It’s breaking the access to the website and not a good look for the “app store for Linux”. A lesson in central points of failure?

  • @[email protected]
    link
    fedilink
    English
    141 year ago

    https://www.flathub.org is using Let’s encrypt. Their certs only last 90 days so you need a script to make sure they are updated and pushed to your site. https://flathub.org uses Globalsign which lasts for 13 months. My guess is they don’t have a process for reconciling the two types of end dates.

      • @Unquote0270
        link
        English
        41 year ago

        Even just manually, how hard is it to put a reminder in a calendar somewhere? I’ve never understood how/why this happens, it’s really but difficult.

      • @[email protected]
        link
        fedilink
        English
        11 year ago

        You don’t even need to automate. Certbot comes with a systemd timer called certbot-renew.timer which does this for you.

      • HousePanther
        link
        fedilink
        English
        31 year ago

        Yeah, it isn’t a good look for flathub. I looked at the certificate and the Subject Alternative Names section was missing the www prefix. Why they’re not using Let’s Encrypt and certbot beats me because this could all be automated.

          • HousePanther
            link
            fedilink
            English
            31 year ago

            I use the DNS-01 challenge to take advantage of wildcard certs. Every 30 days, I have a cron job force a renewal, send a SIGHUP to nginx and I am back in biz. Ez-pezy

  • kbity
    link
    fedilink
    -11 year ago

    And it’s still less shit than Snaps. It’s the giant douche and turd sandwich situation with this stuff.