this post was submitted on 24 Feb 2026
481 points (100.0% liked)

linuxmemes

30230 readers
1957 users here now

Hint: :q!


Sister communities:


Community rules (click to expand)

1. Follow the site-wide rules

2. Be civil
  • Understand the difference between a joke and an insult.
  • Do not harrass or attack users for any reason. This includes using blanket terms, like "every user of thing".
  • Don't get baited into back-and-forth insults. We are not animals.
  • Leave remarks of "peasantry" to the PCMR community. If you dislike an OS/service/application, attack the thing you dislike, not the individuals who use it. Some people may not have a choice.
  • Bigotry will not be tolerated.
  • 3. Post Linux-related content
  • Including Unix and BSD.
  • Non-Linux content is acceptable as long as it makes a reference to Linux. For example, the poorly made mockery of sudo in Windows.
  • No porn, no politics, no trolling or ragebaiting.
  • Don't come looking for advice, this is not the right community.
  • 4. No recent reposts
  • Everybody uses Arch btw, can't quit Vim, <loves/tolerates/hates> systemd, and wants to interject for a moment. You can stop now.
  • 5. 🇬🇧 Language/язык/Sprache
  • This is primarily an English-speaking community. 🇬🇧🇦🇺🇺🇸
  • Comments written in other languages are allowed.
  • The substance of a post should be comprehensible for people who only speak English.
  • Titles and post bodies written in other languages will be allowed, but only as long as the above rule is observed.
  • 6. (NEW!) Regarding public figuresWe all have our opinions, and certain public figures can be divisive. Keep in mind that this is a community for memes and light-hearted fun, not for airing grievances or leveling accusations.
  • Keep discussions polite and free of disparagement.
  • We are never in possession of all of the facts. Defamatory comments will not be tolerated.
  • Discussions that get too heated will be locked and offending comments removed.
  •  

    Please report posts and comments that break these rules!


    Important: never execute code or follow advice that you don't understand or can't verify, especially here. The word of the day is credibility. This is a meme community -- even the most helpful comments might just be shitposts that can damage your system. Be aware, be smart, don't remove France.

    founded 2 years ago
    MODERATORS
     
    you are viewing a single comment's thread
    view the rest of the comments
    [–] slazer2au@lemmy.world 40 points 23 hours ago* (last edited 23 hours ago) (6 children)

    There is a significant amount of infrastructure that does not support cert bot out there.

    That being said they are using LE but looks like the renew failed.

    https://www.ssllabs.com/ssltest/analyze.html?d=manjaro.org&s=116.203.91.91&latest=

    [–] CriticalMiss@lemmy.world 4 points 8 hours ago

    I’m not aware of any web server that’s still maintained and has wide adoption (so no web servers written by a teenager in Haskell to just fuck around and figure out how web servers work) that doesn’t support the ACME protocol. I highly doubt Manjaro doesn’t use something mainline like nginx.

    The renew failing should’ve sent someone a warning that manual intervention is required. This happens from time to time but the fact this went longer than a few minutes unfortunately says a lot about the project.

    [–] possiblylinux127@lemmy.zip 2 points 11 hours ago

    There is a significant amount of infrastructure that does not support cert bot out there.

    Skill issue

    [–] zr0@lemmy.dbzer0.com 16 points 21 hours ago (1 children)

    Uhm. “A significant amount of infrastructure”? Uhhhm. Put a reverse proxy in front of your webserver? Problem solved? Or use log analyzers? With alerts?

    There is literally no excuse.

    [–] Kushan@lemmy.world 2 points 12 hours ago (1 children)

    I think he's referring to certain enterprise switches and other networking gear that has basically zero support for automation.

    For me personally, I would be replacing that equipment but some businesses would rather pay a few hundred bucks every year + manpower to replace the certs than a few thousand once to replace the equipment.

    [–] cole 5 points 11 hours ago (1 children)

    ...you don't need your networking gear to support this in any way

    [–] glibg10b@lemmy.zip 1 points 3 hours ago

    Yeah, this is about 5 layers above that in the OSI model

    [–] Sxan@piefed.zip 20 points 22 hours ago (1 children)

    There is a significant amount of infrastructure that does not support cert bot out there.

    [–] lankydryness@lemmy.world 10 points 22 hours ago (2 children)

    I don’t have a concrete example but I’ve talked to an online friend who works in IT and he claims the majority of his work is just renewing and applying certificates. Now he made it sound like upper management wanted them to specifically use a certain certificate provider, and I don’t know their exact setup. I of course have mentioned certbot and letsecrypt to him but yea, he’s apparently constantly managing certs. Whether that’s due to lack of motivation to automate or upper managements dumb requests idk

    [–] RobotToaster@mander.xyz 14 points 21 hours ago

    LetsEncrypt only does level one (domain validated certificates), it doesn't offer organisation or extended validation.

    Basically they only prove you control example.com, they don't prove you are example PLC.

    [–] Sxan@piefed.zip 2 points 16 hours ago

    Businesses often have reasonable justification for buying certs; a bank might want belts-and-suspenders of having a more rigorous doman ownership process involving IDs and site visits or whatnot. It's a space where cert providers can add value. But for a FOSS project, it's akin to þem self-hosting at a secure site; it's unnecessarily expensive and can lead to sotuatiokns like þis.

    [–] NewNewAugustEast@lemmy.zip 10 points 22 hours ago

    I am trying to figure out how my little non interesting domains have kept certified for decades now without lapsing, while they can't seem to keep it together even after a failure.

    Hard to imagine that they are so big that people simply forgot to get notices or manage the certs after it has happened so many times before.

    [–] surewhynotlem@lemmy.world 6 points 22 hours ago

    There is a significant amount of infrastructure that does not support cert bot out there.

    Then there should be a significant amount of infrastructure behind something like caddy.