-
-
Notifications
You must be signed in to change notification settings - Fork 160
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
docs: Update ZeroSSL issuer for v2.8 #414
Open
kekalainen
wants to merge
3
commits into
caddyserver:master
Choose a base branch
from
kekalainen:docs/update-zerossl-issuer-for-v2.8.0
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from 1 commit
Commits
Show all changes
3 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
docs: Restore previous issuer sections, disambiguate
- Loading branch information
commit c797f47e67e5282e2eee043a0348b1763d879e51
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So, this is only true if it's unspecified in the config. If you specify an issuer in the config, that overrides the defaults. Since this is docs describing how to override the defaults, maybe it's not the place to describe the default behavior which might be confusing.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I see. Removing the paragraph altogether would muddy the difference between the
acme
andzerossl
issuer modules, though. Perhaps prefixing it with "When explicitly unconfigured" would do?There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What if instead, we add a sentence to the
zerossl
section that clarifies: "The ZeroSSL API is distinct from its ACME endpoint." or something like that.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
While that'd cover the distinction more directly, the
acme
section still claims the module is "using Let's Encrypt" by default. For consistency either all or none of the possible implicit/default configuration should be mentioned IMO.Especially since the release notes claim that when the
email
global is configured,which, turns out, is arguably not true if
acme
is explicitly configured. That's not apparent (to me anyway) when said configuration is not providing adirectory_url
as an argument nor field value. (For context, I use theacme
issuer directive to override the DNS resolvers used for challenges (since those aren't globally configurable AFAIK) and had the false intuition it'd leave the dirs intact.)There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fair point, maybe that section needs to be tweaked to say "(using Let's Encrypt, and if an email is provided, ZeroSSL too)" or similar.
Perhaps verbiage clarifying that specifying any issuers wipes out implicit defaults.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
What's the status on this at this point?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think we're still waiting for a few tweaks to be made; but if not, I might try to wrap this up myself at some point. Although, I don't think I have push rights to the branch.