Do https with Let's Encrypt

Got an idea? Missing something? Post your feature request here.

Moderator: moderators

Do https with Let's Encrypt

Postby JollyOrc » Mon Dec 07, 2015 10:17 am

That way people can have custom certificates in an automated, easy and secure way.

I'd actually be willing to pay a one-time contribution for that feature! :)
JollyOrc
 
Posts: 6
Joined: Wed Jan 05, 2011 9:21 am

Re: Do https with Let's Encrypt

Postby mrfloppy » Mon Dec 07, 2015 10:25 am

I'd actually be willing to pay a one-time contribution for that feature!

You already have this feature. You can use any webserver as a reverse proxy.

That way people can have custom certificates in an automated, easy and secure way.

It is not a secure way because it's automated. :evil:
mrfloppy
 
Posts: 48
Joined: Thu Apr 16, 2015 10:12 am

Re: Do https with Let's Encrypt

Postby JollyOrc » Mon Dec 07, 2015 6:51 pm

It is more secure than using the bog-standard subsonic generic certificate. And involves less hassle on the end users end.

And I didn't write that it is more secure due to the automation. It is more secure than the bog-standard setup and on top of that it would be automated.
JollyOrc
 
Posts: 6
Joined: Wed Jan 05, 2011 9:21 am

Re: Do https with Let's Encrypt

Postby DaveWut » Thu Dec 10, 2015 1:00 pm

mrfloppy wrote:
That way people can have custom certificates in an automated, easy and secure way.

It is not a secure way because it's automated. :evil:


I don't see by any way how that's not secure. It's probably one of the most secure way to obtain your certificates. You don't have to manipulate your private key and neither the rest of the certificate chain, plus you need to renew once every 3 months. Google do have certificates that last only three months:
Image

And I'm probably sure they automate everything, because it's the most logical thing to do when you have a lot of servers to manage (like they do).

As for your question JollyOrc, use an Apache2 proxy. It will make your setup a little simpler. You won't have to change the configuration of the subsonic web server and it will allow you to centralize the management of your certificates only by using the client command line tool of Let's Encrypt.
User avatar
DaveWut
 
Posts: 57
Joined: Fri Nov 11, 2011 12:29 am

Re: Do https with Let's Encrypt

Postby JollyOrc » Sun Dec 20, 2015 11:43 am

DaveWut wrote:As for your question JollyOrc, use an Apache2 proxy. It will make your setup a little simpler. You won't have to change the configuration of the subsonic web server and it will allow you to centralize the management of your certificates only by using the client command line tool of Let's Encrypt.


I'm doing this with Caddyserver right now, but I run into the problem that the login.view and the settings pages somehow call localhost directly. (more wordy here: http://www.orkpiraten.de/blog/subsonic-caddy-oh-my)

Is there a way to force Subsonic to not do this?
JollyOrc
 
Posts: 6
Joined: Wed Jan 05, 2011 9:21 am

Re: Do https with Let's Encrypt

Postby MonsterMuffin » Wed Dec 30, 2015 11:06 am

It's extremely possible, just reverse proxy it.

Image
MonsterMuffin
 
Posts: 14
Joined: Tue Mar 10, 2015 10:04 am

Re: Do https with Let's Encrypt

Postby DaveWut » Thu Jan 21, 2016 1:05 pm

JollyOrc wrote:
DaveWut wrote:As for your question JollyOrc, use an Apache2 proxy. It will make your setup a little simpler. You won't have to change the configuration of the subsonic web server and it will allow you to centralize the management of your certificates only by using the client command line tool of Let's Encrypt.


I'm doing this with Caddyserver right now, but I run into the problem that the login.view and the settings pages somehow call localhost directly. (more wordy here: http://www.orkpiraten.de/blog/subsonic-caddy-oh-my)

Is there a way to force Subsonic to not do this?


I'm not sure how Caddyserver works for their reverse proxy settings, but as for Apache2, you need to add a directive that tells apache to preserve the hostname. Here is what I recommend: viewtopic.php?f=6&t=14746
User avatar
DaveWut
 
Posts: 57
Joined: Fri Nov 11, 2011 12:29 am


Return to Feature Requests

Who is online

Users browsing this forum: No registered users and 11 guests