mailu: cert flavor while the predecessor's proxy owns the challenge path #82

Merged
jschoubben merged 1 commits from fix/mailu-tls-cert-behind-the-predecessors-proxy into main 2026-09-25 22:11:26 +00:00
Owner

Proven live, closing a months-old silent fault: Traefik's own ACME machinery owns /.well-known/acme-challenge on :80 outright (unknown tokens get its 404) and its entrypoint redirect owns every other path — the hand-authored passthrough never matched anything, which is why mailu's certbot state quietly expired in April while copied cert files carried the name (a real user hit the expired cert on IMAPS tonight when letsencrypt flavor served the stale state).

cert flavor serves the copied files (valid to Nov 27). Mailu certifying itself becomes possible the day route-proxy takes port 80 — its handler falls through unknown challenge tokens by design — and that flip is one line here, made then. Before Nov 27 either that cutover lands or the cert files need one manual refresh from Traefik's acme.json.

Proven live, closing a months-old silent fault: Traefik's own ACME machinery owns `/.well-known/acme-challenge` on :80 outright (unknown tokens get *its* 404) and its entrypoint redirect owns every other path — the hand-authored passthrough **never matched anything**, which is why mailu's certbot state quietly expired in April while copied cert files carried the name (a real user hit the expired cert on IMAPS tonight when `letsencrypt` flavor served the stale state). `cert` flavor serves the copied files (valid to Nov 27). Mailu certifying itself becomes possible the day route-proxy takes port 80 — its handler falls through unknown challenge tokens by design — and that flip is one line here, made then. Before Nov 27 either that cutover lands or the cert files need one manual refresh from Traefik's acme.json.
jschoubben added 1 commit 2026-09-25 22:11:20 +00:00
letsencrypt was the aspiration and cannot work yet, proven live: the
predecessor's own ACME machinery owns /.well-known/acme-challenge on
port 80 outright (unknown tokens get its 404) and its entrypoint
redirect owns every other path — the hand-authored passthrough never
matched anything, which is why mailu's certbot state had quietly
expired in April while the copied files carried the name. cert flavor
serves those files (valid to Nov 27). Mailu certifying itself becomes
possible the day route-proxy takes port 80, whose handler falls through
unknown tokens by design — that flip is one line here, made then.
jschoubben merged commit d5b169b6b6 into main 2026-09-25 22:11:26 +00:00
jschoubben deleted branch fix/mailu-tls-cert-behind-the-predecessors-proxy 2026-09-25 22:11:27 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#82