home.social

#zerossl — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zerossl, aggregated by home.social.

fetched live
  1. 🎯 #Caddy on the VPS handles HTTPS with on-demand TLS. Certificates are auto-provisioned per subdomain, with a #ZeroSSL fallback when Let's Encrypt hits its 50-certs-per-week rate limit.

    🔧 A small #Python service on the server reconfigures Caddy routes dynamically as tunnels connect and disconnect.

  2. 🎯 #Caddy on the VPS handles HTTPS with on-demand TLS. Certificates are auto-provisioned per subdomain, with a #ZeroSSL fallback when Let's Encrypt hits its 50-certs-per-week rate limit.

    🔧 A small #Python service on the server reconfigures Caddy routes dynamically as tunnels connect and disconnect.

  3. 🎯 #Caddy on the VPS handles HTTPS with on-demand TLS. Certificates are auto-provisioned per subdomain, with a #ZeroSSL fallback when Let's Encrypt hits its 50-certs-per-week rate limit.

    🔧 A small #Python service on the server reconfigures Caddy routes dynamically as tunnels connect and disconnect.

  4. 🎯 #Caddy on the VPS handles HTTPS with on-demand TLS. Certificates are auto-provisioned per subdomain, with a #ZeroSSL fallback when Let's Encrypt hits its 50-certs-per-week rate limit.

    🔧 A small #Python service on the server reconfigures Caddy routes dynamically as tunnels connect and disconnect.

  5. 🎯 #Caddy on the VPS handles HTTPS with on-demand TLS. Certificates are auto-provisioned per subdomain, with a #ZeroSSL fallback when Let's Encrypt hits its 50-certs-per-week rate limit.

    🔧 A small #Python service on the server reconfigures Caddy routes dynamically as tunnels connect and disconnect.

  6. #ZeroSSL certificate renewal is slow. Several minutes per domain, but it goes through successfully. Normally this runs unattended and I don't pay attention. So maybe that's normal.🤷‍♂️
    #TLS #SSL #homelab #selfhosting

  7. DNS-PERSIST-01 ACME validation - Uh oh, constant annoyance, clients are moving so slowly. I would really love to have this with ZeroSSL. It seems that one of the best ways would be using lego with win-acme’s scripts for Windows environment.

    Deep breath. Yeah, it’s doable, slightly annoying. Adding extra custom tech which I would want to avoid in the very first place. But for the systems that NEED it, it still would be better option than NOT having it at all. Maybe when I’m not too busy, I’ll sort it out. It’s doable for sure, if the motivation and need just is there. - Yes, ZeroSSL is also lacking the DNS-PERSIST-01 support, so, double bummer, but life is.

    #TLS #ZeroSSL #LetsEncrypt #winacme #ACME #Lego

  8. DNS-PERSIST-01 ACME validation - Uh oh, constant annoyance, clients are moving so slowly. I would really love to have this with ZeroSSL. It seems that one of the best ways would be using lego with win-acme’s scripts for Windows environment.

    Deep breath. Yeah, it’s doable, slightly annoying. Adding extra custom tech which I would want to avoid in the very first place. But for the systems that NEED it, it still would be better option than NOT having it at all. Maybe when I’m not too busy, I’ll sort it out. It’s doable for sure, if the motivation and need just is there. - Yes, ZeroSSL is also lacking the DNS-PERSIST-01 support, so, double bummer, but life is.

    #TLS #ZeroSSL #LetsEncrypt #winacme #ACME #Lego

  9. DNS-PERSIST-01 ACME validation - Uh oh, constant annoyance, clients are moving so slowly. I would really love to have this with ZeroSSL. It seems that one of the best ways would be using lego with win-acme’s scripts for Windows environment.

    Deep breath. Yeah, it’s doable, slightly annoying. Adding extra custom tech which I would want to avoid in the very first place. But for the systems that NEED it, it still would be better option than NOT having it at all. Maybe when I’m not too busy, I’ll sort it out. It’s doable for sure, if the motivation and need just is there. - Yes, ZeroSSL is also lacking the DNS-PERSIST-01 support, so, double bummer, but life is.

    #TLS #ZeroSSL #LetsEncrypt #winacme #ACME #Lego

  10. DNS-PERSIST-01 ACME validation - Uh oh, constant annoyance, clients are moving so slowly. I would really love to have this with ZeroSSL. It seems that one of the best ways would be using lego with win-acme’s scripts for Windows environment.

    Deep breath. Yeah, it’s doable, slightly annoying. Adding extra custom tech which I would want to avoid in the very first place. But for the systems that NEED it, it still would be better option than NOT having it at all. Maybe when I’m not too busy, I’ll sort it out. It’s doable for sure, if the motivation and need just is there. - Yes, ZeroSSL is also lacking the DNS-PERSIST-01 support, so, double bummer, but life is.

    #TLS #ZeroSSL #LetsEncrypt #winacme #ACME #Lego

  11. DNS-PERSIST-01 ACME validation - Uh oh, constant annoyance, clients are moving so slowly. I would really love to have this with ZeroSSL. It seems that one of the best ways would be using lego with win-acme’s scripts for Windows environment.

    Deep breath. Yeah, it’s doable, slightly annoying. Adding extra custom tech which I would want to avoid in the very first place. But for the systems that NEED it, it still would be better option than NOT having it at all. Maybe when I’m not too busy, I’ll sort it out. It’s doable for sure, if the motivation and need just is there. - Yes, ZeroSSL is also lacking the DNS-PERSIST-01 support, so, double bummer, but life is.

    #TLS #ZeroSSL #LetsEncrypt #winacme #ACME #Lego

  12. Let's Encrypt больше не вариант? Обзор альтернатив

    4 июня 2026 года Let's Encrypt тихо обновил пользовательское соглашение до версии 1.7. Новый пункт обязывает получателя сертификата подтвердить, что он не находится под полными санкциями США. В России это вызвало волну обсуждений — и не без причины. В Беларуси пока тихо. Но тихо — не значит «нас это не касается».

    habr.com/ru/articles/1046618/

    #SSL #HTTPS #сертификаты #ACME #certbot #санкции #ZeroSSL #PKI #Беларусь #letsencrypt

  13. Let's Encrypt больше не вариант? Обзор альтернатив

    4 июня 2026 года Let's Encrypt тихо обновил пользовательское соглашение до версии 1.7. Новый пункт обязывает получателя сертификата подтвердить, что он не находится под полными санкциями США. В России это вызвало волну обсуждений — и не без причины. В Беларуси пока тихо. Но тихо — не значит «нас это не касается».

    habr.com/ru/articles/1046618/

    #SSL #HTTPS #сертификаты #ACME #certbot #санкции #ZeroSSL #PKI #Беларусь #letsencrypt

  14. Let's Encrypt больше не вариант? Обзор альтернатив

    4 июня 2026 года Let's Encrypt тихо обновил пользовательское соглашение до версии 1.7. Новый пункт обязывает получателя сертификата подтвердить, что он не находится под полными санкциями США. В России это вызвало волну обсуждений — и не без причины. В Беларуси пока тихо. Но тихо — не значит «нас это не касается».

    habr.com/ru/articles/1046618/

    #SSL #HTTPS #сертификаты #ACME #certbot #санкции #ZeroSSL #PKI #Беларусь #letsencrypt

  15. ZeroSSL - Please add IPv6 support and a DNS-PERSIST-01 validation method. #ZeroSSL #IPv6 #SSL #TLS #certificates #networking

  16. ZeroSSL - Please add IPv6 support and a DNS-PERSIST-01 validation method. #ZeroSSL #IPv6 #SSL #TLS #certificates #networking

  17. ZeroSSL - Please add IPv6 support and a DNS-PERSIST-01 validation method. #ZeroSSL #IPv6 #SSL #TLS #certificates #networking

  18. ZeroSSL - Please add IPv6 support and a DNS-PERSIST-01 validation method. #ZeroSSL #IPv6 #SSL #TLS #certificates #networking

  19. ZeroSSL a kind request, supporting DNS-PERSIST-01 validation method would be just awesome! - Thanks #ZeroSSL #LetsEncrypt #Certificates

  20. Oh joy. Nothing like an early Sunday morning surprise: your website is down, and you realize you forgot about your Buypass certificate’s expiry date. Anyway, a quick ACME client reconfiguration and I’ve switched over to another European provider, ZeroSSL. Problem solved. #SysAdminLife #WebsiteDown #TLS #HTTPS #ACME #Buypass #ZeroSSL #Developer #Fail #SundayMorning

  21. Oh joy. Nothing like an early Sunday morning surprise: your website is down, and you realize you forgot about your Buypass certificate’s expiry date. Anyway, a quick ACME client reconfiguration and I’ve switched over to another European provider, ZeroSSL. Problem solved. #SysAdminLife #WebsiteDown #TLS #HTTPS #ACME #Buypass #ZeroSSL #Developer #Fail #SundayMorning

  22. Oh joy. Nothing like an early Sunday morning surprise: your website is down, and you realize you forgot about your Buypass certificate’s expiry date. Anyway, a quick ACME client reconfiguration and I’ve switched over to another European provider, ZeroSSL. Problem solved. #SysAdminLife #WebsiteDown #TLS #HTTPS #ACME #Buypass #ZeroSSL #Developer #Fail #SundayMorning

  23. Oh joy. Nothing like an early Sunday morning surprise: your website is down, and you realize you forgot about your Buypass certificate’s expiry date. Anyway, a quick ACME client reconfiguration and I’ve switched over to another European provider, ZeroSSL. Problem solved. #SysAdminLife #WebsiteDown #TLS #HTTPS #ACME #Buypass #ZeroSSL #Developer #Fail #SundayMorning

  24. Anyone know a European alternative to LetsEncrypt?

    And I mean: get a free (or very reasonably priced) certificate for a private web site with one or two sub-domains?

    #letsencrypt #zerossl #europe #eu #web #hosting

  25. Anyone know a European alternative to LetsEncrypt?

    And I mean: get a free (or very reasonably priced) certificate for a private web site with one or two sub-domains?

    #letsencrypt #zerossl #europe #eu #web #hosting

  26. Anyone know a European alternative to LetsEncrypt?

    And I mean: get a free (or very reasonably priced) certificate for a private web site with one or two sub-domains?

    #letsencrypt #zerossl #europe #eu #web #hosting

  27. Anyone know a European alternative to LetsEncrypt?

    And I mean: get a free (or very reasonably priced) certificate for a private web site with one or two sub-domains?

    #letsencrypt #zerossl #europe #eu #web #hosting

  28. Anyone know a European alternative to LetsEncrypt?

    And I mean: get a free (or very reasonably priced) certificate for a private web site with one or two sub-domains?

    #letsencrypt #zerossl #europe #eu #web #hosting

  29. @mirabilos
    I use #zerossl for my web and mail servers.

    https://zerossl.com/

    I no longer use certbot but acme.sh to generate certificates.

    ZeroSSL is the default CA for https://acme.sh/

    edit: I fall back to letsencrypt when I need a wildcard cert such as *.domain.tld

  30. @mirabilos
    I use #zerossl for my web and mail servers.

    https://zerossl.com/

    I no longer use certbot but acme.sh to generate certificates.

    ZeroSSL is the default CA for https://acme.sh/

    edit: I fall back to letsencrypt when I need a wildcard cert such as *.domain.tld

  31. @mirabilos
    I use #zerossl for my web and mail servers.

    https://zerossl.com/

    I no longer use certbot but acme.sh to generate certificates.

    ZeroSSL is the default CA for https://acme.sh/

    edit: I fall back to letsencrypt when I need a wildcard cert such as *.domain.tld

  32. @mirabilos
    I use #zerossl for my web and mail servers.

    https://zerossl.com/

    I no longer use certbot but acme.sh to generate certificates.

    ZeroSSL is the default CA for https://acme.sh/

    edit: I fall back to letsencrypt when I need a wildcard cert such as *.domain.tld

  33. @mirabilos
    I use #zerossl for my web and mail servers.

    https://zerossl.com/

    I no longer use certbot but acme.sh to generate certificates.

    ZeroSSL is the default CA for https://acme.sh/

    edit: I fall back to letsencrypt when I need a wildcard cert such as *.domain.tld

  34. I recently started to replace #nginx with @caddy and it's as satisfying as it is scary to replace a complex config that spans five included files and a total of about 400 lines with a single Caddyfile of around 80 lines.

    And on top of that #Caddy also made certbot redundant as it takes care of fetching and renewing the tls certs from #LetsEncrypt and keeps a #ZeroSSL backup for all of my domains.

    I think I'm in love..

  35. I recently started to replace #nginx with @caddy and it's as satisfying as it is scary to replace a complex config that spans five included files and a total of about 400 lines with a single Caddyfile of around 80 lines.

    And on top of that #Caddy also made certbot redundant as it takes care of fetching and renewing the tls certs from #LetsEncrypt and keeps a #ZeroSSL backup for all of my domains.

    I think I'm in love..

  36. I recently started to replace #nginx with @caddy and it's as satisfying as it is scary to replace a complex config that spans five included files and a total of about 400 lines with a single Caddyfile of around 80 lines.

    And on top of that #Caddy also made certbot redundant as it takes care of fetching and renewing the tls certs from #LetsEncrypt and keeps a #ZeroSSL backup for all of my domains.

    I think I'm in love..

  37. I recently started to replace #nginx with @caddy and it's as satisfying as it is scary to replace a complex config that spans five included files and a total of about 400 lines with a single Caddyfile of around 80 lines.

    And on top of that #Caddy also made certbot redundant as it takes care of fetching and renewing the tls certs from #LetsEncrypt and keeps a #ZeroSSL backup for all of my domains.

    I think I'm in love..

  38. I recently started to replace #nginx with @caddy and it's as satisfying as it is scary to replace a complex config that spans five included files and a total of about 400 lines with a single Caddyfile of around 80 lines.

    And on top of that #Caddy also made certbot redundant as it takes care of fetching and renewing the tls certs from #LetsEncrypt and keeps a #ZeroSSL backup for all of my domains.

    I think I'm in love..

  39. Switching my Caddy server to use ZeroSSL for AMCE SSL certification, replacing LetsEncrypt, was as easy as adding this to my Caddyfile:

    {
        acme_ca https://acme.zerossl.com/v2/DV90
    }
    

    #CaddyServer #Caddy #SSL #ACME #LetsEncypt #ZeroSSL

  40. Switching my Caddy server to use ZeroSSL for AMCE SSL certification, replacing LetsEncrypt, was as easy as adding this to my Caddyfile:

    {
        acme_ca https://acme.zerossl.com/v2/DV90
    }
    

    #CaddyServer #Caddy #SSL #ACME #LetsEncypt #ZeroSSL

  41. Switching my Caddy server to use ZeroSSL for AMCE SSL certification, replacing LetsEncrypt, was as easy as adding this to my Caddyfile:

    {
        acme_ca https://acme.zerossl.com/v2/DV90
    }
    

    #CaddyServer #Caddy #SSL #ACME #LetsEncypt #ZeroSSL

  42. Switching my Caddy server to use ZeroSSL for AMCE SSL certification, replacing LetsEncrypt, was as easy as adding this to my Caddyfile:

    {
        acme_ca https://acme.zerossl.com/v2/DV90
    }
    

    #CaddyServer #Caddy #SSL #ACME #LetsEncypt #ZeroSSL

  43. @jpmens what are other #ACME providers except of @letsencrypt and where are they located?

    @european_alternatives lists only one (#BuypassGoSSL) so far:
    european-alternatives.eu/categ

    #ZeroSSL itself seems to be Austria-based, but is a subsidiary of HID Global (Texas, US) which again is a subsidiary of ASSA Abloy (Sweden), so it being independent from US-shenanigans is not quite clear.

    We should probably start shipping a "ca-certififcates-eu" package in distributions...

  44. @jpmens what are other #ACME providers except of @letsencrypt and where are they located?

    @european_alternatives lists only one (#BuypassGoSSL) so far:
    european-alternatives.eu/categ

    #ZeroSSL itself seems to be Austria-based, but is a subsidiary of HID Global (Texas, US) which again is a subsidiary of ASSA Abloy (Sweden), so it being independent from US-shenanigans is not quite clear.

    We should probably start shipping a "ca-certififcates-eu" package in distributions...

  45. @jpmens what are other #ACME providers except of @letsencrypt and where are they located?

    @european_alternatives lists only one (#BuypassGoSSL) so far:
    european-alternatives.eu/categ

    #ZeroSSL itself seems to be Austria-based, but is a subsidiary of HID Global (Texas, US) which again is a subsidiary of ASSA Abloy (Sweden), so it being independent from US-shenanigans is not quite clear.

    We should probably start shipping a "ca-certififcates-eu" package in distributions...

  46. @jpmens what are other #ACME providers except of @letsencrypt and where are they located?

    @european_alternatives lists only one (#BuypassGoSSL) so far:
    european-alternatives.eu/categ

    #ZeroSSL itself seems to be Austria-based, but is a subsidiary of HID Global (Texas, US) which again is a subsidiary of ASSA Abloy (Sweden), so it being independent from US-shenanigans is not quite clear.

    We should probably start shipping a "ca-certififcates-eu" package in distributions...