With many thanks to The Mighty Buzzard riding shotgun and helping me through some misunderstandings, I updated the certificates (certs) for all of SoylentNews' domains. Our certs are now good through: Wednesday, June 12, 2019.
Everything seemed to go as expected. If you experience any issues, please mention them here, or pop onto our IRC channel using your favorite client or the web interface and speak up in the #dev or #Soylent channel.
(Score: 4, Interesting) by Whoever on Thursday March 14 2019, @03:00PM (5 children)
I hope you are now automatically updating the certificates. It's quite easy to do this with Let's Encrypt.
(Score: 5, Interesting) by martyb on Thursday March 14 2019, @03:08PM
Yes, it is possible. No, it's not likely. TheMightyBuzzard expressed misgivings about automagically updating DNS records. I must say I share, them, too. I see a couple places where some automation would come in handy, but I would still prefer to have a human in the loop... Just. In. Case.
Besides, you are talking to the QA guy for the site. I am positively gifted in making things go sidedays which is NOT something you want happening in a running system.
Do be aware that we have a total of 10 systems to keep in sync, as well.
So, I'm not saying never, but it will be a long while before we would go fully automated, and there are reasons for it.
Wit is intellect, dancing.
(Score: 2) by isostatic on Thursday March 14 2019, @03:53PM (3 children)
We should be pushing certificate lengths down to 3 month maximum at a minimum, and probably shorter than that.
(Score: 3, Informative) by NotSanguine on Thursday March 14 2019, @04:37PM (2 children)
Three months is the default for Let's Encrypt certificates.
No, no, you're not thinking; you're just being logical. --Niels Bohr
(Score: 2) by isostatic on Thursday March 14 2019, @08:17PM (1 child)
And they want to go shorter than that, but given they issue something like a million certificates every day for free, they can't currently justify it.
(Score: 2) by NotSanguine on Thursday March 14 2019, @08:58PM
Thanks. I had no idea. I just figured they were like TGV. /sarc
If you want, you can teach me to tie my shoes or shake properly after pissing.
No, no, you're not thinking; you're just being logical. --Niels Bohr