Since the beginning of this year, Let's Encrypt rolled out a new shortlived profile for certificates that make them valid for only 160 hours. The intention, as they say, is to encourage automation and reduce the window of certificate compromise (because revocation is somewhat a flakey thing).

Yet, I haven't seen a lot of news about it since then. Hence the question: is this shorter cert thingy something you considered and deployed for your homelab?

As for me I've set up lego-acme with profile: "shortlived" on my rig. Lego runs on a bihourly cronjob, but only renews when a cert has >=3 days to expiry. It's been pretty much a set-and-forget experience, although some more monitoring would be nice.

you are viewing a single comment's thread
view the rest of the comments
[–] 11 points 14 hours ago (4 children)

I migrated from vanilla Nginx Proxy Manager to NPMplus (because of CrowdSec), and it defaults to short-lived certificates. Other than temporarily making my Uptime Kuma SSL monitors completely freak out because my certificates "were too close to expiration", everything still works exactly the same.

  • source
  • hideshow 4 child comments
  • [–] 1 point 4 hours ago (2 children)

    I'm just using regular Nginx, which I've been using for 20 years. What does Nginx Proxy Manager or npmplus do better?

    I've been meaning to try Angie too, which is a fork of Nginx.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 hours ago (1 child)

    Not really sure they do anything "better", it's mainly for convenience. It's an all-in-one solution with a nice UI and sane defaults. That helps me have a somewhat consistent setup across all my hosted services. If you're happy with managing Nginx directly, then you probably have no reason to use these.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 hours ago

    Makes sense! I didn't realise it has a UI.

    I've got a bunch of snippets in /etc/nginx/snippets/, so for example I just need to add include snippets/proxy.conf to a server block to add most of the configuration needed for a reverse proxy. I've been using Nginx for long enough that I just write the rest of the server block by hand.

  • source
  • parent