!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

105 Members
Another day, another cert renewal43 Servers

Load older messages


SenderMessageTime
11 Nov 2024
@thinkchaos:matrix.orgThinkChaosAnyways the cert dir structure was different I think so would still break users19:04:52
@emilazy:matrix.orgemily
In reply to @thinkchaos:matrix.org
I took a quick look at other ACME clients listed in https://letsencrypt.org/docs/client-options/ and pretty sure I saw one could migrate Lego data but don't find it again
nothing really exists that meets requirements and is superior to lego IMO
19:04:55
@emilazy:matrix.orgemilyCaddy builds on CertMagic/ACMEZ and is a better implementation with a much better model (a proper daemon), but it doesn't quite have the shape of the thing we need19:05:18
@thinkchaos:matrix.orgThinkChaosYeah that was my conclusion from a quick look, hence the custom tool proposal :)19:05:20
@emilazy:matrix.orgemilyhttps://github.com/https-dev/docs/blob/master/acme-ops.md essential reading19:05:47
@emilazy:matrix.orgemily(primarily from the Caddy/CertMagic/ACMEZ author)19:06:00
@arianvp:matrix.orgArianMy website still runs 21.05 lol19:06:06
@emilazy:matrix.orgemily😱19:06:31
@arianvp:matrix.orgArianIf it ain't broken.... 19:06:31
@emilazy:matrix.orgemilyanything with that many CVEs is broken by definition19:06:43
@emilazy:matrix.orgemilyor at least I can break it for you if you'd like19:06:48
@arianvp:matrix.orgArianDisagree19:06:49
@arianvp:matrix.orgArianIt's just a static website if someone owns it I'll just make a new server 😂19:07:08
@arianvp:matrix.orgArianI don't have the ssh key anymore. If you are bored and wanna try to break in you have my consent 19:07:30
@emilazy:matrix.orgemilyit sounds like you need me to break in to get you your SSH key back19:08:08
@emilazy:matrix.orgemilylike smashing someone's windows to unlock the door from the inside for them19:08:19
@arianvp:matrix.orgArianNormalize machines with 10 years of uptime and some php 519:08:53
@arianvp:matrix.orgArianI need this to cope with npm version bumps during day job 19:09:18
@emilazy:matrix.orgemilythat makes me feel old because I remember PHP 4 being the hot new thing19:24:23
12 Nov 2024
@pfhuh:matrix.orgpfhuh joined the room.05:55:11
@thinkchaos:matrix.orgThinkChaosI toyed with GNU parallel to replace the locking, but it's not great to say the least. It tries to re-login as the user running it to start a daemon, and can helpfully do that over SSH for you... Doesn't work well with namespaces/locked down services. And it's Perl, so anyone using the "perlless" setup it'll cause forbidden deps issues22:51:32
@thinkchaos:matrix.orgThinkChaosAs they say, never meet your heroes, nor look at a popular program's code22:52:04
@emilazy:matrix.orgemilydid you remember to cite it?22:52:33
@thinkchaos:matrix.orgThinkChaosWhere?22:52:52
@emilazy:matrix.orgemilyit infamously nags you to cite it in academic publications if you use it. you have to promise it that you'll cite it.22:53:21
@emilazy:matrix.orgemilyhttps://git.savannah.gnu.org/cgit/parallel.git/tree/doc/citation-notice-faq.txt22:53:25
@emilazy:matrix.orgemilysome distros patch it out.22:53:30
@thinkchaos:matrix.orgThinkChaosI'm not going to make a PR with that, it's just not worth pursuing22:53:52
@thinkchaos:matrix.orgThinkChaoslol didn't know that22:53:57
@thinkchaos:matrix.orgThinkChaosI'll cite it's name in vain is what I'll do22:54:22

Show newer messages


Back to Room ListRoom Version: 6