The recent @letsencrypt shutdown of TLS-SNI-01 validation (due to idiotic hosting providers) is very disappointing. It was by far the most convenient, hands-off, universal validation mechanism. https://community.letsencrypt.org/t/2018-01-11-update-regarding-acme-tls-sni-and-shared-hosting-infrastructure/50188 …
-
-
That’s what I do: # Within each site config server block: include snippets/letsencrypt.conf; # letsencrypt.conf: location ~ .well-known/acme-challenge/ { root /var/www/letsencrypt; default_type text/plain; }
-
Yes, this is the plan. But the previous config required zero additional config stanzas (other than the cert itself).
- Show replies
New conversation -
-
-
I have a generic http vhost which only serves the acme challenges and does https redirects, nothing else - all content is in https vhosts...
-
Example for Apache and nginx: https://gist.github.com/TobiX/63b698db7de37ec7d09f380ea0da0a24 …
End of conversation
New conversation -
-
-
"manual http" users can continue being lazy
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.