Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

certbot works, but I'm not a fan of using it.

I'd much rather configure nginx / Apache myself so I know exactly what's happening and can mold the solution to fit whatever use cases I have.



certbot --standalone

You'll need to turn off your web server for a minute or two while certbot runs ('standalone' means it starts up a temporary web server of its own and binds to port 80 for a moment) but then it leaves the new certificate for you in a few files in /usr/local/ somewhere, and you proceed to edit the nginix.conf file yourself. It works great.


You don't need to turn off your webserver, you can use `certbot certonly --webroot -w /path/to/docroot ...` where /path/to/docroot points to the document root, i.e. the root directory of the website contents, provided that your webserver is listening on port 80 (HTTP).

On my personal servers, I have the regular webserver configured to listen on port 443 (HTTPS) only, and I have a separate webserver on port 80 that's only used for ACME challenges. All other HTTP requests are immediately upgraded to HTTPS. Among other things, this split solves the cyclic dependency between the webserver not starting without TLS certificates, but also being required to provision certificates.

Details: https://blog.bethselamin.de/posts/how-i-run-certbot.html


You can also use the dns challenge and not worrying for the web server at all.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: