You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ACME is a protocol, not a company. A private CA — step-ca, smallstep, Caddy's internal one — speaks it on your own network, answers the challenge over your own LAN, and issues from your own root. Nothing is published, no public domain is involved, and the board never talks to the internet.
That matters because private authorities issue short-lived certificates on purpose: step-ca's default is 24 hours. Renewing that by hand is not a plan, and @machinchose's fallback — acme.sh in a cron job on the board — is what people are doing today. Installing a certificate yourself (#45) is in v2.33.0; this is the step after it.
Scope: an opt-in client on the board, configured with a directory URL, the CA bundle to trust for it, an optional EAB key pair and the names to request. HTTP-01 only. Renewal at two thirds of the lifetime, retried with backoff, with the result in the log and a metric.
Deliberately out of scope: DNS-01, Let's Encrypt and wildcards. Let's Encrypt can issue for a LAN device through DNS-01, but it means a credential that can edit your DNS zone sitting on a board that can reflash four computers, your management hostname published in Certificate Transparency logs, and — if you use a wildcard to hide that — the wildcard's key on the BMC. The 47-day lifetimes coming for public certificates are a reason to automate, not a reason to put a public certificate on a BMC.
The board has ~87 MB of usable memory and about 11 % rootfs headroom, so acme.sh-driven-by-the-daemon versus a compiled-in client gets measured before it gets chosen.
Tracked as SQU-284. Upvote if you run a private CA, and say which one.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
ACME is a protocol, not a company. A private CA — step-ca, smallstep, Caddy's internal one — speaks it on your own network, answers the challenge over your own LAN, and issues from your own root. Nothing is published, no public domain is involved, and the board never talks to the internet.
That matters because private authorities issue short-lived certificates on purpose: step-ca's default is 24 hours. Renewing that by hand is not a plan, and @machinchose's fallback — acme.sh in a cron job on the board — is what people are doing today. Installing a certificate yourself (#45) is in v2.33.0; this is the step after it.
Scope: an opt-in client on the board, configured with a directory URL, the CA bundle to trust for it, an optional EAB key pair and the names to request. HTTP-01 only. Renewal at two thirds of the lifetime, retried with backoff, with the result in the log and a metric.
Deliberately out of scope: DNS-01, Let's Encrypt and wildcards. Let's Encrypt can issue for a LAN device through DNS-01, but it means a credential that can edit your DNS zone sitting on a board that can reflash four computers, your management hostname published in Certificate Transparency logs, and — if you use a wildcard to hide that — the wildcard's key on the BMC. The 47-day lifetimes coming for public certificates are a reason to automate, not a reason to put a public certificate on a BMC.
The board has ~87 MB of usable memory and about 11 % rootfs headroom, so acme.sh-driven-by-the-daemon versus a compiled-in client gets measured before it gets chosen.
Tracked as SQU-284. Upvote if you run a private CA, and say which one.
Status: OpenAll reactions