Show HN: ACME Let's Encrypt client – binary releases, works like 'make'
github.com
github.com
example.com {
root path/to/root
}
And Let's Encrypt will automatically be used. It's amazingly simple.I wonder if in the future we'll see things like mod_acme that automate Let's Encrypt into other servers.
Presumably we'll start seeing tighter integration with other web servers, why can't there be a mod_le that automatically downloads certs from LE? And why wouldn't you want that?
Good work and good ideas though. I haven't looked at the Python client, but it seems like there may be some valid points here.
In contrast, the official client can absolutely work without having root access. You can install it locally (pip install --user letsencrypt) and change all working directories to paths your user can write to using a configuration file.
It should be possible to use the client without having root access, by passing --state (and perhaps --hooks) to use a state directory you control.
My motivation for not requiring root is shared hosting: I have a regular user witch access to an Apache webroot directory. They didn't fully automate Let's Encrypt, but they provide a script which installs certificates for the central webserver. So I have to download and run any ACME client myself to get my certificates.
I would read the source code and compile ($ go build) it.
The bigger issue is probably firewalls (in front of the server getting a cert) only allowing inbound on 80 and 443.
443 is not really ideal for this purpose, but requiring control of it is probably the least worst option, security-wise.
Put a public key in the DNS, sign the CSR with the corresponding private key, the CA will fetch DNS, verify the signature, and then sign your certificate.
If I could just put a public key in DNS, sign stuff with the corresponding private key, and send the signed request via POST to LE, then they can easily check that I control the DNS, and I can automate it (and never have to change the webserver’s content or DNS).
What I’m looking for is "I write a value into DNS once, and use that to prove at any future point at which it exists that I still control the DNS".
In this example, by putting an RSA public key in there. (the very same I use for the CSR)
The problem, apparently, is that CA forum rules require that a random challenge be used. Of course this doesn't make much sense in the context of ACME, where you have a private key identifying the user account. But this obstructs the specification of a deterministic challenge for DNS, alas.
does this work with azure ASP.NET?