User Tools

Site Tools


letsencrypt

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
letsencrypt [2019/01/08 20:42]
admin
letsencrypt [2026/08/01 23:41] (current)
admin
Line 1: Line 1:
-== new == +== new certificate ​== 
-<​code>​certbot --nginx certonly -d yourdomain.com --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh</​code>​+<​code>​/usr/bin/certbot --nginx certonly -d yourdomain.com --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh</​code>​
  
-== renew == +== add new for nginx == 
-<​code>​certbot --nginx renew --deploy-hook ​/usr/local/sbin/push_to_confiared.sh</​code>​+<​code>​ssl_protocols ​      TLSv1 TLSv1.1 TLSv1.2; 
 +ssl_ciphers ​        ​HIGH:​!aNULL:​!MD5;​ 
 +listen 443 ssl http2; 
 +listen [::]:443 ssl http2; 
 +ssl_certificate ​     ​/etc/letsencrypt/live/​yourdomain.com/​fullchain.pem;​ 
 +ssl_certificate_key ​ /​etc/​letsencrypt/​live/​yourdomain.com/privkey.pem;</​code>​
  
-== /​usr/​local/​sbin/​push_to_confiared.sh ==+== renew for apache == 
 +<​code>/​usr/​bin/​certbot --apache renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh --post-hook "/​etc/​init.d/​apache2 reload"</​code>​ 
 + 
 +== renew for nginx == 
 +<​code>/​usr/​bin/​certbot --nginx renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh 
 +--post-hook "/​etc/​init.d/​nginx reload"</​code>​ 
 + 
 +== /​usr/​local/​sbin/​push_to_confiared.sh ​to push for IPv4 reverse proxy ==
 <​code>​ <​code>​
 #!/bin/bash #!/bin/bash
 #​RENEWED_LINEAGE=/​etc/​letsencrypt/​live/​site.com #​RENEWED_LINEAGE=/​etc/​letsencrypt/​live/​site.com
-/​usr/​bin/​curl --data-urlencode "​certificate=`cat ${RENEWED_LINEAGE}/​cert.pem`" --data-urlencode "​chain=`cat ${RENEWED_LINEAGE}/​chain.pem`" --data-urlencode "​privatekey=`cat ${RENEWED_LINEAGE}/​privkey.pem`" https://​api.confiared.com/​reverse-proxy/​upload-certificate -o /​var/​log/​last_letsencrypt_confiared_api.log+# Pushes a renewed certificate to the Confiared reverse-proxy,​ so the edges that terminate 
 +# IPv4 stop serving the previous one. Called by certbot as renew_hook/​deploy_hook. 
 +# --insecure is deliberate: this can run while the certificate of api.confiared.com itself 
 +# is the one being repaired. 
 + 
 +if [ ! -f "​${RENEWED_LINEAGE}/​cert.pem"​ ] 
 +then 
 +  echo "​${RENEWED_LINEAGE}/​cert.pem was not found, abort" > /​var/​log/​last_letsencrypt_confiared_api.log 
 +  echo "​${RENEWED_LINEAGE}/​cert.pem was not found, abort" >> /​var/​log/​last_letsencrypt_confiared_api.err 
 +  exit 255 
 +fi 
 + 
 +# The api answers 400 + a json explaining why when it refuses a certificate. curl exits 0 on 
 +# a 400, so testing $? alone reports success for a certificate that was in fact rejected: that 
 +# is how a stale certificate stayed on the edges until it expired. Test the http code instead. 
 +# Not -f: -f would throw away the json body, which is the only place the reason is written. 
 +push() 
 +
 +  local code 
 +  code=$(/​usr/​bin/​curl ​--insecure --silent --max-time 120 -w '​%{http_code}'​ \ 
 +    ​--data-urlencode "​certificate=$(cat ${RENEWED_LINEAGE}/​cert.pem)" ​
 +    ​--data-urlencode "​chain=$(cat ${RENEWED_LINEAGE}/​chain.pem)" ​
 +    ​--data-urlencode "​privatekey=$(cat ${RENEWED_LINEAGE}/​privkey.pem)" ​
 +    ​https://​api.confiared.com/​reverse-proxy/​upload-certificate ​
 +    ​-o /​var/​log/​last_letsencrypt_confiared_api.log
 +  [ "​$code"​ = "​200"​ ] 
 +
 + 
 +if push 
 +then 
 +  exit 0 
 +fi 
 + 
 +# Refused or unreachable. Retry for ~16h: the api can be down, or the refusal can be transient. 
 +for i in {1..99} 
 +do 
 +  sleep 600 
 +  if push 
 +  then 
 +    exit 0 
 +  fi 
 +done 
 + 
 +echo "`date -Is` push refused after 99 tries, see /​var/​log/​last_letsencrypt_confiared_api.log"​ >> /​var/​log/​last_letsencrypt_confiared_api.err 
 +exit 1
 </​code>​ </​code>​
 +
 +== cron ==
 +<​code>​0 3 * * * sleep ${RANDOM:​0:​3}m;​[ `ps aux | grep nginx | grep -v -F grep | wc -l` -gt 0 ] && /​usr/​bin/​certbot --nginx renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh --post-hook "/​etc/​init.d/​nginx reload"​ > /​var/​log/​letsencrypt.log 2>&1
 +0 3 * * * sleep ${RANDOM:​0:​3}m;​[ `ps aux | grep apache2 | grep -v -F grep | wc -l` -gt 0 ] && /​usr/​bin/​certbot --apache renew --deploy-hook /​usr/​local/​sbin/​push_to_confiared.sh --post-hook "/​etc/​init.d/​apache2 reload"​ > /​var/​log/​letsencrypt.log 2>&​1</​code>​
letsencrypt.1546980121.txt.gz · Last modified: 2019/01/08 20:42 by admin