!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

119 Members
Another day, another cert renewal49 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
3 Jun 2024
@arianvp:matrix.orgArianah awesome09:36:19
@arianvp:matrix.orgArianOh well no hard feelings. we’re all human. just makes my blood pressure go up to know I’m breaking people’s TLS setup :’) 09:37:15
@arianvp:matrix.orgArianAdded a WIP PR to add the team to code-owners: https://github.com/NixOS/nixpkgs/pull/316854 09:45:09
@arianvp:matrix.orgArianIf there are any volunteers to join the team just yell ;) 09:45:39
@sandro:supersandro.deSandro 🐧You could symlink the old hash to the new one if the new directory doesn't exist and the contents are similar enough to be compatible09:52:47
@sandro:supersandro.deSandro 🐧
In reply to @arianvp:matrix.org
maybe we should symlink or copy the directory instead of moving? idk. Maybe it's not worth it supporting rollbacks. Just thinking out loud of another failure mode here
Copy means you have old, potentially ran out certs
09:52:47
@sandro:supersandro.deSandro 🐧
In reply to @arianvp:matrix.org
(and it's important. E.g. German government has been issueing LEtsEncrypt certificates for a lot of XMPP servers through MITM'ing through middleboxes at Hetzner datacenters and got caught redhanded multiple times last year)

I know of the one case that went on Hackernews.

DNS challenge works against that, does it?

09:52:47
@sandro:supersandro.deSandro 🐧I have a PR for a test improvement open for 4 months to prevent sich issues in the future and no one really cared, so I just gave up https://github.com/NixOS/nixpkgs/pull/28699909:52:47
@arianvp:matrix.orgArianYeh no blame on you at all. 09:53:22
@sandro:supersandro.deSandro 🐧Going back to null is also not that great because then we rely on the lego defaults which could change in the future09:56:08
@sandro:supersandro.deSandro 🐧If you have a change I could test, throw it over the fence10:00:00
@arianvp:matrix.orgArianyeh I think the only solution is to do some state mangling. Or just put in the release notes that the hash changed and call it a day 10:00:10

Show newer messages


Back to Room ListRoom Version: 6