!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

118 Members
Another day, another cert renewal49 Servers

Load older messages


SenderMessageTime
10 Apr 2026
@arianvp:matrix.orgArianAll the revoked certs work fine for me on chrome for android20:51:09
@arianvp:matrix.orgArianI guess it's because chrome only pushes revoked certs through updates?20:51:53
@thinkchaos:matrix.orgThinkChaos

Yeah only Firefox has good (i.e. functional) revocation support ATM thanks to the mentioned CRLite.
This blog post explains how it works nicely: https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/

You should consider using FF on Android just for extensions: it supports standard WebExts like uBlock Origin!

23:02:19
11 Apr 2026
@rasmata:matrix.org@rasmata:matrix.org joined the room.19:17:38
@rasmata:matrix.org@rasmata:matrix.org left the room.19:17:40
12 Apr 2026
@leona:leona.isleona changed their profile picture.12:15:37
13 Apr 2026
@alesya-h:nixos.devAlesya changed their display name from Alesya Huzik to Alesya.01:44:34
14 Apr 2026
@lukas:landgraf.moeLukas joined the room.01:53:57
23 Apr 2026
@rasmata:matrix.org@rasmata:matrix.org joined the room.19:20:09
@rasmata:matrix.org@rasmata:matrix.org left the room.19:20:13
27 Apr 2026
@ninja:worldethicaldataforum.orgNinja joined the room.14:32:13
2 May 2026
@tom:dragar.deTom changed their profile picture.18:40:56
8 May 2026
@hexa:lossy.networkhexahttps://letsencrypt.status.io/19:44:49
@hexa:lossy.networkhexa

We have been made aware of a potential incident and are shutting down all issuance.

19:45:07
@k900:0upti.meK900Wew19:45:25
@hexa:lossy.networkhexahttps://bugzilla.mozilla.org/show_bug.cgi?id=203835121:46:48
9 May 2026
@m1cr0man:m1cr0man.comm1cr0manDoes this actually affect us? Afaik you can't issue a subordinate with lego01:31:06
@hexa:lossy.networkhexait prevented me from renewing11:32:12
12 May 2026
@artify:artify.zoneRichard Tichý joined the room.11:24:50
13 May 2026
@hexa:lossy.networkhexahttps://github.com/go-acme/lego/releases/tag/v5.0.313:50:49
@hexa:lossy.networkhexaRedacted or Malformed Event13:51:40
@hexa:lossy.networkhexaremoving extraLegoRenewFlags will change hash data14:42:44
@hexa:lossy.networkhexa osnyx (he/him) I don't see a way to make the lego 5.0 migration not renew all certs fwiw 15:29:36
@hexa:lossy.networkhexahttps://go-acme.github.io/lego/migration/cli/index.html15:29:37
@hexa:lossy.networkhexaRedacted or Malformed Event15:29:47
@hexa:lossy.networkhexawe'll drop renew flags, because renew is gone15:35:12
@hexa:lossy.networkhexaand both global and renew flags now live in run15:35:25
@hexa:lossy.networkhexacan't invalidate the hashdata harder15:35:43
@hexa:lossy.networkhexa
+ lego run --accept-tos --path . --no-random-sleep --http --http.address :80 --server https://acme.test/dir --key-type ec256 --domains builtin.example.test --domains 192.168.1.2
2026-05-13T15:45:13.971858291Z INFO  Private key saved. filepath=accounts/acme.test/noemail@example.com/noemail@example.com.key
2026-05-13T15:45:13.979702584Z ERROR Error error="renew: registration: the account noemail@example.com is not registered"
15:51:05
@hexa:lossy.networkhexa so on email change we not get "not registered" 15:51:21

Show newer messages


Back to Room ListRoom Version: 6