-
moparisthebest
has anyone set up CAA's tying to a specific letsencrypt account yet? and if so, do you know how to get the account id from acme.sh :'(
-
moparisthebest
also I've seen different formats for CAA iodef, should it be email@example.org or mailto:email@example.org ?
-
octagon
email should have mailto
-
octagon
`certbot show_account` prints an account url
-
octagon
it'll contain api.letsencrypt.org somewhere
-
octagon
check wwhereever acme.sh stores its stuff
-
moparisthebest
ok this prints a URL that's probably right: acme.sh --update-account --server letsencrypt
-
moparisthebest
any examples of restricting validationmethods *and* accounturi ? there's a ; after the domain, but does that seperate each? :)
-
moparisthebest
found an example where each is seperated by '; ' so guess I'll try it
-
octagon
``` issue "letsencrypt.org; validationmethods=http-01; accounturi=https://ENDPOINT.api.letsencrypt.org/acme/acct/NUMBER" iodef "mailto:caa@domain.tld" ``` I recommend keeping the uri at the end so no need to worry about ; parsing
-
moparisthebest
octagon, why do you have your flags set 0 instead of 128 ? (ie setting the critical bit that tells CAs to not issue if they don't understand something)
-
octagon
the critical flag isn't used yet afaik
-
moparisthebest
this mentions it: https://letsencrypt.org/docs/caa/#what-to-put-in-the-record
-
octagon
interesting
-
Licaon_Kter
moparisthebest: > and if so, do you know how to get the account id from acme.sh :'( `~/.acme.sh/ca/acme-v02.api.letsencrypt.org/directory/ca.conf` see `ACCOUNT_URL`
-
Licaon_Kter
singpolyma: odd to see different output for different domains (issues), I mean for one it complains about "for these but not for <input>", for another it says about DNSSEC, for other said about putting TLSA in DNS I was expecting some sort of consistency, for the main part, then add the extra stuff. For now, I'm not sure how a "good" result looks like :))
-
octagon
do any clinets check tlsa records?
-
MattJ
octagon, none that I know, but I may be wrong
-
Licaon_Kter
singpolyma: error 504 now
-
singpolyma
Licaon_Kter: once you add the TLSA records it tells you to add you can see what a good result is like. You can check what it says for cheogram.com for example
-
Licaon_Kter
I looked at jmp.chat :))
-
singpolyma
Yeah, that one isn't public on xmpp so I don't think I finished setup on it yet
-
singpolyma
Well, it is public but no one else is using it, heh
-
emus
singpolyma: you see the 502 errors right?
-
singpolyma
emus: are they happening again? I can look when I get home
-
emus
I heard from another dev
-
emus
singpolyma: said it was last night. so before the last 12 hours
-
moparisthebest
If anyone else wants a CAA template to copy I think `dig caa moparisthe.best` is right but of course I won't know for sure until my cert tries to renew :D thanks for the help octagon
-
Licaon_Kter
moparisthebest: didn't you try with staging?
-
moparisthebest
Licaon_Kter: https://upload.canchat.org:5281/file_share/X-CL96W5kWZbfsHXyrzJvGxf/ufH3q6jLTKagpWzLDMAOsQ.jpg
-
Licaon_Kter
I didn't say deploy, wtf? I said use LE staging server to get certs. And/Or block certs generation...
-
moparisthebest
Licaon_Kter: no I'm saying that book is what I did :D
-
moparisthebest
I'll have 30 days to fix it if it goes wrong... ๐
-
Licaon_Kter
:))
-
mirux
> If anyone else wants a CAA template to copy I think `dig caa moparisthe.best` is right but of course I won't know for sure until my cert tries to renew :D thanks for the help octagon Could try with --dry-run?
-
mirux
At least for certbot
-
moparisthebest
acme.sh doesn't :)
-
mirux
๐
-
Menel
acme.sh --issue --staging ...
-
Licaon_Kter
> acme.sh --issue --staging ... Exactly
-
moparisthebest
Right, could have, but didn't
-
savagepeanut
I always forget to use staging until it's too late
-
emus
http://blog.jmp.chat/b/certwatch/certwatch
-
dryan
Do you know what happend with creep.im? The warrant canary is outdated.
-
Menel
You could ask a@creep.im if they forgot, or....
-
dryan
Doesn't work anymore.
-
Menel
Well that service is on the blocklist for spam, so maybe the server where you're writing from also blocks creep.im.
-
dryan
Menel, Could you give me the list?
-
Menel
https://github.com/JabberSPAM/blacklist/blob/master/blacklist.txt
-
dryan
> https://github.com/JabberSPAM/blacklist/blob/master/blacklist.txt Thank you. It seems like last year he also skipped one. Maby he has other things on his plate. We will wait until the end of the year. . > Well that service is on the blocklist for spam, so maybe the server where you're writing from also blocks creep.im. I'm gonna send him one from danwin1210.de Thank you very much Menel. You help a lot of people in here.
-
octagon
Maybe they're actually co-opted
-
dryan
You know any real life examples where they could force somebody to update the canary, octagon ?
-
nuegia.net
github is completely broken for me
-
nuegia.net
I wish the XSF would use literally anything else other then Micro$oft services for hosting this kind of stuff
-
techmetx11
nuegia.net: this is not hosted by the XSF
-
techmetx11
this is unofficially maintained by xmpp service operators
-
nuegia.net
at this point github has gotten so bad we need a alternative frontend project for it like invidious, nitter, and bibliogram
-
Licaon_Kter
nuegia.net: gitlab dot com is worseR on every level
-
nuegia.net
sourcehut is an option
-
nuegia.net
or even just a plain http webserver would be better then micro$oft
-
unix.dog
iโm curious whatโs broken on github for you
-
dryan
> nuegia.net: gitlab dot com is worseR on every level I tought I'm the only one who feels that way.
-
nuegia.net
i don't know about worse but gitlab is pretty bad too
-
nuegia.net
if gitlab works at all, most of the time it doesn't it causes the fans to scream on my computers and bogs down my web browser
-
dryan
I have to enable javascript even to see the menus.
-
octagon
oh no the evil javascript