@Ooops @stratself Certbot renews a certificate when the remaining lifetime is lower than 30 %. If you change the profile from tlsserver (90 days) to shortlived (6 days), you do not need to adjust the renewal interval manually, because it is relative to the cert livetime.
I think it is not Letsencrypt's part to document how to use the different profiles with certbot. It should be explained in the documentation of the ACME client (certbot and others).
pdl
@stratself I am using the shortlived profile since about February this year. Works as designed. Cert renewal is done via mod_md in apache2. No additional script like certbot needed. I had to switch
MDProfile tlsserver
to
MDProfile shortlived
in the md.conf. Renewal is done at 33 % remaining lifetime by default.
@libewa @SpiceDealer You do not need docker for running more than one service on a RasPi or another computer. Just configure the web services to listen on an arbitrary port on localhost. Set up a reverse proxy (you can do this with traefik, nginx, apache2 ...) and expose your services with unique names on standard port 443.
Of course, many services are run via docker in a very comfortable way.
@flandish This is no backdoor. This is an denial of service. It's a big difference. I have to estimate the risk and decide if I want to take it. ZeroSSL uses the infrastructure of Sectigo, an US company. Sectigo can pull the plug very easily. So it is no alternative. Maybe Actalis or Certum are good alternatives. But the government of Poland has not been unproblematic in the past.
@123 @possiblylinux127 ZeroSSL nutzt wohl die Sectigo-Infrastruktur. Also auch ein Amerikaner im Rücken, der den Stecker ziehen kann.
@A_norny_mousse @state_electrician Three certs are free. If you need more (or wildcard certs) you have to pay.
@slazer2au @Sibbo The administration of domain names is not done by ICANN. ICANN is responsible for managing IP addresses, ports, AS numbers. There are local registries for the administration of domain names. My .de domains are administered by DENIC in Germany. .net and .com are administered by US companies. This domains eventually can be shutdown by US authorities.
@flandish If US authorities want to fake my server, they can use any CA, regardless which CA I originally used.
Of course, US authorities can force Letsencrypt to revoke my certificates and block any renewing. This is very unlikely to happen. If it happens, I have to change my CA. There would be a downtime for my private services, but there is no data corruption or data loss on my servers.
@flandish Which backdoor? When I request a CA for a certificate, I send the public key to the CA. The CA does a validation and signs the certificate.
The CA does not see any traffic from my server. A man-in-the-middle needs my private key, which is under my administration. If I loose my private key, it does not matter if the certificate is signed by a US based CA or an European CA.
@flandish @possiblylinux127 Letsencrypt just has the public keys, no private keys. If Letsencrypt gives my public keys to sam, it does not matter, because public keys are public. My private key is under my administration only.
@Sibbo Of course. Actually, there are 200 million active certificates issued by Letsencrypt. Revoking them, 200 million websites would be down. 200 million websites all over the world, including US. I don't think this is a realistic scenario.
If you are worried about that, you should avoid any software developed in US. You should avoid any software which itself or its sources are hosted in US. Mastodon is available on Github, this is Microsoft. US authorities may force Github to shutdown or infiltrate the hosted sources with spyware.
@Ooops I do not understand what you mean with "they are failing to advertise this". Letsencrypt has announced in in their blog:
https://letsencrypt.org/2025/01/16/6-day-and-ip-certs
https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued
The profiles are documented:
https://letsencrypt.org/docs/profiles/
It is your deciscion what profile to use. If you use the shortlived profile and your key is compromised, you benefit from the short lifetime. This benefit you have regardless of the availability of the 90 day certs.
https://letsencrypt.org/2025/01/16/6-day-and-ip-certs