Commit Graph

110 Commits (cbe0e663eced8d77ec8400d8e790845fcf3b0de5)

Author SHA1 Message Date
Vincent Bernat cbe0e663ec nixos/acme: don't use --reuse-key 3 years ago
Lucas Savva 920a3f5a9d nixos/acme: Fix webroot issues 3 years ago
Robert Hensing f0e20e0975 acme: Determine offline whether renewal is due 3 years ago
Lucas Savva 514a0b6d8a nixos/acme: Fix bash issue, enable debug 3 years ago
Lucas Savva 5b4f9c4244 nixos/acme: Set up webroot as non-root user 3 years ago
Lucas Savva a01df7dc46 nixos/acme: Incorporate review suggestions 3 years ago
Sandro Jäckel a7e31c64d9
nixos/acme: Suggest directory used security.acme.certs.<name>.webroot 3 years ago
Lucas Savva 92a3a37153 nixos/acme: Remove all systemd-tmpfiles usage 3 years ago
Lucas Savva f670e1dc23 nixos/acme: change service umask to 0023 3 years ago
Lucas Savva 351065f970 nixos/acme: reduce dependency on tmpfiles 3 years ago
Lucas Savva 85769a8cd8 nixos/acme: prevent mass account creation 3 years ago
Lucas Savva e3120397a5 nixos/acme: Remove dependency on system version for hash 3 years ago
Lucas Savva 79ecf069f5
nixos/acme: Add data.email to othersHash in nixos > 20.09 4 years ago
Lucas Savva 76401c9a3b
nixos/acme: lego run whenen account is missing 4 years ago
Lucas Savva 89d134b3fd
nixos/acme: Use more secure chmods 4 years ago
Jeroen Simonetti cc3ce9a13a nixos/security/acme: Add DNS resolver option 4 years ago
Lucas Savva 1edd91ca09
nixos/acme: Fix ocspMustStaple option and add test 4 years ago
Andreas Rammhold 2c0ee52d91
nixos/security/acme: order after nss-lookup.target 4 years ago
Lucas Savva 34b5c5c1a4
nixos/acme: More features and fixes 4 years ago
Lucas Savva 67a5d660cb
nixos/acme: Run postRun script as root 4 years ago
Lucas Savva 1b6cfd9796
nixos/acme: Fix race condition, dont be smart with keys 4 years ago
Lucas Savva 982c5a1f0e
nixos/acme: Restructure module 4 years ago
datafoo cc37d7edd7 nixos/acme: execute a single lego command 4 years ago
J. Konrad Tegtmeier-Rottach 1719353619 nixos/acme: add extraLegoRunFlags option 4 years ago
J. Konrad Tegtmeier-Rottach a0189a4c49 nixos/acme: add extraLegoFlags option 4 years ago
Lucas Savva 037ef70d5c
nixos/acme: fix incorrect example 4 years ago
Lucas Savva 47da7aafdf
nixos/acme: update documentation 4 years ago
Thomas Churchman 8a061ebdef nixos/acme: improve some descriptions 4 years ago
Emily ef7e6eeaf4 nixos/acme: set maintainers to acme team 4 years ago
Ismaël Bouya 8e88b8dce2
nixos/acme: Fix postRun in acme certificate being ran at every run 4 years ago
Arian van Putten 5c1c642939 Revert "nixos/acme: Fix allowKeysForGroup not applying immediately" 4 years ago
Lucas Savva 827d5e6b44
acme: share accounts between certificates 4 years ago
Jörg Thalheim d7ff6ab94a
acme: create certificates in subdirectory 4 years ago
Maximilian Bosch 1a5289f803
nixos/acme: don't depend on multi-user.target inside a container 4 years ago
Emily 62e34d1c87 nixos/acme: change default keyType to ec256 4 years ago
Yegor Timoshenko c32da2ed9c nixos/acme: force symlink from fullchain.pem to cert.pem 4 years ago
Martin Weinelt 3575555fa8
nixos/acme: apply chmod and ownership unconditionally 4 years ago
Emily ffb7b984b2 nixos/acme: add extraLegoRenewFlags option 4 years ago
Emily b522aeda5a nixos/acme: add ocspMustStaple option 4 years ago
Emily 7b14bbd734 nixos/acme: adjust renewal timer options 4 years ago
Martin Weinelt 5ff9441471
nixos/acme: renew after rebuild and on boot 4 years ago
Emily 8ecbd97f82 nixos/acme: move the crt to fullchain.pem 4 years ago
Lucas Savva 636eb23157
nixos/acme: Fix b.example.com test 4 years ago
Lucas Savva ac983cff48
nixos/acme: add dns-01 test, fix cert locating bug 4 years ago
Lucas Savva 2181313c54
nixos/acme: simplify email resolve logic 4 years ago
Lucas Savva 769fbf9254 nixos/acme: fix some descriptions, default acceptTerms to false 4 years ago
Lucas Savva 61665e3363 nixos/acme: ignore tmpfiles rules for null webroots 4 years ago
Lucas Savva 9467f2ba2c nixos/acme: Add logic to select right email address 4 years ago
Lucas Savva 1e3607d331 nixos/acme: replace simp-le with lego client 4 years ago
Ben Price 83972b80b4 nixos/acme: implement postRun using ExecStartPost 5 years ago