Learn about Centmin Mod LEMP Stack today
Register Now

Letsencrypt Letsencrypt Free SSL Public Beta December 3th 6PM GMT

Discussion in 'Domains, DNS, Email & SSL Certificates' started by eva2000, Dec 3, 2015.

  1. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
  2. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
  3. rdan

    rdan Well-Known Member

    5,447
    1,408
    113
    May 25, 2014
    Ratings:
    +2,201
    Local Time:
    1:51 AM
    Mainline
    10.2
    Does Centmin_09LE support both non www and ww domain?
     
  4. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    yup :)
     
  5. rdan

    rdan Well-Known Member

    5,447
    1,408
    113
    May 25, 2014
    Ratings:
    +2,201
    Local Time:
    1:51 AM
    Mainline
    10.2
    But not possible to issue an already created vhost right?
     
  6. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    not right now, soon addons/letsencrypt.sh will be able to SSL - Letsencrypt Question... | Centmin Mod Community

     
  7. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    letsencrypt client has been updated to 0.1.1 Let's Encrypt client 0.1.1 released - Let's Encrypt Community Support For Centmin Mod Letsencrypt integration right now every run always updates the letsencrypt client before trying to obtain a Letsencrypt SSL certificate :)

    Code:
    /root/.local/share/letsencrypt/bin/letsencrypt --help 
    
      letsencrypt [SUBCOMMAND] [options] [-d domain] [-d domain] ...
    
    The Let's Encrypt agent can obtain and install HTTPS/TLS/SSL certificates.  By
    default, it will attempt to use a webserver both for obtaining and installing
    the cert. Major SUBCOMMANDS are:
    
      (default) run        Obtain & install a cert in your current webserver
      certonly             Obtain cert, but do not install it (aka "auth")
      install              Install a previously obtained cert in a server
      revoke               Revoke a previously obtained certificate
      rollback             Rollback server configuration changes made during install
      config_changes       Show changes made to server config during installation
      plugins              Display information about installed plugins
    
    Choice of server plugins for obtaining and installing cert:
    
      --apache          Use the Apache plugin for authentication & installation
      --standalone      Run a standalone webserver for authentication
      (nginx support is experimental, buggy, and not installed by default)
      --webroot         Place files in a server's webroot folder for authentication
    
    OR use different plugins to obtain (authenticate) the cert and then install it:
    
      --authenticator standalone --installer apache
    
    More detailed help:
    
      -h, --help [topic]    print this message, or detailed help on a topic;
                            the available topics are:
    
       all, automation, paths, security, testing, or any of the subcommands or
       plugins (certonly, install, nginx, apache, standalone, webroot, etc)
    Code:
    /root/.local/share/letsencrypt/bin/letsencrypt --help webroot
    usage:
      letsencrypt [SUBCOMMAND] [options] [-d domain] [-d domain] ...
    
    The Let's Encrypt agent can obtain and install HTTPS/TLS/SSL certificates.  By
    default, it will attempt to use a webserver both for obtaining and installing
    the cert. Major SUBCOMMANDS are:
    
      (default) run        Obtain & install a cert in your current webserver
      certonly             Obtain cert, but do not install it (aka "auth")
      install              Install a previously obtained cert in a server
      revoke               Revoke a previously obtained certificate
      rollback             Rollback server configuration changes made during install
      config_changes       Show changes made to server config during installation
      plugins              Display information about installed plugins
    
    optional arguments:
      -h, --help            show this help message and exit
      -c CONFIG_FILE, --config CONFIG_FILE
                            config file path (default: None)
    
    webroot:
      Webroot Authenticator
    
      -w WEBROOT_PATH, --webroot-path WEBROOT_PATH
                            public_html / webroot path. This can be specified
                            multiple times to handle different domains; each
                            domain will have the webroot path that preceded it.
                            For instance: `-w /var/www/example -d example.com -d
                            www.example.com -w /var/www/thing -d thing.net -d
                            m.thing.net` (default: None)
     
    Last edited: Dec 17, 2015
  8. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
  9. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    OVH becomes platinum sponsor for Letsencrypt and looking to integrate Letsencrypt into their control panel OVH becomes a Platinum Sponsor - Let's Encrypt Community Support :cool:(y)

    OVH NEWS | THE LATEST ON IT INNOVATIONS AND TRENDS - OVH
     
    Last edited: Dec 24, 2015
  10. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    woah Let's Encrypt got a bunch of new sponsors including Vultr and Google Chrome https://twitter.com/letsencrypt :D

    Current Sponsors - Let's Encrypt - Free SSL/TLS Certificates

    Become a Sponsor - Let's Encrypt - Free SSL/TLS Certificates

    rouch calculation of ~$2.4 million in sponshorship for ~185k certificates issued so far Let's Encrypt Stats - Let's Encrypt - Free SSL/TLS Certificates and growing :)
     
    Last edited: Dec 24, 2015
  11. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    got a few minutes ?

    Let's encrypt is now the 5th largest CA provider in the world ! Surprisingly Comodo ECC has such a huge number !

    upload_2015-12-31_2-58-57.png

    how are people using LE

    upload_2015-12-31_3-2-49.png

    upload_2015-12-31_3-6-14.png

    upload_2015-12-31_3-12-23.png

     
    Last edited: Dec 31, 2015
  12. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    sweet Let's Encrypt DNS challenge verfication has been enabled on staging dev API end point DNS challenge is in staging - Feature Requests - Let's Encrypt Community Support :)

    definitely needed if you run load balanced cluster of servers and need to validate your domain for Letsencrypt SSL certificate issuance :)

    If you're playing with Centmin Mod 123.09beta01le2 branch and already setup the client after running nginx vhost centmin.sh menu option 2 or 22, you can edit the webroot.ini config file at /etc/letsencrypt/webroot.ini and switch back to staging server by uncommenting it and commenting out the live one for beta invitees
    Code:
    # Always use the staging/testing server
    #server = https://acme-staging.api.letsencrypt.org/directory
    
    # for beta invitees
    server = https://acme-v01.api.letsencrypt.org/directory
    
    However, Centmin Mod isn't setup for dns challenge routines only webroot so not much testing can be done yet. Staging is still useful if you want to get around public beta rate limits for general testing.
     
  13. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
  14. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    whoops Malvertising campaign used a free certificate from Let's Encrypt | CSO Online

     
  15. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
  16. ModeltogTossen

    ModeltogTossen I wish I could??

    313
    97
    28
    Dec 20, 2015
    Denmark
    Ratings:
    +143
    Local Time:
    6:51 PM
    1.9.12
    10.0.23
    Yes, and I think its going to explode now because dns-1 are in production..
     
  17. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    not really yet look at authentication challenges methods in stats Let's Encrypt Stats - Let's Encrypt - Free SSL/TLS Certificates - hardly any use dns-01 right now

    probably due to clients support lacking for dns-01

    upload_2016-1-30_19-37-25.png
     
  18. ModeltogTossen

    ModeltogTossen I wish I could??

    313
    97
    28
    Dec 20, 2015
    Denmark
    Ratings:
    +143
    Local Time:
    6:51 PM
    1.9.12
    10.0.23
    If we look at it like this in isolation then you're correct - but I'm very sure that is to change in a very short time.. Lets see in about 2-3 months from now. Personally I'm excited.. That also apply on your work - when you take the choice to merge your letsencrypt work into the 09beta branch.. Oh - the future is bright.. :joyful:
     
  19. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+
    yes will be something awesome for all Centmin Mod LEMP stack users :D
     
  20. eva2000

    eva2000 Administrator Staff Member

    54,907
    12,240
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +18,811
    Local Time:
    3:51 AM
    Nginx 1.27.x
    MariaDB 10.x/11.4+