Since the beginning of this year, Let’s Encrypt rolled out a new shortlived profile for certificates that make them valid for only 160 hours. The intention, as they say, is to encourage automation and reduce the window of certificate compromise (because revocation is somewhat a flakey thing).

Yet, I haven’t seen a lot of news about it since then. Hence the question: is this shorter cert thingy something you considered and deployed for your homelab?

As for me I’ve set up lego-acme with profile: "shortlived" on my rig. Lego runs on a bihourly cronjob, but only renews when a cert has >=3 days to expiry. It’s been pretty much a set-and-forget experience, although some more monitoring would be nice.

  • antsu@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 hours ago

    Not really sure they do anything “better”, it’s mainly for convenience. It’s an all-in-one solution with a nice UI and sane defaults. That helps me have a somewhat consistent setup across all my hosted services. If you’re happy with managing Nginx directly, then you probably have no reason to use these.

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      Makes sense! I didn’t realise it has a UI.

      I’ve got a bunch of snippets in /etc/nginx/snippets/, so for example I just need to add include snippets/proxy.conf to a server block to add most of the configuration needed for a reverse proxy. I’ve been using Nginx for long enough that I just write the rest of the server block by hand.