this post was submitted on 30 Jan 2025
330 points (99.4% liked)

Selfhosted

41674 readers
584 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I think it's a good idea, everyone should be automating this anyway.

you are viewing a single comment's thread
view the rest of the comments
[–] kokesh@lemmy.world 6 points 5 days ago (4 children)

I just wish I wouldn't have to renew certs so often.

[–] bjoern_tantau@swg-empire.de 14 points 5 days ago (2 children)

You're not supposed to do it manually.

[–] ramble81@lemm.ee 8 points 5 days ago (1 children)

Tell that to all the embedded device manufacturers… switches, appliances, nas, etc.

There’s a whole load of things that will have a massive administrative burden if the frequency is dropped.

[–] bjoern_tantau@swg-empire.de -5 points 5 days ago
[–] kokesh@lemmy.world 6 points 5 days ago (2 children)

My server does it automatically, but I have few services I can't make to read the certs from server storage, so I have to manually copy cert content. Especially Adguard Home for some reason refuses to read my certs.

[–] bjoern_tantau@swg-empire.de 11 points 5 days ago (1 children)

Have the same problem. But symlinks or copying them via cron solved it for me.

[–] kokesh@lemmy.world 4 points 5 days ago

Yes! yes | cp -Lrf /etc/letsencrypt/live/..domain.../*.pem /var/snap/adguard-home/current

[–] forbiddenlake@lemmy.world 5 points 5 days ago

You could use a reverse proxy to terminate tls, and take the tls off of ad guard itself.

[–] jagged_circle@feddit.nl 2 points 4 days ago

Its done for better security

[–] tofuwabohu@slrpnk.net 1 points 5 days ago (1 children)

Have you tried to automate it?

[–] kokesh@lemmy.world 0 points 5 days ago (1 children)

Fullchain.pem works. Privkey doesn't. I've tried chmod 777 (yes, I know, just testing) and still can't access the file.

[–] Illecors@lemmy.cafe 1 points 5 days ago (1 children)

Whole path has to be accessible, not just the file itself. All dirs above the file need to have the executable bit set that affects the user accessing the file.

[–] kokesh@lemmy.world 1 points 5 days ago

I know, but for some reason Adguard can read the fullchain, not privkey. Now it works.