Since the beginning of this year, Let’s Encrypt rolled out a new shortlived profile for certificates that make them valid for only 160 hours. The intention, as they say, is to encourage automation and reduce the window of certificate compromise (because revocation is somewhat a flakey thing).

Yet, I haven’t seen a lot of news about it since then. Hence the question: is this shorter cert thingy something you considered and deployed for your homelab?

As for me I’ve set up lego-acme with profile: "shortlived" on my rig. Lego runs on a bihourly cronjob, but only renews when a cert has >=3 days to expiry. It’s been pretty much a set-and-forget experience, although some more monitoring would be nice.

  • antsu@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    11
    ·
    15 hours ago

    I migrated from vanilla Nginx Proxy Manager to NPMplus (because of CrowdSec), and it defaults to short-lived certificates. Other than temporarily making my Uptime Kuma SSL monitors completely freak out because my certificates “were too close to expiration”, everything still works exactly the same.

    • dan@upvote.au
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 hours ago

      I’m just using regular Nginx, which I’ve been using for 20 years. What does Nginx Proxy Manager or npmplus do better?

      I’ve been meaning to try Angie too, which is a fork of Nginx.

      • antsu@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Not really sure they do anything “better”, it’s mainly for convenience. It’s an all-in-one solution with a nice UI and sane defaults. That helps me have a somewhat consistent setup across all my hosted services. If you’re happy with managing Nginx directly, then you probably have no reason to use these.

        • dan@upvote.au
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 hours ago

          Makes sense! I didn’t realise it has a UI.

          I’ve got a bunch of snippets in /etc/nginx/snippets/, so for example I just need to add include snippets/proxy.conf to a server block to add most of the configuration needed for a reverse proxy. I’ve been using Nginx for long enough that I just write the rest of the server block by hand.

    • eco_game@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      3
      ·
      15 hours ago

      Interesting, I didn’t know NPMplus was a thing. Looks like I’ve got some researching and possibly reconfiguring to do…