home.social

#acmesh — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #acmesh, aggregated by home.social.

fetched live
  1. My opnsense now deploys valid certs to my Fritzbox too. ✅
    Chrome seems to cache that old selfsigned cert. Vivaldi shows it is valid.
    #opnsense #acmesh #letsencrypt #httpseverywere #fritzbox

  2. Just found out, that acme.sh supports deploying certs to zyxel gs1900 switches AND opnsense supports it as automation 😎
    Proxmox, truenas are supported too, but I do have processes for these hosts already.
    #acmesh #opnsense #zyxel #gs1900 #httpseverwhere

  3. Как перестать зависеть от Cloudflare в DNS и не выстрелить себе в ногу

    DNS — это та штука, которую замечаешь только когда она падает. Весь твой трафик, почта, сертификаты, доступ к админкам — всё висит на том, что кто-то корректно ответит на запрос «а где example.com ?». У меня этим «кем-то» был Cloudflare. Для большинства это правильный выбор — удобно, быстро, бесплатно. Но в какой-то момент я поймал себя на мысли, что фундамент всей моей инфраструктуры я не контролирую: он живёт в чужом дашборде, по чужим правилам и лимитам. Я перенёс все свои зоны — несколько десятков доменов — на собственную DNS-инфра- структуру. Ниже — зачем, какая получилась архитектура, и обо что я споткнулся по дороге.

    habr.com/ru/articles/1041894/

    #dns #powerdns #acmesh #cloudflare #devops #ansible

  4. TIL (today I learned): @letsencrypt has a neat little project for running a test CA for the ACME protocol called Pebble.

    github.com/letsencrypt/pebble

    letsencrypt.org/2025/04/30/peb

    I just wired it into the tests for the foundata.acmesh #Ansible collection inside each #Podman
    container to test the webroot challenge end-to-end across all platforms without requiring external infrastructure:

    github.com/foundata/ansible-co

    #acmesh #opensource #devops

  5. Certbot doesn't define CN by default which is required by pgBackRest and OpenVPN as of today. I tried to use a CSR but Certbot doesn't automatically renew those certificates making certbot pointless. I'm now using acme.sh and it just works github.com/acmesh-official/acm

    #acme #acmesh #certbot #tls #ssl #openvpn #pgbackrest

  6. Автопродление TLS тоже ломается

    Текст в ленте: Много лет индустрия информационной безопасности старается улучшить стандарты шифрования в сети двумя способами: массовое распространение HTTPS как общего стандарта шифрования для всех сайтов — даже для тех, которым защита формально не требуется. Очень много времени было потрачено на то, чтобы убедить пользователей в важности тотального шифрования абсолютно всех коммуникаций; сокращение сроков выдачи сертификатов SSL/TLS, чтобы стимулировать пользователей внедрять автоматические процедуры/скрипты для автопродления сертификатов, чтобы исключить «человеческий фактор» и забывчивость сисадминов, которые забывают менять сертификаты. Но иногда этого недостаточно. К сожалению, автоматические скрипты продления сертификатов тоже могут выйти из строя.

    habr.com/ru/companies/globalsi

    #tls #сертификат #acme #letsencrypt #шифрование #certbot #acmesh #dns #bazel

  7. Decided to turn this Toot (mastodon.eddmil.es/@iMeddles/1) into a blogpost, with a slightly overly grumpy title. This details why I think acme.sh uses an insecure default, how people using acme.sh should remedy this, and why (despite the title) it's probably not *that* big of a deal:

    i.am.eddmil.es/posts/acmesh-in

    #acme #acmesh #LetsEncrypt

  8. TiL that #acmesh, unlike just about any other #acme client I've used, doesn't rotate the private key at renewal by default. And by "TiL" I meant "just had to spend 20 mins reconfiguring a bunch of servers to do it correctly". That'll teach me to read the docs closer and not make assumptions. (I won't learn the lesson of course, but it'll teach me anyway)

  9. Für Home Assistant lässt sich mit dem Add-on Let's Encrypt ein eigenes SSL-Zertifikat erstellen, um die Kommunikation zwischen dem Server und den Clients abzusichern.

    strobelstefan.de/blog/2025/03/

    #letsencrypt #acmesh #homeassistant

  10. Let's Encrypt stellt die @Benachrichtigung für ablaufende Zertifikate ein.
    Ein wunderbarer Grund den ganzen Prozess für die eigenen Systeme mit acme.sh zu automatisieren.

    Ein Beispiel: Für die eigene Nextcloud wird von Certbot auf acme.sh gewechselt.

    #letsencrypt #acmesh #nextcloud #raspberrypi

    strobelstefan.de/blog/2025/03/

  11. @tootbrute @sbb

    In case you are interested how I solved having a publicly signed SSL certificate for a home server not connected to the Internet, here is what I did:

    codeberg.org/harald/Codeschnip

    The downside: there seems to be no way without having a registered domain. It took me unnecessary time to accept this. The upside: taking the step to get yourself a domain is simpler and cheaper than I was aware of and with the right tool, the rest was easy enough.

    #dns #homeserver #acmesh #letsencrypt

  12. Renew DNS-01 Let’s Encrypt certificates with Acme.sh, Docker, SaltStack and Gandi LiveDNS

    blog.narf.ssji.net/2024/09/30/

    The HTTP-based challenge to issue LetsEncrypt certificates can’t be used for internal or non-HTTP servers. This post describes the use of acme.sh in Docker to issue and renew certificates over DNS via SaltStack.

    #AcmeSh #Docker #GandiLiveDNS #LetSEncrypt #PGP #SaltStack
  13. Получаем wildcard сертификат letsencrypt с помощью acme.sh

    Получаем wildcard сертификаты с помощью acme.sh и авторизацией по DNS через cloudflare. +Рабочие скрипты.

    habr.com/ru/articles/845954/

    #acmesh #letsencrypt #acmedns #cloudflare #wildcard #domains

  14. Настройка HTTPS для контейнеризированных Java-сервисов

    Сейчас все большее количество интернет-ресурсов и приложений декларируют полный переход на протокол передачи данных, использующий шифрование HTTPS. Более того, некоторые из них ужесточают требования к обеспечению шифрования. Теперь если вы, например, попробуете открыть ресурс, на котором был установлен самоподписанный сертификат, по зашифрованному каналу в браузере, вам могут не только вывести предупреждение о небезопасном соединении, но и пресечь попытку подключения. Все эти изменения чреваты разного рода неудобствами как для специалистов, так и для конечных пользователей. Сегодня мы попробуем разобраться с практической стороной применения сертификатов. Создадим простейшее веб-приложение на Java и доведем его до готовности к эксплуатации в виде контейнеризированного приложения, работающего по протоколу HTTPS. Для создания приложения мы будем использовать фреймворк Jmix , который основан на Spring Boot и Vaadin, поэтому описанные подходы будут работать также для широкого класса веб-приложений на Spring Boot. Мы предполагаем, что вы установили Docker актуальной версии для своей ОС, используя brew, chocolately или deb/rpm.

    habr.com/ru/companies/haulmont

    #java #https #jmix #nginx #docker #ssl #acmesh

  15. A Chinese CA was exploiting a command injection in a shell script implementing the ACME protocol, and they are now taking everything down? What?!

    I can’t find if this CA was actually trusted by any browser, though.

    github.com/acmesh-official/acm

    #acmesh #hica

  16. New blog post: Renewn DNS-01 Let’s Encrypt certificates with Acme.sh, Docker, SaltStack and Gandi LiveDNS

    The HTTP-based challenge to issue LetsEncrypt certificates can’t be used for internal or non-HTTP servers. This post describes the use of acme.sh in Docker to issue and renew certificates over DNS via SaltStack.

    https://blog.narf.ssji.net/2022/10/28/renewn-dns-01-lets-encrypt-certificates-with-acme-sh-docker-saltstack-and-gandi-livedns/

    #AcmeSh #Docker #GandiLiveDNS #LetSEncrypt #PGP #SaltStack #wip #engineering #security #sysadmin #tip

  17. New blog post: Renew DNS-01 Let’s Encrypt certificates with Acme.sh, Docker, SaltStack and Gandi LiveDNS

    The HTTP-based challenge to issue LetsEncrypt certificates can’t be used for internal or non-HTTP servers. This post describes the use of acme.sh in Docker to issue and renew certificates over DNS via SaltStack.

    https://blog.narf.ssji.net/2022/10/28/renew-dns-01-lets-encrypt-certificates-with-acme-sh-docker-saltstack-and-gandi-livedns/

    #AcmeSh #Docker #GandiLiveDNS #LetSEncrypt #PGP #SaltStack #wip #engineering #security #sysadmin #tip