summaryrefslogtreecommitdiff
path: root/certbot-replicate
diff options
context:
space:
mode:
authorDaniel Micay <daniel.micay@grapheneos.org>2025-05-04 21:57:41 -0400
committerDaniel Micay <daniel.micay@grapheneos.org>2025-05-04 23:46:56 -0400
commit298c357bc9a6023d1ce470ad1711851775313c0a (patch)
tree1cd61c8c4e8a5c692b11e645c8ed28a4f2501f36 /certbot-replicate
parentc57490de09fcdc3eadadc8422b4b17da313841b2 (diff)
handle Let's Encrypt removing OCSP support
We can no longer use OCSP stapling and Must-Staple. These will soon be obsolete once the `shortlived` profile is available for public use since it will provide certificates with a similar lifetime as OCSP responses. In the meantime, we've moved to the `tlsserver` profile stripping legacy features to prepare for the `shortlived` profile which will be identical to `tlsserver` but with a validity period of 6 days.
Diffstat (limited to 'certbot-replicate')
-rwxr-xr-xcertbot-replicate1
1 files changed, 0 insertions, 1 deletions
diff --git a/certbot-replicate b/certbot-replicate
index aab07d55..ef7d9cf4 100755
--- a/certbot-replicate
+++ b/certbot-replicate
@@ -11,7 +11,6 @@ for replica in ${replicas[@]}; do
echo
rsync -rpcvl --delete --fsync --preallocate /etc/letsencrypt/ $replica:/etc/letsencrypt &&
- rsync -rpcvl --delete --fsync --preallocate /var/cache/certbot-ocsp-fetcher/ $replica:/var/cache/certbot-ocsp-fetcher &&
ssh root@$replica nginx -s reload ||
status=1
done