Re: [webmin-l] letsencrypt... "duplicate" flag and "end" slash in path
Marcos Rubinstein <[email protected]>
| Newsgroups | gmane.comp.web.webmin.general |
|---|---|
| Message-ID | <CAMo2Tjk9Vx-1G1tRfb9sisEkpHGEqABf6AhJ07P8sCpeF9tGow@mail.gmail.com> |
On Tue, Mar 29, 2016 at 9:54 PM, Jamie Cameron <[email protected]> wrote: > On 29/Mar/2016 11:54 Marcos Rubinstein <[email protected]> wrote .. > > Hi Jamie: > > > > why did you decide to use the "--duplicate" file for letsencrypt? > > > > and... can I choose *not* to use it? > > > > also... > > > > for some reason... if in the apache configuration you don't use the / > > (slash) when defining the root directory of a virtual domain.... the > webmin > > letsencrypt module (under webmin configuration/ssl) will give you an > > error!!!! (in other words.... if I have in the config something like > > "rootdir /something/virtualdomain instead of /something/virtualdomain/ , > I > > will get an error saying that "/something/virtualdomain" does not > > exists.... that's when I use the option of "A different Apache virtual > > host" and choose that virtualhost... if, instead, I use "Other directory" > > and I include the final slash (/) on that... webmin is able to get the > > certificate). NOTA BENE: after "playing" with the "letsencrypt" CLI... I > > found out that letsencrypt does not "understand" the "old style" > > httpd.conf!... it only detect the last "Virtual Domain" defined in > > httpd.conf and in ssl.conf... even when Webmin can "see" all the Virtuals > > defined in those conf files! > > That's odd, the code doesn't assume that the root directory ends with a /. > What's the exact error you are getting? > > the error: Requesting a new certificate for www.mydomain.org, using the website directory "/path-to/mydomain" .. .. request failed : Updating letsencrypt and virtual environment dependencies...You are using pip version 8.0.3, however version 8.1.1 is available. You should consider upgrading via the 'pip install --upgrade pip' command. .... Running with virtualenv: /root/.local/share/letsencrypt/bin/letsencrypt certonly -a webroot -d www.mydomain.org --webroot-path "/path-to/mydomain" --duplicate --config /tmp/.webmin/802539_17261_1_letsencrypt.cgi The webroot plugin is not working; there may be problems with your existing configuration. The error was: PluginError('"/path-to/mydomain" does not exist or is not a directory',) and I used the option of " A different Apache virtual host" and I selected " www.mydomain.org" (of course... mydomain.org is not the real name I used ;) ) (real domain name changed to that to protect the inocent ;) ) > > BTW... the problem with "--duplicate"... is that. you end up with > > /etc/letsencrypt/live/mydomain-00n and > > /etc/letsencypt/archive/mydomain-00n.... while if you don't use the flag > > --duplicate... there is only one /etc/letsencrypt/live/mydomain and one > > /etc/letsencrypt/archive/mydomain... and in the last one you get > cert1.pem, > > cert2.pem.... certN.pem and in the "live" area cert.pem is a symlink to > > "certN.pem" in the archive area... then, once you define your > certificates > > in ssl.conf as /etc/letsencrypt/live/mydomain/cert.pem you don't need to > do > > anything else but restart httpd to get the new certificate showing in the > > browsers!... Also... the first time that I used a letsencrypt certificate > > for webmin... I was able to do it on the "SSL Settings" tab (webmin > > cofiguration/ssl) by pointig the Private key file to > > /etc/letsencrypt/live/mymaindomain/privkey.pem and the Certificate File > as > > a "Separate file" pointing to > /etc/letsencript/live/mymaindomain/cert.pem. > > This shouldn't be an issue though for Webmin, as it copies the output files > to it's own directory. Or do you have some other Apache config that is > referring > to the files under /etc/letsencrypt directly? > > exactly, I still don't understand why you need to use the --duplicate flag... doing that force me to have webmin fetching one cert for itself... and then have a script using letsencrypt CLI to update the one for apache.... or, change apache's ssh configuration each time, or change links each time, etc.... I don't see why you can't copy /etc/letsencrypt/live/www.mydomain/privkey.pem to the /etc/webmin/ directory... or instruct webmin to use that key directly!... Also: in the example I gave you.. I selected "No" on the "Copy new key and certificate to Webmin?" Any chance to have a configuration option of *not* using --duplicate switch? even if using it is the default! Thanks! Marcos > > Thaks for all the work that you do with Webmin!!! (that I have been using > > since the last millennium ;) ) > > > > Peace, with Justice! > > Si, se puede! > > Marcos > > > > "For what can war, but endless war, still breed?" (John Milton) > ------------------------------------------------------------------------------ Transform Data into Opportunity. Accelerate data analysis in your applications with Intel Data Analytics Acceleration Library. Click to learn more. http://pubads.g.doubleclick.net/gampad/clk?id=278785471&iu=/4140 - Forwarded by the Webmin mailing list at [email protected] To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list