diff options
| author | Lucas Savva <lucas@m1cr0man.com> | 2020-01-12 21:05:57 +0000 |
|---|---|---|
| committer | Lucas Savva <lucas@m1cr0man.com> | 2020-01-12 21:28:53 +0000 |
| commit | 1e3607d331a650e958b48e0c6a9231e68dd023f8 (patch) | |
| tree | 2d7fe36e13466c0c432680c5d2eda417c03c4bc7 /pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch | |
| parent | 832d1f4a571bee6a8b719792ec10426205bebea1 (diff) | |
nixos/acme: replace simp-le with lego client
Lego allows users to use the DNS-01 challenge to validate their
certificates. It is mostly backwards compatible, with a few
caveats.
- extraDomains can no longer have different webroots to the
main webroot for the cert.
- An email address is now mandatory for account creation
The following other changes were required:
- Deprecate security.acme.certs.<name>.plugins, as this was
specific to simp-le
- Rename security.acme.validMin to validMinDays, to avoid
confusion and errors. Lego requires the TTL to be specified in
days
- Add options to cover DNS challenge (dnsProvider,
credentialsFile, dnsPropagationCheck)
- A shared state directory is now used (/var/lib/acme/.lego)
to avoid account creation rate limits and share credentials
between certs
Diffstat (limited to 'pkgs/development/python-modules/python-mapnik/python-mapnik_std_optional.patch')
0 files changed, 0 insertions, 0 deletions
