| 2 Dec 2025 |
hexa | persistent DNS TXT records as proof of domain control | 15:46:08 |
hexa | if that works out that feels like it will be big | 15:46:38 |
hexa | shortlived is still "locked behind an allowlist" | 15:47:16 |
| 10 Dec 2025 |
Sandro 🐧 | FYI: https://github.com/NixOS/nixpkgs/pull/467908 | 23:35:40 |
| 14 Dec 2025 |
hexa | https://datatracker.ietf.org/doc/draft-ietf-acme-device-attest/ | 14:12:18 |
hexa | wondering if the security.acme module will have to support enterprise pki in the future 🙂 | 14:22:21 |
Arian | Smallstep implements this and we have a module for it in nixos I think | 17:08:17 |
| 24 Dec 2025 |
hexa | ok, so shortlived certificates are "6ish days" | 00:17:22 |
hexa | or exactly 160h | 00:17:25 |
hexa | specifying the remainder in valid days seems less useful 😄 | 00:17:48 |
hexa | I'd be fine with less than 72h remaining, ok that's three days | 00:19:06 |
hexa | but the renew timer should run more often than daily | 00:19:19 |
hexa | * but now the renew timer should run more often than daily | 00:19:23 |
hexa |  Download image.png | 00:40:59 |
hexa | validMinDays = 3;
renewInterval = "3/6:00:00";
extraLegoRunFlags = [ "--profile=shortlived" ];
extraLegoRenewFlags = [ "--profile=shortlived" ];
| 00:41:26 |
hexa | oh, I think the profile option was backported | 00:41:39 |
hexa | * oh, I think the profile option was backported, so that can be shortened to | 00:44:34 |
hexa | validMinDays = 3;
renewInterval = "3/6:00:00";
profile = "shortlived";
| 00:44:37 |
| 26 May 2021 |
| @grahamc:nixos.org set the history visibility to "world_readable". | 20:36:34 |
| @grahamc:nixos.org changed the room name to "" from "". | 20:36:34 |
| Server Stats Discoverer (traveler bot) joined the room. | 20:36:42 |
| @grahamc:nixos.org invited m1cr0man. | 20:36:47 |
| @grahamc:nixos.orgchanged room power levels. | 20:36:52 |
| m1cr0man joined the room. | 20:37:09 |
| Dandellion joined the room. | 20:38:19 |
| emily joined the room. | 20:43:31 |
| hexa joined the room. | 20:44:30 |
| m1cr0man set the room topic to "Another day, another cert renewal". | 20:46:02 |
| Matrix Traveler (bot) joined the room. | 20:51:53 |
| sumner joined the room. | 21:00:03 |