I need to generate a private key, send you the public key, and get you to sign it. Somewhere in there, I need to prove I have control of the HTTP server on the existing A record, or that I can add a DNS TXT.
I can't say I'm a fan of shipping a SimpleHttp server baked into the tool, listening on port 80 (so run as root) which is also trying to deal with account authentication at the same time as generating the CSR, scanning directories of private keys to try to figure out how to sign the ACME nonce, etc. Getting this 'letsencrypt-auto' process to be able to receive and respond to HTTP requests on my domain is a different class of problem than getting a specially crafted file into a specific path on my domain. The former is clearly much more difficult in production than the latter....
Why not simply a script which;
- Takes as it's input the CSR and privkey files
- Does an HTTP GET to retrieve the ACME nonce
- Sign the nonce, generate the file you need to put on your webserver and tells you
the path to put it.
- Prompt to 'Press ENTER once the file is in place...'
- HTTP GET to indicate file is in place, server verifies, and returns the completed
full-chain cert.
(An optional parameter with a path to copy the signed-nonce file would make the script non-interactive.)This could be written in a few lines of bash, right, assuming you could find an openssl command line which could sign the nonce in the correct form?
Keep in mind you have to repeat this process every 6 months with your live site, so what we want are simple composable / pluggable tools which don't try to own too much of the overall process, right?
Alternatively, ship two separate scripts (le-verify, le-certify) which create the ACME validation file and retrieve the cert once the file is in place, respectively.
I'm also not quite sure, why is there any concept of a user account on letsencrypt at all? Hopefully it is optional, I don't see what in this process requires that I register an "account" with them?