thanks. i will ask you guys if i get stuck.
i think it worked.
yes, but http does not force you onto https yet
TLS config looks good too
a good idea to run that quarterly to see if anything bumps you down to C
for practical purposes, B and up is good enough
i guess you use some configuration wizard, probably the letsencrypt client from the distro repos
thanks.
yes i do.
okay.
then you do not need to worry about keeping up with nuances and obscuria
yay!!
letsencrypt has a paid team of engineering staff and their autopilot keeps your config sane
just make sure you have it in a crontab
dunno if that adds itself, actually, but worth double checking
the LE certs are 90 day DV certs
and 90 days rolls over surprisingly quick
okay. thanks for the info.
i use this one, but i like single purpose tools and staying on top of the whole stack is a thing for me - posting that in case someone else likeminded is seeking an ACME client (there are also valid single purpose rust and go clients for those so inclined) https://github.com/zenhack/simp_le Simple Let's Encrypt client
relatedly mozilla has a nice tool they keep up to date https://mozilla.github.io/server-side-tls/ssl-config-generator/
i guess it is time for me to drop TLSv1.1 at this point