!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

116 Members
Another day, another cert renewal50 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
3 Jun 2024
@sandro:supersandro.deSandro 🐧
In reply to @arianvp:matrix.org
(and it's important. E.g. German government has been issueing LEtsEncrypt certificates for a lot of XMPP servers through MITM'ing through middleboxes at Hetzner datacenters and got caught redhanded multiple times last year)

I know of the one case that went on Hackernews.

DNS challenge works against that, does it?

09:52:47
@sandro:supersandro.deSandro 🐧I have a PR for a test improvement open for 4 months to prevent sich issues in the future and no one really cared, so I just gave up https://github.com/NixOS/nixpkgs/pull/28699909:52:47
@arianvp:matrix.orgArianYeh no blame on you at all. 09:53:22
@sandro:supersandro.deSandro 🐧Going back to null is also not that great because then we rely on the lego defaults which could change in the future09:56:08
@sandro:supersandro.deSandro 🐧If you have a change I could test, throw it over the fence10:00:00
@arianvp:matrix.orgArianyeh I think the only solution is to do some state mangling. Or just put in the release notes that the hash changed and call it a day 10:00:10

Show newer messages


Back to Room ListRoom Version: 6