Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you cannot get a TLS cert for internal infrastructure in a few minutes, I'd recommend you start looking into why.


no good document on it and it is not very important for me ( I run it on homelab).

still wonder how to do it in minutes.


I use this (in a docker image) to generate certificates automatically: https://github.com/adferrand/dnsrobocert

Expect to spend 1-2 hours first time you try it until you can setup the correct DNS records, API keys and configuration.

Afterwards it's pretty hands off, every three months you'll receive an email from letsencrypt and you'll have to rerun this script to regenerate your certificates. Takes 2-3 minutes max (but of course you still need to distribute your certificates to all relevant services...)


If you run traefik it's even easier: https://docs.traefik.io/https/acme/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: