Re: [webmin-l] letsencrypt... "duplicate" flag and "end" slash in path

Marcos Rubinstein <[email protected]>
Newsgroups gmane.comp.web.webmin.general
Message-ID <CAMo2Tjk9Vx-1G1tRfb9sisEkpHGEqABf6AhJ07P8sCpeF9tGow@mail.gmail.com>
On Tue, Mar 29, 2016 at 9:54 PM, Jamie Cameron <[email protected]> wrote:

> On 29/Mar/2016 11:54 Marcos Rubinstein <[email protected]> wrote ..
> > Hi Jamie:
> >
> > why did you decide to use the "--duplicate" file for letsencrypt?
> >
> > and... can I choose *not* to use it?
> >
> > also...
> >
> > for some reason... if in the apache configuration you don't use the /
> > (slash) when defining the root directory of a virtual domain.... the
> webmin
> > letsencrypt module (under webmin configuration/ssl) will give you an
> > error!!!! (in other words.... if I have in the config something like
> > "rootdir /something/virtualdomain instead of /something/virtualdomain/ ,
> I
> > will get an error saying that "/something/virtualdomain" does not
> > exists.... that's when I use the option of "A different Apache virtual
> > host" and choose that virtualhost... if, instead, I use "Other directory"
> > and I include the final slash (/) on that... webmin is able to get the
> > certificate). NOTA BENE: after "playing" with the "letsencrypt" CLI... I
> > found out that letsencrypt does not "understand" the "old style"
> > httpd.conf!... it only detect the last "Virtual Domain" defined in
> > httpd.conf and in ssl.conf... even when Webmin can "see" all the Virtuals
> > defined in those conf files!
>
> That's odd, the code doesn't assume that the root directory ends with a /.
> What's the exact error you are getting?
>
>
the error:

Requesting a new certificate for www.mydomain.org, using the website
directory "/path-to/mydomain" ..

.. request failed :

Updating letsencrypt and virtual environment dependencies...You are using
pip version 8.0.3, however version 8.1.1 is available.
You should consider upgrading via the 'pip install --upgrade pip' command.
....
Running with virtualenv: /root/.local/share/letsencrypt/bin/letsencrypt
certonly -a webroot -d www.mydomain.org --webroot-path "/path-to/mydomain"
--duplicate --config /tmp/.webmin/802539_17261_1_letsencrypt.cgi
The webroot plugin is not working; there may be problems with your existing
configuration.
The error was: PluginError('"/path-to/mydomain" does not exist or is not a
directory',)


and I used the option of " A different Apache virtual host" and I selected "
www.mydomain.org"

(of course... mydomain.org is not the real name I used ;) ) (real domain
name changed to that to protect the inocent ;) )


> > BTW... the problem with "--duplicate"... is that. you end up with
> > /etc/letsencrypt/live/mydomain-00n and
> > /etc/letsencypt/archive/mydomain-00n.... while if you don't use the flag
> > --duplicate... there is only one /etc/letsencrypt/live/mydomain and one
> > /etc/letsencrypt/archive/mydomain... and in the last one you get
> cert1.pem,
> > cert2.pem.... certN.pem and in the "live" area cert.pem is a symlink to
> > "certN.pem" in the archive area... then, once you define your
> certificates
> > in ssl.conf as /etc/letsencrypt/live/mydomain/cert.pem you don't need to
> do
> > anything else but restart httpd to get the new certificate showing in the
> > browsers!... Also... the first time that I used a letsencrypt certificate
> > for webmin... I was able to do it on the "SSL Settings" tab (webmin
> > cofiguration/ssl) by pointig the Private key file to
> > /etc/letsencrypt/live/mymaindomain/privkey.pem and the Certificate File
> as
> > a "Separate file" pointing to
> /etc/letsencript/live/mymaindomain/cert.pem.
>
> This shouldn't be an issue though for Webmin, as it copies the output files
> to it's own directory. Or do you have some other Apache config that is
> referring
> to the files under /etc/letsencrypt directly?
>
>
exactly, I still don't understand why you need to use the --duplicate
flag... doing that force me to have webmin fetching one cert for itself...
and then have a script using letsencrypt CLI to update the one for
apache.... or, change apache's ssh configuration each time, or change links
each time, etc.... I don't see why you can't copy
/etc/letsencrypt/live/www.mydomain/privkey.pem to the /etc/webmin/
directory... or instruct webmin to use that key directly!... Also: in the
example I gave you.. I selected "No" on the "Copy new key and certificate
to Webmin?" Any chance to have a configuration option of *not* using
--duplicate switch? even if using it is the default!

Thanks!
Marcos


> > Thaks for all the work that you do with Webmin!!! (that I have been using
> > since the last millennium ;) )
> >
> > Peace, with Justice!
> > Si, se puede!
> > Marcos
> >
> > "For what can war, but endless war, still breed?" (John Milton)
>

------------------------------------------------------------------------------
Transform Data into Opportunity.
Accelerate data analysis in your applications with
Intel Data Analytics Acceleration Library.
Click to learn more.
http://pubads.g.doubleclick.net/gampad/clk?id=278785471&iu=/4140

-
Forwarded by the Webmin mailing list at [email protected]
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.