!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

103 Members
Another day, another cert renewal45 Servers

Load older messages


SenderMessageTime
17 Nov 2022
@andreas.schraegle:helsinki-systems.deAndreas SchrägleHey. I've been getting kind of annoyed by letsencrypt texting me about my expiring certs, because I changed something about them and didn't revoke them. So, is there anything we can do to automate this? Have people thought about this and documented their thoughts somewhere?21:55:23
18 Nov 2022
@hexa:lossy.networkhexasounds like a neat idea00:02:42
@omlet:matrix.orgomlet left the room.00:31:07
19 Nov 2022
@uny:matrix.orguny left the room.23:02:51
20 Nov 2022
@k900:0upti.meK900 ⚡️https://hydra.nixos.org/build/199252313/nixlog/2015:17:10
@k900:0upti.meK900 ⚡️What is even happening here15:17:15
@andreas.schraegle:helsinki-systems.deAndreas Schrägle
openssl x509 -noout -dates < ~/nixpkgs/nixos/tests/common/acme/server/acme.test.cert.pem
notBefore=Oct 21 13:28:36 2020 GMT
notAfter=Nov 20 13:28:36 2022 GMT
15:35:59
@k900:0upti.meK900 ⚡️Why are we hardcoding those anyway, m15:40:41
@k900:0upti.meK900 ⚡️* Why are we hardcoding those anyway? 15:40:44
@andreas.schraegle:helsinki-systems.deAndreas Schräglethere's a readme explaining it in that directory15:41:28
@k900:0upti.meK900 ⚡️No but like 15:45:40
@k900:0upti.meK900 ⚡️Why can't we just generate them as part of the test15:45:48
@andreas.schraegle:helsinki-systems.deAndreas Schräglemaybe because they're not only used in this test? maybe that would be a solution in general. the readme links a lengthy discussion, which I apparently read at the time, because I reacted to some things, but don't really remember.15:48:28
@andreas.schraegle:helsinki-systems.deAndreas Schrägleshort term, regenerating them will unblock the channel. I'd suggest we do that and then someone can think about a potentially better solution.15:49:33
@k900:0upti.meK900 ⚡️Agreed15:50:56
26 Nov 2022
@k900:0upti.meK900 ⚡️The test broke again :(06:57:25
@k900:0upti.meK900 ⚡️https://hydra.nixos.org/build/200012010/nixlog/806:57:27
@hexa:lossy.networkhexato be fair, there was no fix yet 🙂18:10:47
@hexa:lossy.networkhexai restarted it twice and it worked18:10:54
@hexa:lossy.networkhexaand we couldn't grab the log anymore18:10:59
@hexa:lossy.networkhexawhat is the error though?18:12:02
@ahsmha:matrix.orgahmed changed their display name from rh to ahmed.19:19:40
1 Dec 2022
@hexa:lossy.networkhexa changed their display name from hexa to hexa (22.11 now).13:08:34
@hexa:lossy.networkhexa changed their display name from hexa (22.11 now) to hexa.14:38:23
7 Dec 2022
@qbit:tapenet.orgqbit joined the room.17:54:45
@me:linj.techlinj joined the room.21:36:54
@me:linj.techlinjRedacted or Malformed Event21:39:52
@me:linj.techlinj * I use acme module with caddy to do http01 challenge, so the cert's group is set to caddy and its owner is acme. Is there a way to let a systemd dynamic service read that cert?21:40:12
@me:linj.techlinj * I use acme module with caddy to do http01 challenge, so the cert's group is set to caddy and its owner is acme. What is the way to let a systemd dynamic service read that cert with minimal permission given to it?21:45:17
13 Dec 2022
@k900:0upti.meK900 ⚡️https://hydra.nixos.org/build/20191409608:43:07

Show newer messages


Back to Room ListRoom Version: 6