |
| 18 May 2022 |
| Jhu joined the room. | 06:47:29 |
| 20 May 2022 |
| Rosario Pulella left the room. | 07:18:06 |