!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

103 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
26 Oct 2025
@sir-morton:matrix.orgSir_Morton joined the room.15:34:39
@neobrain:matrix.org@neobrain:matrix.org joined the room.21:28:44
27 Oct 2025
@neobrain:matrix.org@neobrain:matrix.org left the room.07:34:36
7 Nov 2025
@atra1n:matrix.org@atra1n:matrix.org removed their profile picture.16:36:32
@atra1n:matrix.org@atra1n:matrix.org removed their display name Train.16:36:52
@atra1n:matrix.org@atra1n:matrix.org left the room.16:37:04
@emma:rory.gay@emma:rory.gay left the room.22:41:45
12 Nov 2025
@inayet:matrix.orgInayet changed their display name from inayet to Inayet.12:37:54
19 Nov 2025
@alina:catgirl.cloud@alina:catgirl.cloud left the room.15:01:52
2 Dec 2025
@hexa:lossy.networkhexaRedacted or Malformed Event15:43:04
@hexa:lossy.networkhexahttps://letsencrypt.org/2025/12/02/from-90-to-45.html15:43:10
@hexa:lossy.networkhexahttps://datatracker.ietf.org/doc/html/draft-sheurich-acme-dns-persist-0115:45:57
@hexa:lossy.networkhexapersistent DNS TXT records as proof of domain control15:46:08
@hexa:lossy.networkhexaif that works out that feels like it will be big15:46:38
@hexa:lossy.networkhexashortlived is still "locked behind an allowlist"15:47:16
10 Dec 2025
@sandro:supersandro.deSandro 🐧FYI: https://github.com/NixOS/nixpkgs/pull/46790823:35:40
14 Dec 2025
@hexa:lossy.networkhexahttps://datatracker.ietf.org/doc/draft-ietf-acme-device-attest/14:12:18
@hexa:lossy.networkhexawondering if the security.acme module will have to support enterprise pki in the future 🙂 14:22:21
@arianvp:matrix.orgArianSmallstep implements this and we have a module for it in nixos I think17:08:17
24 Dec 2025
@hexa:lossy.networkhexaok, so shortlived certificates are "6ish days"00:17:22
@hexa:lossy.networkhexaor exactly 160h00:17:25
@hexa:lossy.networkhexaspecifying the remainder in valid days seems less useful 😄 00:17:48
@hexa:lossy.networkhexaI'd be fine with less than 72h remaining, ok that's three days00:19:06
@hexa:lossy.networkhexabut the renew timer should run more often than daily00:19:19
@hexa:lossy.networkhexa* but now the renew timer should run more often than daily00:19:23
@hexa:lossy.networkhexaimage.png
Download image.png
00:40:59
@hexa:lossy.networkhexa
      validMinDays = 3;
      renewInterval = "3/6:00:00";
      extraLegoRunFlags = [ "--profile=shortlived" ];
      extraLegoRenewFlags = [ "--profile=shortlived" ];
00:41:26
@hexa:lossy.networkhexaoh, I think the profile option was backported00:41:39
@hexa:lossy.networkhexa* oh, I think the profile option was backported, so that can be shortened to00:44:34
@hexa:lossy.networkhexa
      validMinDays = 3;
      renewInterval = "3/6:00:00";
      profile = "shortlived";
00:44:37

Show newer messages


Back to Room ListRoom Version: 6