I made a tool for automatically updating the current and next (rollover) TLSA DNS records with acme.sh and the Cloudflare API

This page summarizes the projects mentioned and recommended in the original post on /r/selfhosted

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • acme.sh

    A pure Unix shell script implementing ACME client protocol

  • For the few people here that happen to run a self-hosted email server with acme.sh for TLS key/cert generation and Cloudflare for DNS management, I have made a tool that i personally use to get a perfect 100% score on Internet.nl's email test.

  • cf-tlsa-acmesh

    A simple Go program that lets you automate the updating of TLSA DNS records with the Cloudflare v4 API from acme.sh generated keys, including a rollover (next) key.

  • It is written in Go and the GitHub repo is here. It includes instructions about installing and setting up the tool, and it should probably also be compatible with any other tools that can generate current and next EC private keys.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • mail-server

    Secure & Modern All-in-One Mail Server (IMAP, JMAP, SMTP)

  • Yes, still using Maddy + Dovecot + Rspamd and everything works fine, but I've been thinking about trying out https://stalw.art/ to be able to try out the new JMAP protocol that is intended to replace IMAP.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts