This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
|
letsencrypt [2019/07/24 20:04] admin |
letsencrypt [2026/08/01 23:41] (current) admin |
||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | == new == | + | == new certificate == |
| <code>/usr/bin/certbot --nginx certonly -d yourdomain.com --deploy-hook /usr/local/sbin/push_to_confiared.sh</code> | <code>/usr/bin/certbot --nginx certonly -d yourdomain.com --deploy-hook /usr/local/sbin/push_to_confiared.sh</code> | ||
| + | |||
| + | == add new for nginx == | ||
| + | <code>ssl_protocols TLSv1 TLSv1.1 TLSv1.2; | ||
| + | ssl_ciphers HIGH:!aNULL:!MD5; | ||
| + | listen 443 ssl http2; | ||
| + | listen [::]:443 ssl http2; | ||
| + | ssl_certificate /etc/letsencrypt/live/yourdomain.com/fullchain.pem; | ||
| + | ssl_certificate_key /etc/letsencrypt/live/yourdomain.com/privkey.pem;</code> | ||
| == renew for apache == | == renew for apache == | ||
| Line 9: | Line 17: | ||
| --post-hook "/etc/init.d/nginx reload"</code> | --post-hook "/etc/init.d/nginx reload"</code> | ||
| - | == /usr/local/sbin/push_to_confiared.sh == | + | == /usr/local/sbin/push_to_confiared.sh to push for IPv4 reverse proxy == |
| <code> | <code> | ||
| #!/bin/bash | #!/bin/bash | ||
| #RENEWED_LINEAGE=/etc/letsencrypt/live/site.com | #RENEWED_LINEAGE=/etc/letsencrypt/live/site.com | ||
| - | /usr/bin/curl --silent --data-urlencode "certificate=`cat ${RENEWED_LINEAGE}/cert.pem`" --data-urlencode "chain=`cat ${RENEWED_LINEAGE}/chain.pem`" --data-urlencode "privatekey=`cat ${RENEWED_LINEAGE}/privkey.pem`" https://api.confiared.com/reverse-proxy/upload-certificate -o /var/log/last_letsencrypt_confiared_api.log | + | # Pushes a renewed certificate to the Confiared reverse-proxy, so the edges that terminate |
| + | # IPv4 stop serving the previous one. Called by certbot as renew_hook/deploy_hook. | ||
| + | # --insecure is deliberate: this can run while the certificate of api.confiared.com itself | ||
| + | # is the one being repaired. | ||
| + | |||
| + | if [ ! -f "${RENEWED_LINEAGE}/cert.pem" ] | ||
| + | then | ||
| + | echo "${RENEWED_LINEAGE}/cert.pem was not found, abort" > /var/log/last_letsencrypt_confiared_api.log | ||
| + | echo "${RENEWED_LINEAGE}/cert.pem was not found, abort" >> /var/log/last_letsencrypt_confiared_api.err | ||
| + | exit 255 | ||
| + | fi | ||
| + | |||
| + | # The api answers 400 + a json explaining why when it refuses a certificate. curl exits 0 on | ||
| + | # a 400, so testing $? alone reports success for a certificate that was in fact rejected: that | ||
| + | # is how a stale certificate stayed on the edges until it expired. Test the http code instead. | ||
| + | # Not -f: -f would throw away the json body, which is the only place the reason is written. | ||
| + | push() | ||
| + | { | ||
| + | local code | ||
| + | code=$(/usr/bin/curl --insecure --silent --max-time 120 -w '%{http_code}' \ | ||
| + | --data-urlencode "certificate=$(cat ${RENEWED_LINEAGE}/cert.pem)" \ | ||
| + | --data-urlencode "chain=$(cat ${RENEWED_LINEAGE}/chain.pem)" \ | ||
| + | --data-urlencode "privatekey=$(cat ${RENEWED_LINEAGE}/privkey.pem)" \ | ||
| + | https://api.confiared.com/reverse-proxy/upload-certificate \ | ||
| + | -o /var/log/last_letsencrypt_confiared_api.log) | ||
| + | [ "$code" = "200" ] | ||
| + | } | ||
| + | |||
| + | if push | ||
| + | then | ||
| + | exit 0 | ||
| + | fi | ||
| + | |||
| + | # Refused or unreachable. Retry for ~16h: the api can be down, or the refusal can be transient. | ||
| + | for i in {1..99} | ||
| + | do | ||
| + | sleep 600 | ||
| + | if push | ||
| + | then | ||
| + | exit 0 | ||
| + | fi | ||
| + | done | ||
| + | |||
| + | echo "`date -Is` push refused after 99 tries, see /var/log/last_letsencrypt_confiared_api.log" >> /var/log/last_letsencrypt_confiared_api.err | ||
| + | exit 1 | ||
| </code> | </code> | ||