!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

86 Members
Another day, another cert renewal39 Servers

Load older messages


SenderMessageTime
19 Oct 2024
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I use mullvad DNS in my PCs and Phones15:57:20
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I can't set a local dns record15:57:32
@k900:0upti.meK900Then you can set it to resolve to whatever internal address you want it to be on Cloudflare15:57:57
@k900:0upti.meK900It will be resolvable publiclyw15:58:03
@k900:0upti.meK900* It will be resolvable publicly15:58:04
@k900:0upti.meK900But it will resolve to 192.168.1.6 or whatever15:58:15
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I made that before, I added an A record in cloudflare dns that points to 192.168.1.6, but in all my browsers and devices said that the cert is not trusted, why is that?16:00:01
@nakibrayan:matrix.imRayan Nakib (ريان نقيب) * I made that before, I added an A record in cloudflare dns that points to 192.168.1.6, but all my browsers and devices said that the cert is not trusted, why is that?16:00:31
@k900:0upti.meK900Presumably because the cert was for the wrong domain name16:00:40
@k900:0upti.meK900Or self-signed16:00:42
@k900:0upti.meK900Or both16:00:44
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I will retry, and see16:00:57
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)thanks :)16:01:00
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)20241019_171424.png
Download 20241019_171424.png
16:15:14
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)why I am getting this error?16:15:20
@k900:0upti.meK900It will tell you if you scroll down16:16:12
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)image.png
Download image.png
16:16:42
@k900:0upti.meK900That means it's a self-signed certificate16:17:18
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)it's self singed?16:17:19
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)why it's not using lt's encrypt?16:17:30
@nakibrayan:matrix.imRayan Nakib (ريان نقيب) * why it's not using lt's encrypt?!16:17:33
@k900:0upti.meK900The ACME module generates temporary self-signed certificates by default, to use while it's trying to obtain proper ones from Let's Encrypt16:17:43
@k900:0upti.meK900Presumably, the certificate request failed16:17:52
@k900:0upti.meK900You should check the logs on the machine to see why16:18:00
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)
16:19:16
@nakibrayan:matrix.imRayan Nakib (ريان نقيب) *
Oct 19 17:18:58 MacBook-Pro-8-1 acme-nextcloud-rayanlab.duckdns.org-start[140901]: Waiting to acquire lock /run/acme/1.lock
Oct 19 17:18:58 MacBook-Pro-8-1 acme-nextcloud-rayanlab.duckdns.org-start[140901]: Acquired lock /run/acme/1.lock
Oct 19 17:18:59 MacBook-Pro-8-1 acme-nextcloud-rayanlab.duckdns.org-start[140905]: 2024/10/19 17:18:59 [nextcloud-rayanlab.duckdns.org] The certificate expires in 89 days, the number of days defined to perform the renewal is 30: no renewal.
Oct 19 17:18:59 MacBook-Pro-8-1 acme-nextcloud-rayanlab.duckdns.org-start[140901]: Releasing lock /run/acme/1.lock
Oct 19 17:18:59 MacBook-Pro-8-1 systemd[1]: acme-nextcloud-rayanlab.duckdns.org.service: Deactivated successfully.
░░ Subject: Unit succeeded
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ The unit acme-nextcloud-rayanlab.duckdns.org.service has successfully entered the 'dead' state.
Oct 19 17:18:59 MacBook-Pro-8-1 systemd[1]: Finished Renew ACME certificate for nextcloud-rayanlab.duckdns.org.
░░ Subject: A start job for unit acme-nextcloud-rayanlab.duckdns.org.service has finished successfully
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A start job for unit acme-nextcloud-rayanlab.duckdns.org.service has finished successfully.
░░ 
░░ The job identifier is 24232.
Oct 19 17:18:59 MacBook-Pro-8-1 systemd[1]: acme-nextcloud-rayanlab.duckdns.org.service: Consumed 643ms CPU time, 18.8M memory peak, 5.3K incoming IP traffic, 1.3K outgoing IP traffic.
░░ Subject: Resources consumed by unit runtime
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ The unit acme-nextcloud-rayanlab.duckdns.org.service completed and consumed the indicated resources.
16:19:26
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I don't see any errors16:19:40
@k900:0upti.meK900Then you probably need to reload nginx or whatever you're using16:19:57
@k900:0upti.meK900So it picks up new certificates16:20:01
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)restarted the pc, and it's still, the same error16:22:07

Show newer messages


Back to Room ListRoom Version: 6