Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

tls-sni-02 is not supported on the production ACME server. It is part of the latest ACME draft (ACME v2), which recently got deployed on Let's Encrypt's staging server, but the certificates signed in that environment aren't publicly trusted.


Thanks. So the upshot is that package x/crypto/acme/autocert can no longer obtain production certs. I have bumped this issue, volunteering to do the work to add http-01 support to package autocert: https://github.com/golang/go/issues/21890


And tls-sni-02 does not fix the problem.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: