As an operator of a web application using GenHTTP, I want the server to automatically fetch and update certificates via the ACME protocol, so I do not need to care about that process.
Example
var certificateManager = CertificateManager.LetsEncrypt();
await Host.Create()
.Add(certificateManager);
Acceptance criteria
- The functionality is provided in a new module
- There is a one-line integration that binds to the typical ports (80, 443)
- The certificate manager automatically issues and updates certificates (both on start and during operation)
- During an update of the certificate, there is no application downtime
- The
.well-known handling transparently allows other .well-known requests handled by the app
- The manager works with any ACME server
- The manager logs events when certificates are changed
- The manager stores private keys in a secure way (chmod etc.)
- The feature works with all engines (?)
- The feature is documented on the GenHTTP website
- The feature is covered by acceptance tests
As an operator of a web application using GenHTTP, I want the server to automatically fetch and update certificates via the ACME protocol, so I do not need to care about that process.
Example
Acceptance criteria
.well-knownhandling transparently allows other.well-knownrequests handled by the app