Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Stop spreading FUD: it does not "mess with all sorts of configuration".

It does more than you'd expect, IMO.

> letsencrypt-auto is a wrapper which installs some dependencies from your OS standard package repositories (e.g. using apt-get or yum), and for other dependencies it sets up a virtualized Python environment with packages downloaded from PyPI.

http://letsencrypt.readthedocs.org/en/latest/using.html

I was certainly a bit surprised when apt-get ran.



As said by others if you run it with certonly it doesn't touch the config at all. My cronjob contains a

path/to/letsencrypt-auto certonly --webroot --renew-by-default -w /var/www/letsencrypt/ -d example.com

and puts the signed certificates into /etc/letsencrypt/live/excample.com/fullchain.pem . This is followed by a service nginx reload

I did not trust their automatic configuration as well so I simply configured nginx to use the keys + cert and to serve .well-known/acme from /var/www/letsencrypt/ for all my domains.

That's all. It works quite fine and if something does not work (e.g. python breaks.) such that the renewal is unsuccessful. LE will send you an email in advance (I think 30 days) so you have plenty of time to look after it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: