>>>>> "TM" == Tomas Mraz <tm...@redhat.com> writes:

TM> Although it is much easier now to set up proper certificates for
TM> your servers with Let's Encrypt, it is still not fully automatable
TM> process (it needs at least some set up at the beginning for the
TM> first issued certificate). Thus it cannot be included for example in
TM> rpm packages
TM> %post scripts, etc.

But packages shouldn't be creating certificates in %post scriptlets.  At
least those which start daemons (which I think would be most of them).
That should be done when the daemon starts for the first time using
sscg.  See
https://fedoraproject.org/wiki/Packaging:Initial_Service_Setup

 - J<
_______________________________________________
devel mailing list -- devel@lists.fedoraproject.org
To unsubscribe send an email to devel-le...@lists.fedoraproject.org

Reply via email to