pdl
@pdl@social.tchncs.de
Seit einigen Jahren wird mein Drang zum Selfhosting immer größer. Begonnen haben meine Erfahrungen Ende 2012 mit einem Raspberry Pi 1B, später ein RasPi 3, RasPi 4 mit 4 GB RAM und aktuell ein recycleter Thinkcentre 700.
Zunächst nur Nextcloud (damals noch Owncloud) mit Apache und MySQL (inzwischen MariaDB), später weitere Spielereien wie Mozilla Syncserver, und einiges per Docker: Immich, Wanderer, Dawarich, Reitti, Invidious, Libretranslate, Searxng, Snowflake, Stirlingpdf, FMD.
- Comment on Anyone using 6-day certs yet? 2 days ago:
@Ooops I do not understand what you mean with "they are failing to advertise this". Letsencrypt has announced in in their blog:
https://letsencrypt.org/2025/01/16/6-day-and-ip-certs
https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued
The profiles are documented:
https://letsencrypt.org/docs/profiles/
It is your deciscion what profile to use. If you use the shortlived profile and your key is compromised, you benefit from the short lifetime. This benefit you have regardless of the availability of the 90 day certs. - Comment on Anyone using 6-day certs yet? 2 days ago:
@Ooops @stratself Certbot renews a certificate when the remaining lifetime is lower than 30 %. If you change the profile from tlsserver (90 days) to shortlived (6 days), you do not need to adjust the renewal interval manually, because it is relative to the cert livetime.
I think it is not Letsencrypt's part to document how to use the different profiles with certbot. It should be explained in the documentation of the ACME client (certbot and others). - Comment on Anyone using 6-day certs yet? 2 days ago:
@stratself I am using the shortlived profile since about February this year. Works as designed. Cert renewal is done via mod_md in apache2. No additional script like certbot needed. I had to switch
MDProfile tlsserver
to
MDProfile shortlived
in the md.conf. Renewal is done at 33 % remaining lifetime by default. - Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@flandish This is no backdoor. This is an denial of service. It's a big difference. I have to estimate the risk and decide if I want to take it. ZeroSSL uses the infrastructure of Sectigo, an US company. Sectigo can pull the plug very easily. So it is no alternative. Maybe Actalis or Certum are good alternatives. But the government of Poland has not been unproblematic in the past.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@A_norny_mousse @state_electrician Three certs are free. If you need more (or wildcard certs) you have to pay.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@slazer2au @Sibbo The administration of domain names is not done by ICANN. ICANN is responsible for managing IP addresses, ports, AS numbers. There are local registries for the administration of domain names. My .de domains are administered by DENIC in Germany. .net and .com are administered by US companies. This domains eventually can be shutdown by US authorities.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@flandish If US authorities want to fake my server, they can use any CA, regardless which CA I originally used.
Of course, US authorities can force Letsencrypt to revoke my certificates and block any renewing. This is very unlikely to happen. If it happens, I have to change my CA. There would be a downtime for my private services, but there is no data corruption or data loss on my servers. - Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA. - Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@flandish @possiblylinux127 Letsencrypt just has the public keys, no private keys. If Letsencrypt gives my public keys to sam, it does not matter, because public keys are public. My private key is under my administration only.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@Sibbo Of course. Actually, there are 200 million active certificates issued by Letsencrypt. Revoking them, 200 million websites would be down. 200 million websites all over the world, including US. I don't think this is a realistic scenario.
If you are worried about that, you should avoid any software developed in US. You should avoid any software which itself or its sources are hosted in US. Mastodon is available on Github, this is Microsoft. US authorities may force Github to shutdown or infiltrate the hosted sources with spyware. - Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
@Sibbo I do not see any problem with Letsencrypt. Any CA which is widely trusted has to follow the same rules. This rules are set up by the CA Browser Forum. Which metadata does LE collect? My server's IP address, domain and subdomain, mail address. These are logged in the CT logs. Every CA has to log all certificates in a public CT log. Regardless which CA I choose, these data are public. There are not any critical data or metadata that LE can collect.