frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Show HN: Anchor Relay – A faster, easier way to get Let's Encrypt certificates

https://anchor.dev/relay
15•geemus•1h ago
From the cryptic terminal commands to the innumerable ways to shoot yourself in the foot, I always struggled to use TLS certificates. I love how much easier (and cheaper) Let's Encrypt made it to get certificates, but there are still plenty of things to struggle with.

That's why we built Relay: a free, browser-based tool that streamlines the ACME workflow, especially for tricky setups like homelabs. Relay acts as a secure intermediary between your ACME client and public certificate authorities like Let's Encrypt.

Some ways Relay provides a better experience:

  - really fast, streamlined certificates in minutes, with any ACME client
  - one-time upfront DNS delegation without inbound traffic or DNS credentials sprinkled everywhere
  - clear insights into the whole ACME process and renewal reminders
Try Relay now: https://anchor.dev/relay

Or read our blog post: https://anchor.dev/blog/lets-get-your-homelab-https-certifie...

Please give it a try (it only takes a couple minutes) and let me know what you think.

Comments

xmprt•1h ago
I'm sure some people would find this useful but forgive me if I'm not ready to hand away my security to some unknown third party company. I don't know the first thing about CAs but Let's Encrypt really isn't that difficult to understand.
geemus•1h ago
We take security very seriously, which is why we designed Relay to work so that we never have to see your encryption keys. If Let's Encrypt is working well enough for you, that's great, but we've also heard about rough edges that people struggle with so we are trying to help them out.
michaelt•1h ago
I believe the intent here is:

* If you want an SSL certificate for, say, your printer

* And you don’t want to expose your printer’s port 80 to the public internet because you’re not stupid

* And you don’t want to put your DNS credentials onto your printer either, because again, you’re not stupid

* And you don’t want to pay for a certificate with a longer validity, because it’s a home printer, so you’re stitch with monthly cert rotations

* And you’ve embraced the reality that one can delegate SSL not just to CAs, but also to other third parties. Usually the likes of AWS & cloudflare - but why stop there?

Then this product is what you need!

eternauta3k•1h ago
Why not sign it yourself?
woodruffw•39m ago
Most people find the user experience of self-signed certificates much worse. The developer experience for local issuance isn't great, although mkcert does a really great job of smoothing the parts that can be smoothed[1].

[1]: https://github.com/FiloSottile/mkcert

toast0•23m ago
> * If you want an SSL certificate for, say, your printer

Ummmm why does my printer need a certificate?

mholt•17m ago
If you can't trust your network, you'll want encryption, regardless of devices on it.
NoahZuniga•1h ago
Your site doesn't work. The right arrow button is always disabled
benburkert•1h ago
sorry about that! mind sharing what domain name (or something similar that also doesn't work) & what browser you used?
mano78•57m ago
iOS safari
aeaa3•1h ago
Does this means that you have the ability to

a) impersonate the identities of your users and b) decrypt the SSL traffic of your users

?

benburkert•1h ago
It does not.

Anchor never see sees your private keys for certificates.

We hold an ACME account key on your behalf with the CA, but we cannot use it impersonate your domain or decrypt traffic.

We have a more technical overview of how this works in our docs: https://anchor.dev/docs/public-certs/acme-relay

masfuerte•23m ago
If users delegate their DNS to you, what's stopping you issuing a certificate to yourself for their site?
traceroute66•2m ago
Oh dear.

I'm sorry. But do you really need to re-invent the wheel yet again ?

Go to the Let's Encrypt website, there is a whole page of client implementations[1].

What makes yours better than, for example, `lego` or `caddy` or `step` ?

All of which are easy to use, come with sensible defaults and do not provide you with "innumerable ways to shoot yourself in the foot".

[1] https://letsencrypt.org/docs/client-options/

WhatsApp have just fixed the PSTN (and simultaneously killed it)

https://simwood.com/2025/08/whatsapp-have-just-fixed-the-pstn-and-simultaneously-killed-it/
1•vanburen•33s ago•0 comments

A note about eventual consistency

https://www.ufried.com/blog/eventual_consistency_1/
1•speckx•1m ago•0 comments

FTC sues LA Fitness for making it exceedingly hard to cancel gym memberships

https://www.ftc.gov/news-events/news/press-releases/2025/08/ftc-sues-la-fitness-making-it-difficult-consumers-cancel-gym-memberships
3•jmsflknr•3m ago•0 comments

Zed for Windows: What's Taking So Long?

https://zed.dev/blog/windows-progress-report
1•janjones•4m ago•0 comments

How do LSM Trees work?

https://rowjee.com/blog/lsmtrees
1•romanhn•5m ago•0 comments

Why is my device a touchpad and a mouse and a keyboard?

http://who-t.blogspot.com/2025/08/why-is-my-device-touchpad-and-mouse-and.html
1•naves•5m ago•0 comments

Major autism study uncovers biologically distinct subtypes

https://www.princeton.edu/news/2025/07/09/major-autism-study-uncovers-biologically-distinct-subtypes-paving-way-precision
1•josh-sematic•5m ago•0 comments

How Americans View Journalists in the Digital Age

https://www.pewresearch.org/journalism/2025/08/20/how-americans-view-journalists-in-the-digital-age/
1•thm•5m ago•0 comments

Our Shared Reality Will Self-Destruct in the Next 12 Months

https://www.honest-broker.com/p/our-shared-reality-will-self-destruct
1•nickwritesit•5m ago•0 comments

Show HN: Bizcardz.ai – Custom metal business cards

https://github.com/rhodey/bizcardz.ai
1•rhodey•6m ago•0 comments

Political Donations via ChatGPT Agent

https://matthodges.com/posts/2025-08-20-chatgpt-agent-political-donation/
1•m-hodges•6m ago•0 comments

A Climate of Unparalleled Malevolence

https://www.theguardian.com/environment/2025/aug/19/a-climate-of-unparalleled-malevolence-are-we-on-our-way-to-the-sixth-major-mass-extinction
1•anigbrowl•8m ago•0 comments

The theory and practice of selling the Aga cooker (1935) [pdf]

https://comeadwithus.wordpress.com/wp-content/uploads/2012/08/the-theory-and-practice-of-selling-the-aga-cooker.pdf
1•phpnode•9m ago•0 comments

Fine-Tuned Open Sourced Models vs. System Tuned SOTA Models for Customization?

1•Ihmzf•9m ago•0 comments

GSA launches AI sandbox, says it won't be around for long

https://www.theregister.com/2025/08/20/brandnew_government_ai_sandbox_only/
2•rntn•9m ago•0 comments

Show HN: Nestable.dev – local whiteboard app with nestable canvases, deep links

https://nestable.dev/about
1•anorak27•10m ago•0 comments

Show HN: We beat Google DeepMind but got killed by Zhipu AI

https://github.com/minitap-ai/mobile-use
2•orangepomodoro•12m ago•0 comments

We keep fixing symptoms, not root causes

https://oneuptime.com/blog/post/2025-08-21-logs-traces-metrics-before-and-after/view
1•ndhandala•13m ago•0 comments

A refresher on end-to-end API Security

https://wso2.com/library/blogs/securing-apis-with-wso2-api-manager-a-guide-to-end-to-end-api-security/
1•langur•13m ago•0 comments

Modal's custom container runtime, filesystems, and GPU solver

https://www.amplifypartners.com/blog-posts/how-modal-built-a-data-cloud-from-the-ground-up
4•itunpredictable•15m ago•0 comments

Ultra Ethernet's Design Principles and Architectural Innovations

https://arxiv.org/abs/2508.08906
1•giuliomagnifico•17m ago•0 comments

Russian drone fell in eastern Poland

https://www.reuters.com/world/russian-drone-fell-eastern-poland-warsaw-says-2025-08-20/
3•danielam•19m ago•0 comments

Proxy 4: The Next Leap in C++ Polymorphism

https://devblogs.microsoft.com/cppblog/announcing-proxy-4-the-next-leap-in-c-polymorphism/
2•janjones•21m ago•0 comments

I gave Claude Code a folder of tax documents and used it as a tax agent

https://martinalderson.com/posts/building-a-tax-agent-with-claude-code/
1•martinald•22m ago•1 comments

The Dangerous Legal Strategy Coming for Our Books

https://www.theatlantic.com/ideas/archive/2025/08/book-bans-public-schools/683921/
2•littlexsparkee•23m ago•3 comments

Privacy Washing Is a Dirty Business

https://www.privacyguides.org/articles/2025/08/20/privacy-washing-is-a-dirty-business/
3•samuel246•26m ago•0 comments

Can Peanut Allergies Be Cured?

https://www.scientificamerican.com/article/new-treatments-can-free-kids-from-the-deadly-threat-of-peanut-allergy/
1•stevenjgarner•26m ago•0 comments

Show HN: Llmswap v3.0 – CLI and SDK for OpenAI, Claude, Gemini, Watsonx

https://pypi.org/project/llmswap/
2•sreenathmenon•28m ago•0 comments

Show HN: Turn any study material into practice questions with one photo

https://www.lexielearn.com/en
2•e_patjas•29m ago•0 comments

Show HN: I built an app to track expense temptation

https://app.skipwise.org
1•0xshadow•30m ago•0 comments