!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

120 Members
Another day, another cert renewal51 Servers

Load older messages


SenderMessageTime
8 May 2026
@hexa:lossy.networkhexa

We have been made aware of a potential incident and are shutting down all issuance.

19:45:07
@k900:0upti.meK900Wew19:45:25
@hexa:lossy.networkhexahttps://bugzilla.mozilla.org/show_bug.cgi?id=203835121:46:48
9 May 2026
@m1cr0man:m1cr0man.comm1cr0manDoes this actually affect us? Afaik you can't issue a subordinate with lego01:31:06
@hexa:lossy.networkhexait prevented me from renewing11:32:12
12 May 2026
@artify:artify.zoneRichard Tichý joined the room.11:24:50
13 May 2026
@hexa:lossy.networkhexahttps://github.com/go-acme/lego/releases/tag/v5.0.313:50:49
@hexa:lossy.networkhexaRedacted or Malformed Event13:51:40
@hexa:lossy.networkhexaremoving extraLegoRenewFlags will change hash data14:42:44
@hexa:lossy.networkhexa osnyx (he/him) I don't see a way to make the lego 5.0 migration not renew all certs fwiw 15:29:36
@hexa:lossy.networkhexahttps://go-acme.github.io/lego/migration/cli/index.html15:29:37
@hexa:lossy.networkhexaRedacted or Malformed Event15:29:47
@hexa:lossy.networkhexawe'll drop renew flags, because renew is gone15:35:12
@hexa:lossy.networkhexaand both global and renew flags now live in run15:35:25
@hexa:lossy.networkhexacan't invalidate the hashdata harder15:35:43
@hexa:lossy.networkhexa
+ lego run --accept-tos --path . --no-random-sleep --http --http.address :80 --server https://acme.test/dir --key-type ec256 --domains builtin.example.test --domains 192.168.1.2
2026-05-13T15:45:13.971858291Z INFO  Private key saved. filepath=accounts/acme.test/noemail@example.com/noemail@example.com.key
2026-05-13T15:45:13.979702584Z ERROR Error error="renew: registration: the account noemail@example.com is not registered"
15:51:05
@hexa:lossy.networkhexa so on email change we not get "not registered" 15:51:21
@hexa:lossy.networkhexaRedacted or Malformed Event15:52:44
@emilazy:matrix.orgemilywe can just drop email for LE, right?16:05:48
@emilazy:matrix.orgemilythey no longer use or store it16:05:51
@emilazy:matrix.orgemilybut otoh I guess if we key the hash on it then CAA…16:06:13
@hexa:lossy.networkhexathe test passes an email on the first run16:06:52
@hexa:lossy.networkhexadrops it on the second16:06:54
@hexa:lossy.networkhexaand gets that error16:06:58
@hexa:lossy.networkhexaso renewing with a different email (no email) fails16:07:15
@hexa:lossy.networkhexaI found --force-cert-domains, which is nice16:07:33
@hexa:lossy.networkhexafiled an issue https://github.com/go-acme/lego/issues/308416:25:00
@hexa:lossy.networkhexamaybe we need to --force-renew in these cases16:26:01
@hexa:lossy.networkhexaRedacted or Malformed Event16:26:05
@hexa:lossy.networkhexaRedacted or Malformed Event16:26:26

Show newer messages


Back to Room ListRoom Version: 6