mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,5 Tsd.
aktive Profile

#letsencrypt

4 Beiträge4 Beteiligte0 Beiträge heute

Si vous utilisez #LetsEncrypt, vous avez sans doute reçu les messages « Let's Encrypt Expiration Emails Update » qui vous préviennent que cette AC n'enverra plus de rappels que vos certificats vont bientôt expirer. C'est parce qu'un meilleur système est maintenant disponible, #ARI.
ARI permet à une AC utilisant le protocole #ACME d'indiquer à ses clients des suggestions sur le renouvellement des certificats. Il est décrit dans ce #RFC.

bortzmeyer.org/9773.html

www.bortzmeyer.orgBlog Stéphane Bortzmeyer: RFC 9773: ACME Renewal Information (ARI) Extension
Fortgeführter Thread

2/2
Im Grunde war ich "sauer" als #LetsEncrypt aufn Markt kam...😂 🤷‍♂️ Ich verwende das lets schließlich seit 1985...🤪

#letsSpot wäre historisch korrekt (wenn da nicht das doppel-S wäre...)

#pitSpot ist evtl. bisschen doppeldeutig witzig... so von wegen der Vieldeutigkeit von pit im Englischen?!?

Fortgeführter Thread

This explains why an Android device from 2015 can't connect to modern sites secured by a Let's Encrypt cert.

But a much older 2010 MacBook or 2013 iPad, still can.

And that's with default built-ins, before we get to strategies like replacing IE/Safari with Firefox ESR (which can even enable Windows XP to browse the modern web), or replacing Google Android with PostmarketOS.

en.wikipedia.org/wiki/Postmark

en.wikipedia.orgpostmarketOS - Wikipedia

When you quantify browser support and translate it to real devices, the sad state of Android device vendors really stinks.

I had no idea it was *this* bad.

For example, a Samsung Galaxy or Motorola Moto from 2015:
* ships Android 5.
* may upgrade to one new major release, Android 6, released the next year in 2016.
* minor support updates until 2017.

1 major OS release and you're out,
2 years of minor updates.

en.wikipedia.org/wiki/Moto_G_(

en.wikipedia.org/wiki/Samsung_

en.wikipedia.orgMoto G (3rd generation) - Wikipedia

Eh, that is not cool: installed the #LetsEncrypt add-on in my fresh #HomeAssistant installation. And because it is brand new, I tried the test certificate server first. Everything works ...

Except, HA has no option to force renew the certificate. And now I'm stuck for 30 days with the test cert, which the browser does not accept.

This is broken.

How to Install Centmin Mod on #AlmaLinux #VPS (5 Minute Quick-Start Guide) Here's a detailed step-by-step guide on how to install Centmin Mod on AlmaLinux VPS server.
What is Centmin Mod?
Centmin Mod is a shell-based, menu-driven installer that automates the deployment of a LEMP (Linux, Nginx, MariaDB/MySQL, PHP-FPM) stack on CentOS, AlmaLinux, and Rocky Linux servers. Designed for efficiency and performance, it ...
Continued 👉 blog.radwebhosting.com/how-to- #csf #centminmod #letsencrypt #php

How to Install Centmin Mod on AlmaLinux VPS
RadWeb, LLC · How To Install Centmin Mod On AlmaLinux VPS (5 Minute Quick-Start Guide) - VPS Hosting Blog | Dedicated Servers | Reseller HostingHere's a detailed step-by-step guide on how to install Centmin Mod on AlmaLinux VPS server.

My current conspiracy theory: Now that #letsencrypt has more or less destroyed the market for domain certificates and people are more interested in using client/user certificate, Google throws the market a lifeline by removing clientAuth from acceptable certificates in the browser context with some vague "it's about security" arm waving. #NerdTalk

1/4

How to Install Centmin Mod on #AlmaLinux #VPS (5 Minute Quick-Start Guide) Here's a detailed step-by-step guide on how to install Centmin Mod on AlmaLinux VPS server.
What is Centmin Mod?
Centmin Mod is a shell-based, menu-driven installer that automates the deployment of a LEMP (Linux, Nginx, MariaDB/MySQL, PHP-FPM) stack on CentOS, AlmaLinux, and Rocky Linux servers. Designed for efficiency and performance, it ...
Continued 👉 blog.radwebhosting.com/how-to- #csf #centminmod #php #letsencrypt

How to Install Centmin Mod on AlmaLinux VPS
RadWeb, LLC · How To Install Centmin Mod On AlmaLinux VPS (5 Minute Quick-Start Guide) - VPS Hosting Blog | Dedicated Servers | Reseller HostingHere's a detailed step-by-step guide on how to install Centmin Mod on AlmaLinux VPS server.

Remember the threads¹² about #LetsEncrypt removing a crucial key usage from certificates issued by them in predictive obedience to their premium sponsor Google?

We were at first concerned about #SMTP. While I had lived through this problem with #StartSSL by #StartCom back in 2011, I only had a vague recollection of Jabber but recalled in detail that it broke server-to-server SMTP verification (whether the receiving server acted on it or just documented it).

Well, turns out someone now reported that it indeed breaks #XMPP entirely: https://community.letsencrypt.org/t/do-not-remove-tls-client-auth-eku/237427/66

This means that it will soon no longer be possible at all to operate Jabber (XMPP) servers because the servers use the operating system’s CA certificate bundle for verification, which generally follows the major browsers’ root stores, which has requirements from the CA/Browser forum who apparently don’t care about anything else than the webbrowser, and so no CA whose root certificate is in that store will be allowed to issue certificates suitable for Jabber/XMPP server-to-server communication while these CAs are the only ones trusted by those servers.

So, yes, Google’s requirement change is after all breaking Jabber entirely. Ein Schelm, wer Böses dabei denkt.

Update: it also breaks the connections between domain registrars and registries, with most being unaware that there even is a problem at this time, let alone the crazily short timeframe. See the thread linked to in a self-reply, which also confirms that the CA/Browser forum is supporting Google in this (possibly by means of Google paying, my interpretation).

While https://nerdcert.eu/ by @jwildeboer would in theory help, it’s not existent yet, and there’s not just the question of when it will be included in operating systems’ root CA stores but whether it will be included in them at all.

Google’s policy has no listed contact point, and the CA/B forum isn’t something mere mortals can complain to, so I’d appreciate if someone who can, and who has significant skills to argument this in English and is willing to, to bring it to them.

① mine: https://toot.mirbsd.org/@mirabilos/statuses/01JV8MDA4P895KK6F91SV7WET8
② jwildeboer’s: https://social.wildeboer.net/@jwildeboer/114516238307785904

Let's Encrypt Community Support · Do *NOT* remove TLS Client Auth EKU!I was also bit by this. I switched to tlsserver profile, and when my XMPP certificate got renewed today, it failed to make any S2S connections :(. I'd to revert to classic profile. Could we please keep TLS client auth EKU ? Thanks!

yet another ACME client, based on uacme: github.com/llfw/lfacme

good:
+ uses uacme and POSIX /bin/sh
+ better configuration/hook system than dehydrated
+ comes with manpages
+ small and simple
+ supports Kerberized dns-01 domain validation

bad:
- only supports Kerberized dns-01 domain validation (but this could be improved)
- only tested on FreeBSD (but this could be improved too)

/cc @_bapt_

a simple ACME client based on uacme. Contribute to llfw/lfacme development by creating an account on GitHub.
GitHubGitHub - llfw/lfacme: a simple ACME client based on uacmea simple ACME client based on uacme. Contribute to llfw/lfacme development by creating an account on GitHub.

Anyone with experience of using #dehydrated to request #TLS certificates from #LetsEncrypt?

Thanks to the support team at @beasts (thanks Alex) I've corrected my fat finger error in the config and I can see that the correct DNS records appear to be created in my public DNS zone but then the dehydrated client just times out after a good 5 minutes with `challenge record not found in DNS`.

I'm currently trying to use the LE staging environment so I don't hit any limits that might break any of my existing http auth certs.

UPDATE: Thx to the replies, I implemented the change for all my domains, did a `certbot renew --dry-run` and that succeeded. Yay to a cleaner config :)

#NerdQuestion. When I move {server [...] } blocks in `/etc/nginx/nginx.conf` to separate files in the `/etc/nginx/conf.d` directory, will certbot still find them and will automatic renewals just keep working as before? Anyone with experience on that?

Just requested that Auto Encrypt¹ is added to the list of @letsencrypt clients for Node.js and that Kitten² is added to the list of projects that integrate Let’s Encrypt support:

github.com/letsencrypt/website
github.com/letsencrypt/website

I originally requested that Auto Encrypt and Site.js (the precursor to Kitten, now sunset) be added to the list in 2021. It was not approved (no reason given), so hopefully this time will be different.

github.com/letsencrypt/website

¹ codeberg.org/small-tech/auto-e
² kitten.small-web.org

GitHubAdd Auto Encrypt to clients.json by aral · Pull Request #1921 · letsencrypt/websiteVon aral