!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

122 Members
Another day, another cert renewal54 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
26 Dec 2021
@hexa:lossy.networkhexaI use rfc2316 with my own authoritative server and by default lego waits a minute between each SAN22:42:48
@hexa:lossy.networkhexaif I reduce that time to ~10s it fails sometimes22:43:06
@hexa:lossy.networkhexawhich is worrying22:43:13
@hexa:lossy.networkhexalike … why wouldn't 10 seconds work for a dynamic dns update 😕22:43:22
@winterqt:nixos.devWinter (she/her)
In reply to @aanderse:nixos.dev
Winter: yes
i like my dns provider because they have an awesome feature set and are a good price
i do not like how it takes 30 minutes for my wildcard to renew 😑
what DNS provider if I may ask?
22:55:50
@aanderse:nixos.devaandersenamesilo23:03:50
@moritz.hedtke:matrix.orgmoritz.hedtke
In reply to @hexa:lossy.network
like … why wouldn't 10 seconds work for a dynamic dns update 😕
I could imagine because of the issues documented in https://letsencrypt.org/2020/02/19/multi-perspective-validation.html
23:58:53
@moritz.hedtke:matrix.orgmoritz.hedtkeIf I understood correctly what you mean23:59:04
27 Dec 2021
@moritz.hedtke:matrix.orgmoritz.hedtkewhen I think about it the reasoning doesn't make sense in that case00:00:05
@moritz.hedtke:matrix.orgmoritz.hedtkeTTL?00:00:19
@hexa:lossy.networkhexa moritz.hedtke: the record doesn't exist before the validation try 00:02:41
@hexa:lossy.networkhexaso negcache at worst00:02:57
@hexa:lossy.networkhexabut letsencrypt probably won't do caching here00:03:04
@moritz.hedtke:matrix.orgmoritz.hedtkeAnd you think the record is there before e.g letsencrypt starts querying? I'm not too familiar with acme using dns00:05:55

Show newer messages


Back to Room ListRoom Version: 6