!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

115 Members
Another day, another cert renewal47 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
3 Jun 2024
@k900:0upti.meK900Uhh08:10:58
@k900:0upti.meK900That's a very stupid behavior in lego tbh08:11:03
@arianvp:matrix.orgArianThis is not Lego. this is us08:11:10
@arianvp:matrix.orgArianI think?08:11:15
@k900:0upti.meK900Oh OK yeah it is us08:12:00
@k900:0upti.meK900https://github.com/SuperSandro2000/nixpkgs/blob/6e294f40db992635e4aa566789ac3560ed1f9b1a/nixos/modules/security/acme/default.nix#L1608:12:00
@arianvp:matrix.orgArian so acmeServer used to be null 08:12:19
@arianvp:matrix.orgArianand we change it to the letsencrypt uri08:12:35
@k900:0upti.meK900But how is it leaking into CAA records then08:13:01
@k900:0upti.meK900Is what I don't get08:13:03
@arianvp:matrix.orgArianYou can bind your CAA record to your account ID these days08:13:35
@k900:0upti.meK900Oh08:13:40
@arianvp:matrix.orgArianit's a new extension to ACME protocol08:13:42
@arianvp:matrix.orgArianto detect MITM attacks08:13:45
@k900:0upti.meK900Yeeeeeah08:13:58
@k900:0upti.meK900But then we can just migrate08:14:03
@k900:0upti.meK900Like08:14:11
@arianvp:matrix.orgArian(and it's important. E.g. German government has been issueing LEtsEncrypt certificates for a lot of XMPP servers through MITM'ing through middleboxes at Hetzner datacenters and got caught redhanded multiple times last year)08:14:15
@k900:0upti.meK900Compute old hash and new hash08:14:32

Show newer messages


Back to Room ListRoom Version: 6