this post was submitted on 30 Jan 2025
333 points (99.4% liked)

Selfhosted

42196 readers
435 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I think it's a good idea, everyone should be automating this anyway.

you are viewing a single comment's thread
view the rest of the comments
[–] kokesh 6 points 2 weeks ago (4 children)

I just wish I wouldn't have to renew certs so often.

[–] doughless 15 points 2 weeks ago (1 children)
[–] [email protected] 7 points 2 weeks ago

Fuck Apple and Microshit

[–] [email protected] 14 points 2 weeks ago (2 children)

You're not supposed to do it manually.

[–] [email protected] 8 points 2 weeks ago (1 children)

Tell that to all the embedded device manufacturers… switches, appliances, nas, etc.

There’s a whole load of things that will have a massive administrative burden if the frequency is dropped.

[–] [email protected] -5 points 2 weeks ago
[–] kokesh 6 points 2 weeks ago (2 children)

My server does it automatically, but I have few services I can't make to read the certs from server storage, so I have to manually copy cert content. Especially Adguard Home for some reason refuses to read my certs.

[–] [email protected] 11 points 2 weeks ago (1 children)

Have the same problem. But symlinks or copying them via cron solved it for me.

[–] kokesh 4 points 2 weeks ago

Yes! yes | cp -Lrf /etc/letsencrypt/live/..domain.../*.pem /var/snap/adguard-home/current

[–] forbiddenlake 5 points 2 weeks ago

You could use a reverse proxy to terminate tls, and take the tls off of ad guard itself.

[–] [email protected] 2 points 2 weeks ago

Its done for better security

[–] [email protected] 1 points 2 weeks ago (1 children)

Have you tried to automate it?

[–] kokesh 0 points 2 weeks ago (1 children)

Fullchain.pem works. Privkey doesn't. I've tried chmod 777 (yes, I know, just testing) and still can't access the file.

[–] [email protected] 1 points 2 weeks ago (1 children)

Whole path has to be accessible, not just the file itself. All dirs above the file need to have the executable bit set that affects the user accessing the file.

[–] kokesh 1 points 2 weeks ago

I know, but for some reason Adguard can read the fullchain, not privkey. Now it works.