- Jul 28, 2024
-
-
Jan Alexander Steffens (heftig) authored
With RSA 4096 instead of ECDSA.
-
- Jul 20, 2024
-
-
Jan Alexander Steffens (heftig) authored
certbot switched to ECDSA by default about two years ago, following [recommended practices][1]. We are currently using RSA with 4096 bits, which is extremely slow to sign. Using ECDSA should give us a nice speedup. [1]: https://wiki.mozilla.org/Security/Server_Side_TLS#Intermediate_compatibility_.28recommended.29
-
- Oct 17, 2020
-
-
Kristian Klausen authored
certbot by default sleep 1-480 seconds before renewing, to avoid all people renewing at :00. In our case the logic is is unnecessary as systemd is handling it (RandomizedDelaySec=24h).
-
- May 14, 2019
-
-
Florian Pritz authored
service Some machines use certbot, but don't have nginx so we shouldn't force the reload here. Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Mar 24, 2019
-
-
Florian Pritz authored
Signed-off-by:
Florian Pritz <bluewind@xinu.at>
-
- Sep 21, 2016
-
-
Jan Alexander Steffens (heftig) authored
-
- Jun 20, 2016
-
-
Sven-Hendrik Haase authored
-