!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

93 Members
Another day, another cert renewal43 Servers

Load older messages


SenderMessageTime
19 Oct 2024
@k900:0upti.meK900And then you can use normal ACME stuff with a DNS challenge, even without a wildcard15:55:12
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I want my nextcloud instance to be under, nextcloud.homelab.nakibrayan.com, is this setup possible?15:55:57
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)only in my lan15:56:06
@k900:0upti.meK900Yes15:56:10
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)how?15:56:25
@k900:0upti.meK900You can set up your LAN's DNS server to resolve that15:56:27
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I use mullvad DNS in my PCs and Phones15:57:20
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I can't set a local dns record15:57:32
@k900:0upti.meK900Then you can set it to resolve to whatever internal address you want it to be on Cloudflare15:57:57
@k900:0upti.meK900It will be resolvable publiclyw15:58:03
@k900:0upti.meK900* It will be resolvable publicly15:58:04
@k900:0upti.meK900But it will resolve to 192.168.1.6 or whatever15:58:15
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I made that before, I added an A record in cloudflare dns that points to 192.168.1.6, but in all my browsers and devices said that the cert is not trusted, why is that?16:00:01
@nakibrayan:matrix.imRayan Nakib (ريان نقيب) * I made that before, I added an A record in cloudflare dns that points to 192.168.1.6, but all my browsers and devices said that the cert is not trusted, why is that?16:00:31
@k900:0upti.meK900Presumably because the cert was for the wrong domain name16:00:40
@k900:0upti.meK900Or self-signed16:00:42
@k900:0upti.meK900Or both16:00:44
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)I will retry, and see16:00:57
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)thanks :)16:01:00
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)20241019_171424.png
Download 20241019_171424.png
16:15:14
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)why I am getting this error?16:15:20
@k900:0upti.meK900It will tell you if you scroll down16:16:12
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)image.png
Download image.png
16:16:42
@k900:0upti.meK900That means it's a self-signed certificate16:17:18
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)it's self singed?16:17:19
@nakibrayan:matrix.imRayan Nakib (ريان نقيب)why it's not using lt's encrypt?16:17:30
@nakibrayan:matrix.imRayan Nakib (ريان نقيب) * why it's not using lt's encrypt?!16:17:33
@k900:0upti.meK900The ACME module generates temporary self-signed certificates by default, to use while it's trying to obtain proper ones from Let's Encrypt16:17:43
@k900:0upti.meK900Presumably, the certificate request failed16:17:52
@k900:0upti.meK900You should check the logs on the machine to see why16:18:00

Show newer messages


Back to Room ListRoom Version: 6