ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    1. Topics
    2. Tags
    3. lets encrypt
    Log in to post
    • All categories
    • NashBrydgesN

      Recommended Nginx Config As Single Proxy For Multiple Web Servers

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion nginx lets encrypt
      9
      2 Votes
      9 Posts
      2k Views
      NashBrydgesN

      Thanks @JaredBusch this will be a huge help! I'll give this a try later this evening when I'm back.

    • brianlittlejohnB

      Certbot Apache plugin broken in Fedora 26

      Watching Ignoring Scheduled Pinned Locked Moved Solved IT Discussion lets encrypt certbot apache fredora linux fedora 26 ssl ssl certificates tls
      20
      2 Votes
      20 Posts
      5k Views
      JaredBuschJ

      @zachary715 said in Certbot Apache plugin broken in Fedora 26:

      @scottalanmiller said in Certbot Apache plugin broken in Fedora 26:

      I ran into this issue, forgot about this thread, went through LetsEncrypt's threads and their solution for this problem led me... here! Very nice.

      Just did the exact same thing. Let'sEncrypt forum had the link which led me here right about the time @JaredBusch was responding in my other thread.

      It has been posted on here more than one time. I should probably find one of those posts and make @scottalanmiller tag it appropriately.

      Edit: Or too slow..

    • ObsolesceO

      IIS and LetsEncrypt

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion iis lets encrypt ssl certificates ssl
      3
      1 Votes
      3 Posts
      2k Views
      ObsolesceO

      @NashBrydges Oh this is awesome! Gonna be giving that a go on Monday or Tuesday.

    • NashBrydgesN

      Looking for how-to on setting up a proxy

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion screenconnect lets encrypt apache 2 nginx proxy
      25
      2 Votes
      25 Posts
      5k Views
      NashBrydgesN

      @JaredBusch said in Looking for how-to on setting up a proxy:

      server {
      client_max_body_size 40M;
      listen 80;
      server_name support.bundystl.com;
      rewrite ^ https://$server_name$request_uri? permanent;
      }

      Yep, got all that done and it's working well. What I was referring to was redirecting traffic to HTTPS. Essentially this is the part of the file I was missing...

      server { client_max_body_size 40M; listen 80; server_name support.bundystl.com; rewrite ^ https://$server_name$request_uri? permanent; }
    • scottalanmillerS

      Deploying an NGinx Reverse Proxy with SSL on a LAMP Server with SaltStack

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lamp proxy reverse proxy nginx salt saltstack devops web server lets encrypt ssl tls https https2
      42
      2 Votes
      42 Posts
      7k Views
      stacksofplatesS

      This way you can share the config(s) under conf.d between multiple machines using the same roles (or whatever Salt calls them) and have different main NGINX server settings.

    • AmbarishrhA

      14,766 Let's Encrypt SSL Certificates Issued to PayPal Phishing Sites

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lets encrypt ssl certificates phishing
      7
      1 Votes
      7 Posts
      1k Views
      JaredBuschJ

      There is a blacklist that all CA's have on high dollar domain names to prevent major fraud. LE cannot issue for something.microsoft.com or something.bestbuy.com for example.

      But the sub domain names used in these PayPal examples are all outside of that. They are all on valid (ish) TLD.

    • JaredBuschJ

      SSL between a proxy and its target

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion certbot lets encrypt nginx reverse proxy
      12
      1 Votes
      12 Posts
      2k Views
      DashrenderD

      @travisdh1 said in SSL between a proxy and its target:

      @Dashrender said in SSL between a proxy and its target:

      @dafyre said in SSL between a proxy and its target:

      @scottalanmiller said in SSL between a proxy and its target:

      Never had to do that. Seems like a script to pull it from time to time might be enough, though?

      Set up a passwordless scp of the /etc/letsencrypt (or /etc/certbot?) folder from the proxy to the internal machine?

      Any security risk to this? I don't know anything about it - I just see passwordless and have to ask.

      It's industry standard public/private key encryption, so shouldn't be an issue.

      You should go read up on SQRL. In my not so humble opinion, passwords have long outlived the point where they are a useful security mechanism.

      I'm fully aware of SQRL - I asked Scott on Day one of ML if he would support it when it became available, sadly it's still not released to the wild 😞

    • JaredBuschJ

      Let's Encrypt stats

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lets encrypt ssl ninja tld encryption
      7
      3 Votes
      7 Posts
      2k Views
      dafyreD

      @scottalanmiller said in Let's Encrypt stats:

      @Jason said in Let's Encrypt stats:

      I'm guessing a lot of kids/teens and college age are using let's encrpyt hence the .ninja

      I'm confused, aren't all those domains only used by ninjas?

      Go Ninja, Go Ninja, Go!

    • AmbarishrhA

      ASO alternative

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion aso hosting cpanel lets encrypt
      46
      0 Votes
      46 Posts
      7k Views
      MustaasamSaleemM

      @Ambarishrh
      First of all, I welcome you to Cloudways.com.
      I'm Mustaasam, the WordPress Community Manager at Cloudways.

      I've tested your site on Tools Pingdom, the first hit was about 2.6 seconds and in 5th attempt it was loaded in just 1.07s.

      0_1471867518408_upload-f9d7b63b-daf0-43ae-bad2-34c9a6a9a456

      Here is the URL:
      https://tools.pingdom.com/#!/bNYY17/https://www.ambarishrh.com/

    • AdamFA

      FreePBX, SelfSigned Certs, & Let's Encrypt

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion ssl certificates ssl lets encrypt freepbx
      18
      1 Votes
      18 Posts
      7k Views
      scottalanmillerS

      Yeah, that's a really awesome feature.

    • AmbarishrhA

      Let's Encrypt is now used around 4.86%

      Watching Ignoring Scheduled Pinned Locked Moved News ssl ssl certificates lets encrypt
      14
      1 Votes
      14 Posts
      3k Views
      JaredBuschJ

      @scottalanmiller said in Let's Encrypt is now used around 4.86%:

      Yeah, probably a lot less than a year before LE rules the roost. Maybe four more months? In a year it will have significant dominance, I am guessing.

      More likely about this time next year because they did not come out of beta until March

    • A

      Certbot (New Let's Encrypt Client)

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lets encrypt
      10
      1 Votes
      10 Posts
      2k Views
      A

      Found it, nevermind.....

    • AmbarishrhA

      Let's Encrypt on ASO shared server

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion aso lets encrypt ssl
      7
      2 Votes
      7 Posts
      2k Views
      AmbarishrhA

      @scottalanmiller said:

      @Ambarishrh said:

      Wanted to setup Let's Encrypt for my blog which is now hosted on ASO but as per their tech agent, this is not possible! 😞

      Is that because SSL is not offered at all?

      As per them, its only on dedicated servers and not shared. But using https://gethttpsforfree.com/ i was able to generate certs and install 🙂

    • mlnewsM

      Lets Encrypt Exits Beta

      Watching Ignoring Scheduled Pinned Locked Moved News security encryption eweek lets encrypt
      1
      3 Votes
      1 Posts
      772 Views
      No one has replied
    • A

      HTTPS Everywhere: Encryption for All WordPress.com Sites

      Watching Ignoring Scheduled Pinned Locked Moved News wordpress security encryption ssl lets encrypt
      29
      4 Votes
      29 Posts
      5k Views
      scottalanmillerS

      @tonyshowoff said:

      @scottalanmiller said:

      @tonyshowoff said:

      @Dashrender said:

      @scottalanmiller said:

      @Dashrender said:

      Frankly, I'm frustrated that ICANN has allows so many registrars and SSL cert providers. There are over 1400 CAs trusted by Windows in 2010.

      Any one of those CAs can be compromised and their root cert used to sign fake certs for any site on the internet, instantly having Windows trust those certs.

      The whole security model on the internet is just broken. We don't have secure DNS or reliable Certificate Pinning.

      It would be a monopoly if they didn't make it basically open. Or monopoly-ish. Not an open market.

      Frankly, in this case, a monopoly, like you want for healthcare, seems like the better play. The fees should either be free or extremely low, only enough to handle the costs of administration and hardware required.

      Universal coverage does not imply monopolistic treatment. Further, most countries with universal health coverage also have private systems too.

      Like Panama... good healthcare for free or suckers can pay for private American healthcare from Johns Hopkins.

      Or Bosnia, the only place I know of where the "free" is way worse than private to an insane degree, and that's because of a war so at least that's an excuse.

      Johns Hopkins is the hospital that thought that nut job who thinks the pyramids were grain stores and all kinds of whacky things led their surgical department. You'd have to be insane to get treated at a hospital letting crazies like that even work there let alone run departments.

      (Working there as a janitor would be okay, just not in healthcare portions of the business.)

      That's the kind of hospital that removes your spleen because "if God wanted you to have it, he'd not have made it make you sick." Those people scare me.

    • mlnewsM

      How Big Will the Impact of Lets Encrypt Be?

      Watching Ignoring Scheduled Pinned Locked Moved News security lets encrypt linux
      57
      2 Votes
      57 Posts
      17k Views
      travisdh1T

      @jospoortvliet said:

      using letsencrypt right now on my home server, btw. Have a cron job set up to update the cert every month or so, with an easy tool: ACME. Simpler than the 'standard' tool from Lets Encrypt, if you ask me. Go check it out at https://github.com/hlandau/acme 😉

      I had a good laugh when I spotted the ".travis Try to speed up travis" Apparently I'm slowing things down, tho I do agree that speeding me up would be a good thing 😛

    • JaredBuschJ

      Setting up LetsEncrypt on a CentOS 7 NginX proxy

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lets encrypt centos 7 nginx proxy ssl ssl certificates encryption how to real instructions
      13
      7 Votes
      13 Posts
      12k Views
      JaredBuschJ

      @travisdh1 said in Setting up LetsEncrypt on a CentOS 7 NginX proxy:

      @JaredBusch said in Setting up LetsEncrypt on a CentOS 7 NginX proxy:

      @aaronstuder said in Setting up LetsEncrypt on a CentOS 7 NginX proxy:

      Any updates to this?

      Use Certbot never this method. keep your life simpler.

      Yeah. If the old way is working, that should keep working. However, certbot is easier to use.

      When my system came up for renew after certbot was out, I installed certbot and renewed that way. everything is in the same pace. nothing had to be changed in the config files.

    • JaredBuschJ

      Let’s Encrypt will enter Public Beta on December 3, 2015

      Watching Ignoring Scheduled Pinned Locked Moved IT Discussion lets encrypt ssl certificates encryption
      6
      3 Votes
      6 Posts
      2k Views
      BRRABillB

      @MattSpeller

      Thanks for the writeup for us noobs.

    • 1
    • 2
    • 3
    • 2 / 3