We’ve recently been rolling out a new internal application. At our organisation, users have an email address which is generally firstname.lastname@company.com, or something like that. When a user logs in to the application, the app will look them up using their email address and figure out what parts of the application the user should be able to use.
The problem
One day we got a ticket for a user who was adamant that they had access but when we looked in the application, we couldn’t even find them in the system! Probing a bit further, it turns out that they had recently changed their name, and as a result, their email had changed.
When i think back to the deepest of the many deep holes i’ve dug myself in to over the years, they almost all start with an email.
When working through my inbox, it’s all too easy to just bash out a reply and hit send. Usually, that’s fine - a quick email is all it takes, and the issue is closed. But sometimes, that email triggers a reply, and that reply another, and it’s hard to predict when but eventually I’m having a complex conversation about a complex issue and it all goes wrong and before I know it, we’re at loggerheads and 37 people on the CC list think I’m a jerk.
This is an update of my previous post, now that cert-manager is more mature, and i’ve rebuilt my server on Ubuntu 20.04 (from 18.04).
- install certbot
- install script to update unifi certificate
- Test
- Issue full certificate
- Install cron jobs to automate renewal
Install certbot
Certbot installation instructions are at online of course but here’s a summary:
- Update package list:
sudo apt update - install:
sudo apt install -y certbot
Create a new certificate using LetsEncrypt
We’re going to use standalone mode, and first we’ll get a test certificate just to validate that everything’s working (so that we don’t trigger LetsEncrypt’s rate limits).