All other web servers I looked at (nginx, apache, lighttpd) still require at least a reload for an updated certificate and a configuration file change for a new certificate to be used.
I wonder how caddy works with the very low 5 certificates per public suffix and week limit. Does it automatically bundle domains and request a single certificate with SANs?
Thanks for your comments; glad you like the way we integrated it!
> Does it automatically bundle domains and request a single certificate with SANs?
No, as it turns out, SAN makes the auto-management code highly complicated, since names could overlap in different certs, etc. It also complicates renewals and gives more room for error (e.g. 49 of the domains verify but 1 fails, so the cert can't be renewed). So I've opted not to support SAN certificates for the automatic HTTPS feature. But you can of course still issue your own SAN certificates and use those.
Right now, Caddy reloads itself when it renews certificates, but as of Caddy 0.8.2 (slated for release any day now), Caddy will do it all in-process, no reloading.
Yeah, Caddy is amazing. Matt is doing an awesome job with it.
> I wonder how caddy works with the very low 5 certificates per public suffix and week limit. Does it automatically bundle domains and request a single certificate with SANs?
I directed Matt to this discussion so I hope can answer these questions for you. I unfortunately cannot.
(note: I know that these are two very different things and I know how complicated it is to get all that state correct and to properly re-initialize the SSL context - still, as certificates get more and more short-lived, this would be a cool thing to have)
Here's an nginx one. Took about < 5 mins to add to my docker-compose file and start proxying my existing site
https://hub.docker.com/r/dmp1ce/nginx-proxy-letsencrypt/
Would love to see a caddy version of same
---
hmm, I guess the current caddy docker images can do this though though they need a little more configuration
One of my tasks this week is to get this in motion.
https://github.com/Xe/dotfiles/tree/master/ansible/roles/cad...
The hardest thing to figure out is HPKP (and I still have not).
I used https://cipherli.st/
hopefully it's good, if not it isn't protecting anything important really