this post was submitted on 30 Jan 2025
332 points (99.4% liked)

Selfhosted

41954 readers
470 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I think it's a good idea, everyone should be automating this anyway.

you are viewing a single comment's thread
view the rest of the comments
[–] kokesh@lemmy.world 6 points 1 week ago (4 children)

I just wish I wouldn't have to renew certs so often.

[–] bjoern_tantau@swg-empire.de 14 points 1 week ago (2 children)

You're not supposed to do it manually.

[–] ramble81@lemm.ee 8 points 1 week ago (1 children)

Tell that to all the embedded device manufacturers… switches, appliances, nas, etc.

There’s a whole load of things that will have a massive administrative burden if the frequency is dropped.

[–] bjoern_tantau@swg-empire.de -5 points 1 week ago
[–] kokesh@lemmy.world 6 points 1 week ago (2 children)

My server does it automatically, but I have few services I can't make to read the certs from server storage, so I have to manually copy cert content. Especially Adguard Home for some reason refuses to read my certs.

[–] bjoern_tantau@swg-empire.de 11 points 1 week ago (1 children)

Have the same problem. But symlinks or copying them via cron solved it for me.

[–] kokesh@lemmy.world 4 points 1 week ago

Yes! yes | cp -Lrf /etc/letsencrypt/live/..domain.../*.pem /var/snap/adguard-home/current

[–] forbiddenlake@lemmy.world 5 points 1 week ago

You could use a reverse proxy to terminate tls, and take the tls off of ad guard itself.

[–] jagged_circle@feddit.nl 2 points 1 week ago

Its done for better security

[–] tofuwabohu@slrpnk.net 1 points 1 week ago (1 children)

Have you tried to automate it?

[–] kokesh@lemmy.world 0 points 1 week ago (1 children)

Fullchain.pem works. Privkey doesn't. I've tried chmod 777 (yes, I know, just testing) and still can't access the file.

[–] Illecors@lemmy.cafe 1 points 1 week ago (1 children)

Whole path has to be accessible, not just the file itself. All dirs above the file need to have the executable bit set that affects the user accessing the file.

[–] kokesh@lemmy.world 1 points 1 week ago

I know, but for some reason Adguard can read the fullchain, not privkey. Now it works.