User Tools

Site Tools


Sidebar

letsencrypt
new certificate
/usr/bin/certbot --nginx certonly -d yourdomain.com --deploy-hook /usr/local/sbin/push_to_confiared.sh
add new for nginx
ssl_protocols       TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers         HIGH:!aNULL:!MD5;
listen 443 ssl http2;
listen [::]:443 ssl http2;
ssl_certificate      /etc/letsencrypt/live/yourdomain.com/fullchain.pem;
ssl_certificate_key  /etc/letsencrypt/live/yourdomain.com/privkey.pem;
renew for apache
/usr/bin/certbot --apache renew --deploy-hook /usr/local/sbin/push_to_confiared.sh --post-hook "/etc/init.d/apache2 reload"
renew for nginx
/usr/bin/certbot --nginx renew --deploy-hook /usr/local/sbin/push_to_confiared.sh
--post-hook "/etc/init.d/nginx reload"
/usr/local/sbin/push_to_confiared.sh
#!/bin/bash
#RENEWED_LINEAGE=/etc/letsencrypt/live/site.com
# Pushes a renewed certificate to the Confiared reverse-proxy, so the edges that terminate
# IPv4 stop serving the previous one. Called by certbot as renew_hook/deploy_hook.
# --insecure is deliberate: this can run while the certificate of api.confiared.com itself
# is the one being repaired.

if [ ! -f "${RENEWED_LINEAGE}/cert.pem" ]
then
  echo "${RENEWED_LINEAGE}/cert.pem was not found, abort" > /var/log/last_letsencrypt_confiared_api.log
  echo "${RENEWED_LINEAGE}/cert.pem was not found, abort" >> /var/log/last_letsencrypt_confiared_api.err
  exit 255
fi

# The api answers 400 + a json explaining why when it refuses a certificate. curl exits 0 on
# a 400, so testing $? alone reports success for a certificate that was in fact rejected: that
# is how a stale certificate stayed on the edges until it expired. Test the http code instead.
# Not -f: -f would throw away the json body, which is the only place the reason is written.
push()
{
  local code
  code=$(/usr/bin/curl --insecure --silent --max-time 120 -w '%{http_code}' \
    --data-urlencode "certificate=$(cat ${RENEWED_LINEAGE}/cert.pem)" \
    --data-urlencode "chain=$(cat ${RENEWED_LINEAGE}/chain.pem)" \
    --data-urlencode "privatekey=$(cat ${RENEWED_LINEAGE}/privkey.pem)" \
    https://api.confiared.com/reverse-proxy/upload-certificate \
    -o /var/log/last_letsencrypt_confiared_api.log)
  [ "$code" = "200" ]
}

if push
then
  exit 0
fi

# Refused or unreachable. Retry for ~16h: the api can be down, or the refusal can be transient.
for i in {1..99}
do
  sleep 600
  if push
  then
    exit 0
  fi
done

echo "`date -Is` push refused after 99 tries, see /var/log/last_letsencrypt_confiared_api.log" >> /var/log/last_letsencrypt_confiared_api.err
exit 1
cron
0 3 * * * sleep ${RANDOM:0:3}m;[ `ps aux | grep nginx | grep -v -F grep | wc -l` -gt 0 ] && /usr/bin/certbot --nginx renew --deploy-hook /usr/local/sbin/push_to_confiared.sh --post-hook "/etc/init.d/nginx reload" > /var/log/letsencrypt.log 2>&1
0 3 * * * sleep ${RANDOM:0:3}m;[ `ps aux | grep apache2 | grep -v -F grep | wc -l` -gt 0 ] && /usr/bin/certbot --apache renew --deploy-hook /usr/local/sbin/push_to_confiared.sh --post-hook "/etc/init.d/apache2 reload" > /var/log/letsencrypt.log 2>&1
letsencrypt.txt · Last modified: 2026/07/26 23:06 by admin