this post was submitted on 10 Mar 2024
53 points (86.3% liked)
Technology
59148 readers
2721 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Certbot is so problematic we still pay for most of our certificates because it’s more reliable.
I’m not sure if Caddy/Traefik is the answer but it’s clear the work should be handed over to a team with a proper focus on reliability.
Can you elaborate on this reliability issue?
Certbot is supposed to automatically renew certificates. It doesn't do that reliably in my experience.
We use it on non-critical systems and every few months I need to go in and fix things... that never happens with traditional certificates - those are setup and forget.
As for the exact problems, I don't think we've ever had the same problem twice. It's always a once off thing but it's still an hour of wasted time each and every time. If it happened on a proper production system it'd be a lot more than an hour, since whatever change is made would need a full gamut of testing / reporting / etc.