!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

110 Members
Another day, another cert renewal44 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
4 Jul 2025
@ctheune:matrix.flyingcircus.ioTheuniinterestingly the doc is a bit outdated already, though ... 10:30:34
@emilazy:matrix.orgemilywell that is just reference material for ACME client developers from >half a decade ago11:09:15
@emilazy:matrix.orgemilymost of it is still good, it's just OCSP stapling went away and ARI changed the renewal timing landscape a bit and so on11:09:40
@ctheune:matrix.flyingcircus.ioTheuniyup12:12:06
@ctheune:matrix.flyingcircus.ioTheunias an outsider that just makes it hard to estimate which parts. i did understand it that way: ocsp and ari having changed.12:12:30
@emilazy:matrix.orgemilywell, it's only really relevant for client developers, or comparing existing implementations but then you basically have to read code to see what they get right in some cases12:28:14
@emilazy:matrix.orgemilythe fundamental issue with lego is that things like ARI don't fit great into a cron job type format if you want the best implementation of them12:29:00
@emilazy:matrix.orgemilyand all the hashing etc. we have to do around it is just working around the model not being quite right12:29:20
@emilazy:matrix.orgemily(the end result does work well though at least at medium scale, it just takes a whole bunch of complexity to make the square peg fit the round hole)12:29:44
@ctheune:matrix.flyingcircus.ioTheuniyup12:34:38
@ctheune:matrix.flyingcircus.ioTheunido you know what the list of supported DNS-01 provider APIs looks like in acmez compared to lego?12:35:05
@ctheune:matrix.flyingcircus.ioTheuniso far that's been the reason why I decided to stick with lego for now.12:35:14
@ctheune:matrix.flyingcircus.ioTheuni I got a green bar on the refactoring I demoed above. Trying to get the other tests clean again now. On disk formats are all compatible ... \o/ 12:35:38
@ctheune:matrix.flyingcircus.ioTheuniI need to explicitly praise the test coverage in the acme module. This helps a lot to find little glitches that I didn't properly catch.13:21:03
@ctheune:matrix.flyingcircus.ioTheuni🎉13:21:06

Show newer messages


Back to Room ListRoom Version: 6