!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

104 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
22 Dec 2022
@raitobezarius:matrix.orgraitobezariuswith pleasure04:15:18
@raitobezarius:matrix.orgraitobezariusthanks for all the amazing work on ACME ;)04:15:28
24 Dec 2022
@k900:0upti.meK900 ⚡️https://hydra.nixos.org/build/202864292/nixlog/507:51:42
@k900:0upti.meK900 ⚡️It broke again :(07:51:47
@raitobezarius:matrix.orgraitobezarius
In reply to @k900:0upti.me
https://hydra.nixos.org/build/202864292/nixlog/5
did it?
20:29:55
@hexa:lossy.networkhexaProbably fine after restart21:11:52
25 Dec 2022
@ahsmha:matrix.orgahmed left the room.10:34:49
26 Dec 2022
@m1cr0man:m1cr0man.comm1cr0manHuh I think my Matrix client was broke, those messages from Saturday just appeared.14:17:22
31 Dec 2022
@hexa:lossy.networkhexa😲19:49:12
1 Jan 2023
@v0id:nltrix.netv0|d left the room.12:05:26
11 Jan 2023
@hexa:lossy.networkhexaso I had to restore a host yesterday and I could've restored the certificates from a backup, but didn't15:55:52
@hexa:lossy.networkhexathe acme module recreated all certs no problemo15:56:04
@hexa:lossy.networkhexaon the first try15:56:08
@hexa:lossy.networkhexamind you, the host has 10 different ones 🙂15:56:25
@hexa:lossy.networkhexa🙏15:56:38
@arianvp:matrix.orgArianyay15:56:47
@hexa:lossy.networkhexaour ACME story is truly great15:57:10
12 Jan 2023
@raitobezarius:matrix.orgraitobezariusI also had situations like this and really it's pure joy10:22:48
13 Jan 2023
@m1cr0man:m1cr0man.comm1cr0manHeh so, the reason I took developing of the wildcard cert support years ago was because I was deploying about 30 domains to a couple of servers, one of which had a subdomain per user (it was for a network society). All I know is, when I check those domains 4 years (holy shit time flies) later, they still work ;) 18:46:03
@m1cr0man:m1cr0man.comm1cr0man
In reply to @hexa:lossy.network
mind you, the host has 10 different ones 🙂
Btw this is why we implemented credential sharing across multiple instances of the renewal service. There's a 5 accounts per day rate limit
20:08:49
@m1cr0man:m1cr0man.comm1cr0manwhen I get some motivation I really want to port some of the features of the renewal script directly to lego. There's stuff in there that would be genuinely easier in the tool itself20:09:21
@hexa:lossy.networkhexagood luck with that20:10:12
@hexa:lossy.networkhexalast time we wanted an offline solution for the expiry check the upstream wasn't very forthcoming20:10:29
@m1cr0man:m1cr0man.comm1cr0manwell, we had a bit of a falling out XD I think it would require the work to be done by us. We must be one of lego's largest users though21:45:40
14 Jan 2023
@andreas.schraegle:helsinki-systems.deAndreas SchrägleWhy did we decide for lego btw, instead of any of the other clients? I know we used to use a different one, but I've never really looked into acme clients much.14:28:08
@hexa:lossy.networkhexa we used simp_le before 15:31:18
@hexa:lossy.networkhexaI think it couldn't do DNS0115:31:23
@hexa:lossy.networkhexahttps://web.archive.org/web/20180603040716/https://github.com/NixOS/nixpkgs/issues/3494115:37:25
@hexa:lossy.networkhexathis the original discussion, started by volth and since deleted … thanks github15:37:36
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/7757815:39:52

Show newer messages


Back to Room ListRoom Version: 6