!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

107 Members
Another day, another cert renewal47 Servers

Load older messages


SenderMessageTime
6 Jul 2025
@m1cr0man:m1cr0man.comm1cr0manThe test suite really is the most valuable bit of the acme module at this point. If you can get everything to pass, then you can be reasonably confident there are no major regressions.13:12:27
@m1cr0man:m1cr0man.comm1cr0man

I can't remember any concrete reason right now as to why it was introduced. Removing it may be difficult, as people definitely are using it.

I understand you are reworking this for your own use case which sounds quite complex and large-scale, but keep in mind that most people use the ACME module for the simplest of cases - they have a vhost, they set enableACME = true, and they magically have certs. Making the ACME module work for as many use cases as possible is important to reduce fragmentation in the community, but there is a limit.

I definitely think there is a solution here where we can keep the self signed cert optionality and what you are trying to do. Your primary concern seems to be around the lack of a syntactically valid cert being present for consumer services. If this option is explicitly set to false, then it can be assumed that users do not care about this guarantee.

13:19:06
@emilazy:matrix.orgemilythe one talking about OCSP stapling is at least obsolete :)13:32:26
7 Jul 2025
@ctheune:matrix.flyingcircus.ioChristian Theune m1cr0man: yeah, not breaking things by introducing my own use case is absolutely on my list. thanks for the github search ... going through the list, the use case is basically DNS-01 where you can get certificates up early. I'll ponder the optionality. Also, I can try to get in touch with the users ... so thanks again for that list. 05:09:40
26 May 2021
@grahamc:nixos.org@grahamc:nixos.org set the history visibility to "world_readable".20:36:34
@grahamc:nixos.org@grahamc:nixos.org changed the room name to "" from "".20:36:34
@server_stats:nordgedanken.devServer Stats Discoverer (traveler bot) joined the room.20:36:42
@grahamc:nixos.org@grahamc:nixos.org invited @m1cr0man:m1cr0man.comm1cr0man.20:36:47
@grahamc:nixos.org@grahamc:nixos.orgchanged room power levels.20:36:52
@m1cr0man:m1cr0man.comm1cr0man joined the room.20:37:09
@dandellion:dodsorf.asDandellion joined the room.20:38:19
@emilazy:matrix.orgemily joined the room.20:43:31
@hexa:lossy.networkhexa joined the room.20:44:30
@m1cr0man:m1cr0man.comm1cr0man set the room topic to "Another day, another cert renewal".20:46:02
@voyager:t2bot.ioMatrix Traveler (bot) joined the room.20:51:53
@sumner:sumnerevans.comsumner joined the room.21:00:03
@andi:kack.itandi- joined the room.21:03:46
@immae:matrix.orgimmae joined the room.21:13:02
@hax404:hax404.dehax404 joined the room.22:17:28
@l3af:matrix.orgl3af joined the room.22:39:21
28 May 2021
@pinage404:matrix.orgpinage404 joined the room.11:07:44
@evils.devils:matrix.orgevils joined the room.17:55:05
29 May 2021
@aaron:fosslib.netaaron joined the room.03:07:32
30 May 2021
@l3af:matrix.orgl3af changed their display name from l3af to test.12:01:47
@l3af:matrix.orgl3af changed their display name from test to l3af.12:01:59
@l3af:matrix.orgl3af changed their display name from l3af to l3aft.12:11:09
@l3af:matrix.orgl3af set a profile picture.12:11:24
@l3af:matrix.orgl3af changed their display name from l3aft to l3af.12:11:58
@l3af:matrix.orgl3af changed their display name from l3af to l3af .12:13:27
@l3af:matrix.orgl3af changed their profile picture.12:13:36

Show newer messages


Back to Room ListRoom Version: 6