Re: [webmin-l] letsencrypt... "duplicate" flag and "end" slash in path
Marcos Rubinstein <[email protected]>
| Newsgroups | gmane.comp.web.webmin.general |
|---|---|
| Message-ID | <CAMo2Tjk0H7g-AEVetok6R_EC0QZtp2AV4AUT-KJ8UfonAKLO5w@mail.gmail.com> |
BTW... this on a virtual server (VzOpen) Centos 6.7 Apache/2.2.15 python 2.6 (when called as "python"... but also in /usr/bin/ python 2.7 and python 3.5m) Peace, with Justice! Si, se puede! Marcos "For what can war, but endless war, still breed?" (John Milton) On Tue, Mar 29, 2016 at 1:54 PM, Marcos Rubinstein <[email protected]> wrote: > Hi Jamie: > > why did you decide to use the "--duplicate" file for letsencrypt? > > and... can I choose *not* to use it? > > also... > > for some reason... if in the apache configuration you don't use the / > (slash) when defining the root directory of a virtual domain.... the webmin > letsencrypt module (under webmin configuration/ssl) will give you an > error!!!! (in other words.... if I have in the config something like > "rootdir /something/virtualdomain instead of /something/virtualdomain/ , I > will get an error saying that "/something/virtualdomain" does not > exists.... that's when I use the option of "A different Apache virtual > host" and choose that virtualhost... if, instead, I use "Other directory" > and I include the final slash (/) on that... webmin is able to get the > certificate). NOTA BENE: after "playing" with the "letsencrypt" CLI... I > found out that letsencrypt does not "understand" the "old style" > httpd.conf!... it only detect the last "Virtual Domain" defined in > httpd.conf and in ssl.conf... even when Webmin can "see" all the Virtuals > defined in those conf files! > > BTW... the problem with "--duplicate"... is that. you end up with > /etc/letsencrypt/live/mydomain-00n and > /etc/letsencypt/archive/mydomain-00n.... while if you don't use the flag > --duplicate... there is only one /etc/letsencrypt/live/mydomain and one > /etc/letsencrypt/archive/mydomain... and in the last one you get cert1.pem, > cert2.pem.... certN.pem and in the "live" area cert.pem is a symlink to > "certN.pem" in the archive area... then, once you define your certificates > in ssl.conf as /etc/letsencrypt/live/mydomain/cert.pem you don't need to do > anything else but restart httpd to get the new certificate showing in the > browsers!... Also... the first time that I used a letsencrypt certificate > for webmin... I was able to do it on the "SSL Settings" tab (webmin > cofiguration/ssl) by pointig the Private key file to > /etc/letsencrypt/live/mymaindomain/privkey.pem and the Certificate File as > a "Separate file" pointing to /etc/letsencript/live/mymaindomain/cert.pem. > > Thaks for all the work that you do with Webmin!!! (that I have been using > since the last millennium ;) ) > > Peace, with Justice! > Si, se puede! > Marcos > > "For what can war, but endless war, still breed?" (John Milton) > ------------------------------------------------------------------------------ Transform Data into Opportunity. Accelerate data analysis in your applications with Intel Data Analytics Acceleration Library. Click to learn more. http://pubads.g.doubleclick.net/gampad/clk?id=278785471&iu=/4140 - Forwarded by the Webmin mailing list at [email protected] To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list