User Tools

Site Tools


letsencrypt

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
letsencrypt [2018/12/29 12:31]
admin created
letsencrypt [2026/08/01 23:41] (current)
admin
Line 1: Line 1:
-== new == +== new certificate ​== 
-certbot --nginx ​new -d yourdomain.com --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh+<​code>/​usr/​bin/​certbot --nginx ​certonly ​-d yourdomain.com --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh</​code>​
  
-== renew == +== add new for nginx == 
-certbot --nginx renew --deploy-hook ​/usr/local/sbin/push_to_confiared.sh+<​code>​ssl_protocols ​      TLSv1 TLSv1.1 TLSv1.2; 
 +ssl_ciphers ​        ​HIGH:​!aNULL:​!MD5;​ 
 +listen 443 ssl http2; 
 +listen [::]:443 ssl http2; 
 +ssl_certificate ​     ​/etc/letsencrypt/live/yourdomain.com/​fullchain.pem;​ 
 +ssl_certificate_key ​ /​etc/​letsencrypt/​live/​yourdomain.com/​privkey.pem;</​code>​
  
-== /​usr/​local/​sbin/​push_to_confiared.sh ==+== renew for apache == 
 +<​code>/​usr/​bin/​certbot --apache renew --deploy-hook ​/​usr/​local/​sbin/​push_to_confiared.sh ​--post-hook "/​etc/​init.d/​apache2 reload"</​code>​ 
 + 
 +== renew for nginx == 
 +<​code>/​usr/​bin/​certbot --nginx renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh 
 +--post-hook "/​etc/​init.d/​nginx reload"</​code>​ 
 + 
 +== /​usr/​local/​sbin/​push_to_confiared.sh to push for IPv4 reverse proxy == 
 +<​code>​ 
 +#​!/​bin/​bash 
 +#​RENEWED_LINEAGE=/​etc/​letsencrypt/​live/​site.com 
 +# Pushes a renewed certificate to the Confiared reverse-proxy,​ so the edges that terminate 
 +# IPv4 stop serving the previous one. Called by certbot as renew_hook/​deploy_hook. 
 +# --insecure is deliberate: this can run while the certificate of api.confiared.com itself 
 +# is the one being repaired. 
 + 
 +if [ ! -f "​${RENEWED_LINEAGE}/​cert.pem"​ ] 
 +then 
 +  echo "​${RENEWED_LINEAGE}/​cert.pem was not found, abort" > /​var/​log/​last_letsencrypt_confiared_api.log 
 +  echo "​${RENEWED_LINEAGE}/​cert.pem was not found, abort" >> /​var/​log/​last_letsencrypt_confiared_api.err 
 +  exit 255 
 +fi 
 + 
 +# The api answers 400 + a json explaining why when it refuses a certificate. curl exits 0 on 
 +# a 400, so testing $? alone reports success for a certificate that was in fact rejected: that 
 +# is how a stale certificate stayed on the edges until it expired. Test the http code instead. 
 +# Not -f: -f would throw away the json body, which is the only place the reason is written. 
 +push() 
 +
 +  local code 
 +  code=$(/​usr/​bin/​curl --insecure --silent --max-time 120 -w '​%{http_code}'​ \ 
 +    --data-urlencode "​certificate=$(cat ${RENEWED_LINEAGE}/​cert.pem)"​ \ 
 +    --data-urlencode "​chain=$(cat ${RENEWED_LINEAGE}/​chain.pem)"​ \ 
 +    --data-urlencode "​privatekey=$(cat ${RENEWED_LINEAGE}/​privkey.pem)"​ \ 
 +    https://​api.confiared.com/​reverse-proxy/​upload-certificate \ 
 +    -o /​var/​log/​last_letsencrypt_confiared_api.log) 
 +  [ "​$code"​ = "​200"​ ] 
 +
 + 
 +if push 
 +then 
 +  exit 0 
 +fi 
 + 
 +# Refused or unreachable. Retry for ~16h: the api can be down, or the refusal can be transient. 
 +for i in {1..99} 
 +do 
 +  sleep 600 
 +  if push 
 +  then 
 +    exit 0 
 +  fi 
 +done 
 + 
 +echo "`date -Is` push refused after 99 tries, see /​var/​log/​last_letsencrypt_confiared_api.log"​ >> /​var/​log/​last_letsencrypt_confiared_api.err 
 +exit 1 
 +</​code>​ 
 + 
 +== cron == 
 +<​code>​0 3 * * * sleep ${RANDOM:​0:​3}m;​[ `ps aux | grep nginx | grep -v -F grep | wc -l` -gt 0 ] && /​usr/​bin/​certbot --nginx renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh --post-hook "/​etc/​init.d/​nginx reload"​ > /​var/​log/​letsencrypt.log 2>&​1 
 +0 3 * * * sleep ${RANDOM:​0:​3}m;​[ `ps aux | grep apache2 | grep -v -F grep | wc -l` -gt 0 ] && /​usr/​bin/​certbot --apache renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh --post-hook "/​etc/​init.d/​apache2 reload"​ > /​var/​log/​letsencrypt.log 2>&​1</​code>​
letsencrypt.1546086712.txt.gz · Last modified: 2018/12/29 12:31 by admin