!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

103 Members
Another day, another cert renewal42 Servers

Load older messages


SenderMessageTime
6 Oct 2021
@rosariopulella:matrix.orgRosario Pulella changed their display name from Rosuavio to Rosario Pulella.10:44:57
@m1cr0man:m1cr0man.comm1cr0manHey folks 👋 been a while since I've been on Matrix 😅 How are things? Seeing the news about the acme root cert stuff last week, it was nice to know that our module was not going to result in any issues 💪 😉20:21:14
@hexa:lossy.networkhexayeah, the module is really awesome, and we are iterating in small steps on it to make it even better!20:47:23
@hexa:lossy.networkhexatwo things on the 21.11 agenda20:47:33
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/139311 (hardening fix) https://github.com/NixOS/nixpkgs/pull/140743 (design) https://github.com/NixOS/nixpkgs/pull/125256 (stale) https://github.com/NixOS/nixpkgs/pull/140479 (merged)20:48:43
12 Oct 2021
@grahamc:nixos.org@grahamc:nixos.orgI don't suppose our module supports DNS01 challenges?15:01:20
@grahamc:nixos.org@grahamc:nixos.org security.acme.certs.<name>.dnsProvider hmm it seems to... time to read the module 15:02:12
@grahamc:nixos.org@grahamc:nixos.orghot dog https://github.com/NixOS/nixpkgs/blob/nixos-21.05/nixos/modules/security/acme.nix#L125-L13115:02:35
@grahamc:nixos.org@grahamc:nixos.orgthis is so much easier than it used to be 15:03:22
@hexa:lossy.networkhexasince 20.09 😁15:06:09
@arianvp:matrix.orgArianYou're welcome!15:11:05
16 Oct 2021
@hexa:lossy.networkhexa m1cr0man: need feedback here https://github.com/NixOS/nixpkgs/pull/139311 15:59:03
25 Oct 2021
@m1cr0man:m1cr0man.comm1cr0manHehe my own certs were broke :P I think some part of the certhash logic failed.. might need to investigate that. I'm not quick to blame the service though because I (naturally) mess around with it so much18:54:27
@m1cr0man:m1cr0man.comm1cr0manSorry I was AWOL I've been very busy18:54:40
@haugh:matrix.orghaugh changed their profile picture.23:04:28
26 Oct 2021
@grahamc:nixos.org@grahamc:nixos.orgchanged room power levels.01:18:33
@mjolnir:nixos.orgNixOS Moderation Bot changed their display name from mjolnir to NixOS Moderation Bot.02:00:18
@mjolnir:nixos.orgNixOS Moderation Bot set a profile picture.02:00:35
@mjolnir:nixos.orgNixOS Moderation Bot changed their profile picture.02:23:50
@mjolnir:nixos.orgNixOS Moderation Bot changed their profile picture.02:33:19
6 Nov 2021
@test:boba.bestTseb joined the room.09:19:26
@test:boba.bestTseb left the room.09:25:07
9 Nov 2021
@haugh:matrix.orghaugh left the room.20:10:47
11 Nov 2021
@mobyturbo:matrix.orgEdLin joined the room.07:46:23
@mobyturbo:matrix.orgEdLin left the room.08:03:18
16 Nov 2021
@moritz.hedtke:matrix.orgmoritz.hedtke joined the room.10:48:54
20 Nov 2021
@nykw:tchncs.denykw joined the room.11:10:15
23 Nov 2021
@server_stats:nordgedanken.devServer Stats Discoverer (traveler bot) left the room.02:35:48
24 Nov 2021
@m1cr0man:m1cr0man.comm1cr0manJust looking through github for acme-related work. I found this old PR: https://github.com/NixOS/nixpkgs/pull/46379 about letting useAcmeHost=true vhosts add their aliases to the acme cert automatically. I'm actually against this idea - the main use case nowadays for useAcmeHost is specifying a wildcard cert to use with a bunch of stuff, and that would generally be a better idea than having a cert with lots of subject alternate names. Fwiw, if you just enableACME on a vhost we already do build a cert that includes serverAliases in extraDomains (see https://github.com/NixOS/nixpkgs/blob/c18638dc95216b1b2930d16e1334613d82d05e8e/nixos/modules/services/web-servers/nginx/default.nix#L935)21:37:23
@hexa:lossy.networkhexa m1cr0man: can i pm you to look at an acme issue? 22:04:31

Show newer messages


Back to Room ListRoom Version: 6