Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. Is Cloudron could get Let's encrypt SSL via DNS ?

Is Cloudron could get Let's encrypt SSL via DNS ?

Scheduled Pinned Locked Moved Solved Support
sslhttpsletsencryptdns
12 Posts 5 Posters 1.9k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JOduMonTJ Offline
      JOduMonTJ Offline
      JOduMonT
      wrote on last edited by
      #1

      Long story short my provider block (sometimes not always) many port, such as 80 (it's for my own good they said) but port 443 still open.

      I use LinuxServer/LetsEncrypt has reverse proxy mainly because it allow me to prove my authority on my subdomain via DNS than I redirect all http to https with cloudflare.

      Basically I would like to understand if it's possible to request the SSL of Let's Encrypt via DNS with Cloudron.

      mehdiM 1 Reply Last reply
      0
      • nebulonN Offline
        nebulonN Offline
        nebulon
        Staff
        wrote on last edited by
        #2

        Cloudron already uses DNS challenge for Acme2 if that domain is managed by one of the automated provider. So only if a domain has one of noop|manual|wildcardset as the provider, Cloudron will use http challenge.

        JOduMonTJ 1 Reply Last reply
        0
        • JOduMonTJ JOduMonT

          Long story short my provider block (sometimes not always) many port, such as 80 (it's for my own good they said) but port 443 still open.

          I use LinuxServer/LetsEncrypt has reverse proxy mainly because it allow me to prove my authority on my subdomain via DNS than I redirect all http to https with cloudflare.

          Basically I would like to understand if it's possible to request the SSL of Let's Encrypt via DNS with Cloudron.

          mehdiM Offline
          mehdiM Offline
          mehdi
          App Dev
          wrote on last edited by
          #3

          @JOduMonT It is possible, just configure cloudron certificate provider to Let'sEncrypt Wildcard.

          (My 2 cents : switch providers. If they are this incompetent, it does not bode well..)

          JOduMonTJ 1 Reply Last reply
          0
          • mehdiM mehdi

            @JOduMonT It is possible, just configure cloudron certificate provider to Let'sEncrypt Wildcard.

            (My 2 cents : switch providers. If they are this incompetent, it does not bode well..)

            JOduMonTJ Offline
            JOduMonTJ Offline
            JOduMonT
            wrote on last edited by
            #4

            @mehdi said in Is Cloudron could get Let's encrypt SSL via DNS ?:

            (My 2 cents : switch providers. If they are this incompetent, it does not bode well..)

            yes but they are the only one which speak an english I could almost understand 😛

            1 Reply Last reply
            0
            • nebulonN nebulon

              Cloudron already uses DNS challenge for Acme2 if that domain is managed by one of the automated provider. So only if a domain has one of noop|manual|wildcardset as the provider, Cloudron will use http challenge.

              JOduMonTJ Offline
              JOduMonTJ Offline
              JOduMonT
              wrote on last edited by
              #5

              @nebulon said in Is Cloudron could get Let's encrypt SSL via DNS ?:

              Cloudron already uses DNS challenge for Acme2 if that domain is managed by one of the automated provider. So only if a domain has one of noop|manual|wildcardset as the provider, Cloudron will use http challenge.

              so what is your saying is it should work out of the box ?

              1 Reply Last reply
              0
              • nebulonN Offline
                nebulonN Offline
                nebulon
                Staff
                wrote on last edited by
                #6

                If you are using a dns provider set in Cloudron for those domains, then yes it should work already. To be clear, I am talking about providers set as mentioned in https://cloudron.io/documentation/domains/#dns-providers

                1 Reply Last reply
                2
                • JOduMonTJ Offline
                  JOduMonTJ Offline
                  JOduMonT
                  wrote on last edited by
                  #7

                  @nebulon thanks, it worked like a charm 🙂

                  1 Reply Last reply
                  1
                  • girishG Offline
                    girishG Offline
                    girish
                    Staff
                    wrote on last edited by girish
                    #8

                    Just wanted to add that (by default) when you use one of the DNS providers, we will also try to get wild card certs. This has the advantage that the subdomain name is not part of the certificate transparency logs. This is a form of security by obscurity but hey everything helps. For example, you can search your domain name here - https://transparencyreport.google.com/https/certificates

                    JOduMonTJ 1 Reply Last reply
                    1
                    • girishG girish

                      Just wanted to add that (by default) when you use one of the DNS providers, we will also try to get wild card certs. This has the advantage that the subdomain name is not part of the certificate transparency logs. This is a form of security by obscurity but hey everything helps. For example, you can search your domain name here - https://transparencyreport.google.com/https/certificates

                      JOduMonTJ Offline
                      JOduMonTJ Offline
                      JOduMonT
                      wrote on last edited by
                      #9

                      @girish said in Is Cloudron could get Let's encrypt SSL via DNS ?:

                      This is a form of security by obscurity but hey everything helps.

                      you means it is more private, more obscure ?

                      but it is not more secure.

                      I personally always choose one certificate of every subdomain, which, at the end, is not necessary more secure just more forged 😉

                      1 Reply Last reply
                      0
                      • girishG Offline
                        girishG Offline
                        girish
                        Staff
                        wrote on last edited by
                        #10

                        @JOduMonT said in Is Cloudron could get Let's encrypt SSL via DNS ?:

                        you means it is more private, more obscure ?

                        yes, indeed. On some cloudron instances, I have apps which are installed as "customername.domain.com". I like to keep the 'customername' part private.

                        JOduMonTJ d19dotcaD 2 Replies Last reply
                        1
                        • girishG girish

                          @JOduMonT said in Is Cloudron could get Let's encrypt SSL via DNS ?:

                          you means it is more private, more obscure ?

                          yes, indeed. On some cloudron instances, I have apps which are installed as "customername.domain.com". I like to keep the 'customername' part private.

                          JOduMonTJ Offline
                          JOduMonTJ Offline
                          JOduMonT
                          wrote on last edited by
                          #11

                          @girish said in Is Cloudron could get Let's encrypt SSL via DNS ?:

                          I like to keep the 'customername' part private.

                          I never taught about it this way but will definitely keep it in mind 😉

                          1 Reply Last reply
                          0
                          • girishG girish

                            @JOduMonT said in Is Cloudron could get Let's encrypt SSL via DNS ?:

                            you means it is more private, more obscure ?

                            yes, indeed. On some cloudron instances, I have apps which are installed as "customername.domain.com". I like to keep the 'customername' part private.

                            d19dotcaD Offline
                            d19dotcaD Offline
                            d19dotca
                            wrote on last edited by d19dotca
                            #12

                            @girish This is an interesting observation. I was just looking to see if this was a real security threat or not, and I suppose it isn't but can offer a bit more privacy using the wildcard approach. Any particular reason why the Let's Encrypt wildcard support can't be done through the actual Cloudron wildcard DNS approach? Is there a way to support this? I'd really like to take advantage of a smaller DNS provider which has some great monitoring features included, but it isn't supported via any API by Cloudron yet, so if I go that route I can only use the Wildcard option, but those don't actually allow for the wildcard certificates.

                            Edit: Nevermind, I see why in the docs: "Let's Encrypt only allows obtaining wildcard certificates using DNS automation. Cloudron will default to obtaining wildcard certificates when using one of the programmatic DNS API providers."

                            --
                            Dustin Dauncey
                            www.d19.ca

                            1 Reply Last reply
                            0
                            Reply
                            • Reply as topic
                            Log in to reply
                            • Oldest to Newest
                            • Newest to Oldest
                            • Most Votes


                              • Login

                              • Don't have an account? Register

                              • Login or register to search.
                              • First post
                                Last post
                              0
                              • Categories
                              • Recent
                              • Tags
                              • Popular
                              • Bookmarks
                              • Search