Using Free SSL/TLS Certificates from Let’s Encrypt for Nginx
nginx.com
nginx.com
In my case, a lot of the routing of domains to customers is stored in a postgres database and a trigger fires an event anyways, so I have a little daemon that listens to these events and the fires off acmetool as needed in order go generate certificates.
I just completed this last week, so when I've seen this article here, I thought that I just wasted some time over this because now there's an integrated nginx solution, but thankfully, this is just an article about doing what I was doing using a tool that's more complicated to use and brings half of an OS installation as dependencies.
For those interested, https://gist.github.com/pilif/1e2610dd7aa57323e0b2 is the script in question. It's really a quick hack, but it works very well for me to auto-create nginx config files.
It's quite interesting to know that people are using the design to its full potential. Ideally, I should probably make something more library/daemon-based for these largescale, custom solutions, though of course I'd like to do it some manner of modular way that allows the existing codebase to be leveraged. For the time being only the acmeapi package within acmetool is stable and suitable for use by other libraries. Something to think about...
I know there are the hooks and that's what I'm using now, but if I could get a distinct exit code to tell me that changes happened to the certificate store, then I could get away without needing to also keeping the hooks around.
That said, this should probably be on your github issues, not in here. That also said: This was such a small issue for me that I didn't even want to bother you - but as you're coming here to post, I guess it doesn't hurt :p
I could modify acmetool to output a word 'NEEDS-RELOADING' or something, which you could grep for programmatically. But this is another option (it would have to be an option; any output from acmetool is liable to get e. mailed to people via cron) for something which can be, as you yourself admit, dealt with as well via hooks. And probably more robustly, too. So on balance, I don't think it's worth doing.
https://github.com/Xe/dotfiles/tree/master/ansible/roles/cad...
All other web servers I looked at (nginx, apache, lighttpd) still require at least a reload for an updated certificate and a configuration file change for a new certificate to be used.
I wonder how caddy works with the very low 5 certificates per public suffix and week limit. Does it automatically bundle domains and request a single certificate with SANs?
Yeah, Caddy is amazing. Matt is doing an awesome job with it.
> I wonder how caddy works with the very low 5 certificates per public suffix and week limit. Does it automatically bundle domains and request a single certificate with SANs?
I directed Matt to this discussion so I hope can answer these questions for you. I unfortunately cannot.
Thanks for your comments; glad you like the way we integrated it!
> Does it automatically bundle domains and request a single certificate with SANs?
No, as it turns out, SAN makes the auto-management code highly complicated, since names could overlap in different certs, etc. It also complicates renewals and gives more room for error (e.g. 49 of the domains verify but 1 fails, so the cert can't be renewed). So I've opted not to support SAN certificates for the automatic HTTPS feature. But you can of course still issue your own SAN certificates and use those.
Right now, Caddy reloads itself when it renews certificates, but as of Caddy 0.8.2 (slated for release any day now), Caddy will do it all in-process, no reloading.
(note: I know that these are two very different things and I know how complicated it is to get all that state correct and to properly re-initialize the SSL context - still, as certificates get more and more short-lived, this would be a cool thing to have)
Here's an nginx one. Took about < 5 mins to add to my docker-compose file and start proxying my existing site
https://hub.docker.com/r/dmp1ce/nginx-proxy-letsencrypt/
Would love to see a caddy version of same
---
hmm, I guess the current caddy docker images can do this though though they need a little more configuration
One of my tasks this week is to get this in motion.
The hardest thing to figure out is HPKP (and I still have not).
I used https://cipherli.st/
hopefully it's good, if not it isn't protecting anything important really
So I saw the light in the form of a bash-script [0], wrote a short hookscript, and now I can centrally manage through DNS.
There are a couple of example scripts [1], and it really simple to write your own.
[0] https://github.com/lukas2511/letsencrypt.sh
[1] https://github.com/lukas2511/letsencrypt.sh/wiki/Examples-fo...
Domains with this configuration get A+ on ssllabs and securityheaders.io (test with "repo.holocm.org" if you like). It includes an autorenewal script wrapped in a systemd timer unit.
There is one bug, though: The autorenewal script fails because letsencrypt crashes when stdin is not a TTY. ( https://github.com/letsencrypt/letsencrypt/issues/2523 )
I'll have to set aside a few more hours to figure this out soon. Even good documentation like this is not working for me: https://developer.mozilla.org/en-US/docs/Web/Security/Public...
I have been using Cloudflare for https for my main site only and have been deciding whether to use Cloudflare for everything or bite the bullet and set up my own https.
HTTPS from user to CF HTTPS from CF to your site
It would be accompanied by a blog post to explain how things work but got busy on other fronts.
If anyone's interested, it's at https://github.com/Landoop/ansible