Retire certbot #589

Open
opened 2025-04-22 14:56:21 +00:00 by raucao · 2 comments
Owner
https://github.com/go-acme/lego refs #519
raucao added the
enhancement
idea
labels 2025-04-22 14:56:21 +00:00
Author
Owner

Note: maybe autossl could also still make sense where we don't have to use DNS validation.

Note: maybe autossl could also still make sense where we don't have to use DNS validation.
raucao added the
security
label 2025-04-22 14:57:51 +00:00
raucao changed title from Switch from certbot to lego to Retire certbot 2025-09-12 14:06:45 +00:00
Author
Owner

Big news:

Not sure if they support DNS verification at all, or how one can do it reliable when doing DNS round-robin to multiple hosts, but those are not edge cases, so I'm sure there's a way.

We'll still need something else for things that aren't behind Nginx, like e.g. ejabberd, so Lego could still be a good choice for those.

Big news: * https://blog.nginx.org/blog/native-support-for-acme-protocol * https://nginx.org/en/docs/http/ngx_http_acme_module.html Not sure if they support DNS verification at all, or how one can do it reliable when doing DNS round-robin to multiple hosts, but those are not edge cases, so I'm sure there's a way. We'll still need something else for things that aren't behind Nginx, like e.g. ejabberd, so Lego could still be a good choice for those.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: kosmos/chef#589
No description provided.