The release notes of 24.10 announce the removal of the certificate authority feature.
This is super disappointing, I used this to generate certificate for my self-hosted systems and add the CA to my computers and devices.
Now I would either have to use a public certificate which shouldn’t be necessary for self-hosted things, there’s no reason to spend money or publish your IP to Lets Encrypt for all to see, or I set up some other PKI infrastructure which is just a pain and typically super complex. Certificate are already a pain to deal with, the TrueNAS UI for them was honestly really decent or this sort of thing.
So if your domain has an A record and you request a certificate it’s put into the spotlight, it’s not something a private network needs to have any involvement with, but it’s normal for public websites.
You can avoid it with DNS verification but that’s harder to automate if your Domain Provider doesn’t support the API.
So much so that you waited almost two years to comment on it.
Sorry I don’t read updates every day, yeah it is awful to see it go, I wish we didn’t lose useful features
Indeed. But if these are only internal, self-hosted things, they wouldn’t have public A records, would they? And it still doesn’t constitute “publishing your IP to Let’s Encrypt.”
acme.sh has API support for somewhere around 200 DNS providers (it doesn’t matter what your domain registrar supports). Cloudflare is quite popular and free.
I ended up rolling my own CA using these instructions:
This is way more flexible than anything available in the old CA in Core; it supports ACME; and as it’s all on-premise infrastructure, I don’t have to deal with occasional broken features on LetsEncrypt.
As a neophyte, I found that entire process an exercise in frustration despite following the instructions to a « t »
Carl Tashian is a really nice guy and I appreciate all the work he put into those instructions, however. I eventually got the CA Pi working for a while and then a Raspian system update bricked the CA.
For me, the process of using @dan instructions to use Cloudflare to request SSLs combined with his distribution scripts for MikroTik, et al is far superior.
Even MacOs accepts them without a fight, including internal-only network infrastructure. Ditto Apps and the TrueNAS UI that accept the use of SSL certificates pulled via the TrueNAS UI. All for free as long as you have a spare valid domain to play with.
I totally understand that some folk prefer to roll their own for even higher security and privacy than can be afforded by Cloudflare but I simply do not consider my network worth the additional time and gray hair.
I built mine on a Raspberry Pi 2W running Ubuntu, so I had to make some modifications to his instructions to get things working. I haven’t bricked it yet. I found not all my devices grok ACME and/or ECC, so I ended up creating 5-year certificates using only RSA.
… and there’s the difference between a dilettante like myself and a expert like you. You could likely get a CA working on a commodore Vic 20 if you had to (acoustic coupler and all) while I struggled while using the same hardware / software as Mr. Tashian.
It’s not my world. Ask me about paper mache and I might have something relevant to opine.
But I love how my network now features SSLs for every major component and some day I may even attempt (again!) to secure a remote cloudkey 2. Last time, opening SSH bricked the device. Fun times, since I hadn’t anticipated that possibility and hence had not made a configuration backup.
If you can make it work, more power to you. I have found some Pi Applications to be incredibly stable (pi-hole) while others struggle to maintain uptime (attritable file server for Sonos or a print server).
I doubt it’s an electrical issue as all these Pi’s hang off the same power strip, use the same system update schedule, etc. and yet some run more reliably than others.
Just the other day, the first partition on the HDD for my kids backups has gone bad again. Meanwhile, the Pi runs as fast as molasses in a March blizzard. So something is off.
Maybe it’s the allegedly-durable flash drive that the OS sits on, maybe it got hit by a cosmic ray blast from a dying star? Who knows. But I cannot recommend a Pi as a file server based on my personal experience.
The key I’ve found is a high-endurance A2-capable SD card for booting, and then to get to a USB or NVMe drive for local data storage, or NFS or iSCSI share for remote data storage.
Yeah, I’ve transitioned to ultra or max abuse cards meant for dashcams, etc. but even so, reliability has not been awesome.
Ultimately, the time it takes to set up a new pi isn’t that long, provided you retain the various fstab, SMB, and avahi conf files that contain most of the configuration headaches?
FWIW I was also using it and wish it hadn’t been removed. I also realised a few weeks ago, when I upgraded. Now I am using Nginx Proxy Manager, doing DNS challenges for lets encrypt Challenge Types - Let's Encrypt
Now obviously this has disadvantages, such as if NPM is down I have to connect to TrueNAS with a TLS warning, but it does work.