this post was submitted on 30 Jan 2025
282 points (99.3% liked)

Selfhosted

41581 readers
967 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I think it's a good idea, everyone should be automating this anyway.

you are viewing a single comment's thread
view the rest of the comments
[–] kokesh@lemmy.world 6 points 1 day ago (4 children)

I just wish I wouldn't have to renew certs so often.

[–] jagged_circle@feddit.nl 2 points 6 hours ago

Its done for better security

[–] bjoern_tantau@swg-empire.de 13 points 1 day ago (2 children)

You're not supposed to do it manually.

[–] ramble81@lemm.ee 7 points 1 day ago (1 children)

Tell that to all the embedded device manufacturers… switches, appliances, nas, etc.

There’s a whole load of things that will have a massive administrative burden if the frequency is dropped.

[–] kokesh@lemmy.world 6 points 1 day ago (2 children)

My server does it automatically, but I have few services I can't make to read the certs from server storage, so I have to manually copy cert content. Especially Adguard Home for some reason refuses to read my certs.

[–] forbiddenlake@lemmy.world 3 points 16 hours ago

You could use a reverse proxy to terminate tls, and take the tls off of ad guard itself.

[–] bjoern_tantau@swg-empire.de 11 points 1 day ago (1 children)

Have the same problem. But symlinks or copying them via cron solved it for me.

[–] kokesh@lemmy.world 4 points 1 day ago

Yes! yes | cp -Lrf /etc/letsencrypt/live/..domain.../*.pem /var/snap/adguard-home/current

[–] tofuwabohu@slrpnk.net 1 points 1 day ago (1 children)

Have you tried to automate it?

[–] kokesh@lemmy.world 0 points 1 day ago (1 children)

Fullchain.pem works. Privkey doesn't. I've tried chmod 777 (yes, I know, just testing) and still can't access the file.

[–] Illecors@lemmy.cafe 1 points 20 hours ago (1 children)

Whole path has to be accessible, not just the file itself. All dirs above the file need to have the executable bit set that affects the user accessing the file.

[–] kokesh@lemmy.world 1 points 11 hours ago

I know, but for some reason Adguard can read the fullchain, not privkey. Now it works.