!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

106 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
19 Jun 2021
@m1cr0man:m1cr0man.comm1cr0man
In reply to @aaron:fosslib.net
hahaha let me know if you come up with a solid answer
i want to write a PR which hacks up the service which is causing the reloads, but I'll need to make sure what the intended behavior is first
I haven't come up with any good reason for httpd-config-reload to run on every rebuild. However, note that it is an almost direct clone of nginx-config-reload, which probably suffers the same problem
14:38:27
@aaron:fosslib.netaaron m1cr0man: ok thanks! 14:39:23
@m1cr0man:m1cr0man.comm1cr0manhttps://github.com/NixOS/nixpkgs/pull/123258 and https://github.com/NixOS/nixpkgs/pull/121750 are still not merged ;) Anyone else had a chance to review them? I've had them running on my server for quite some time no issues14:44:08
26 Jun 2021
@grahamc:nixos.org@grahamc:nixos.orgchanged room power levels.01:10:10
28 Jun 2021
@haugh:matrix.orghaugh joined the room.01:46:46
29 Jun 2021
@robin.gloster:matrix.mayflower.deglobin joined the room.15:44:43
2 Jul 2021
@obfusk:matrix.org幸猫 joined the room.16:07:48
@immae:matrix.orgimmae changed their display name from immae (he/him) to immae.17:45:50
@immae:matrix.orgimmae changed their profile picture.17:46:13
@immae:matrix.orgimmae changed their profile picture.17:47:51
@obfusk:matrix.org幸猫 left the room.18:35:56
@irenes:matrix.orgIrenes joined the room.21:37:45
@immae:matrix.orgimmae left the room.22:22:48
5 Jul 2021
@spacesbot:nixos.devspacesbot - keeps a log of public NixOS channels joined the room.19:20:13
@spacesbot:nixos.devspacesbot - keeps a log of public NixOS channels 19:49:33
6 Jul 2021
@hexa:lossy.networkhexamerged the umask/chmod update13:11:45
@hexa:lossy.networkhexaI re-reviewed myself and I think it's sane.13:12:03
@hexa:lossy.networkhexa m1cr0man: maybe rename this room to NixOS ACME, so it sorts better in the room list? 14:10:11
@m1cr0man:m1cr0man.comm1cr0man set the room name to "NixOS ACME / LetsEncrypt".15:28:23
@m1cr0man:m1cr0man.comm1cr0manSure, how's that?15:28:30
@hexa:lossy.networkhexasorts better, thanks. not sure we are stuck with letsencrypt, but I don't mind :)15:36:09
@m1cr0man:m1cr0man.comm1cr0manIMO it's good SEO ;P 15:37:46
@spacesbot:nixos.devspacesbot - keeps a log of public NixOS channels changed their display name from spacesbot to spacesbot - keeps a log of public NixOS channels.22:11:40
8 Jul 2021
@sumner:sumnerevans.comsumner left the room.00:16:15
9 Jul 2021
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️ joined the room.14:50:31
@vika:matrix.nice.sampler.fivika (she/her) 🏳️‍⚧️ set a profile picture.16:39:11
@andreas.schraegle:helsinki-systems.deAndreas Schrägle joined the room.20:15:14
10 Jul 2021
@m1cr0man:m1cr0man.comm1cr0man https://github.com/NixOS/nixpkgs/issues/129838 we're really getting to the point now where the service start script is getting as complex as it was pre-lego, and we maybe should consider writing the tool ourselves or starting to push changes upstream to lego (if they are likely to be merged).
In order to avoid reintroducing the bug that the local expiry check resolves, we would need to check internet connection and then the OCSP response and then trigger renewal if necessary :sick
12:49:16
@m1cr0man:m1cr0man.comm1cr0man * https://github.com/NixOS/nixpkgs/issues/129838 we're really getting to the point now where the service start script is getting as complex as it was pre-lego, and we maybe should consider writing the tool ourselves or starting to push changes upstream to lego (if they are likely to be merged).
In order to avoid reintroducing the bug that the local expiry check resolves, we would need to check internet connection and then the OCSP response and then trigger renewal if necessary :sick:
12:49:19
@m1cr0man:m1cr0man.comm1cr0man * https://github.com/NixOS/nixpkgs/issues/129838 we're really getting to the point now where the service start script is getting as complex as it was pre-lego, and we maybe should consider writing the tool ourselves or starting to push changes upstream to lego (if they are likely to be merged).
In order to avoid reintroducing the bug that the local expiry check resolves, we would need to check internet connection and then the OCSP response and then trigger renewal if necessary 🤒
12:49:31

Show newer messages


Back to Room ListRoom Version: 6