Re: [webmin-l] letsencrypt... "duplicate" flag and "end" slash in path

"Jamie Cameron" <[email protected]>
Newsgroups gmane.comp.web.webmin.general
Message-ID <[email protected]>
On 29/Mar/2016 20:34 Marcos Rubinstein <[email protected]> wrote ..
> On Tue, Mar 29, 2016 at 9:54 PM, Jamie Cameron <[email protected]> wrote:
> 
> > On 29/Mar/2016 11:54 Marcos Rubinstein <[email protected]> wrote ..
> > > Hi Jamie:
> > >
> > > why did you decide to use the "--duplicate" file for letsencrypt?
> > >
> > > and... can I choose *not* to use it?
> > >
> > > also...
> > >
> > > for some reason... if in the apache configuration you don't use the /
> > > (slash) when defining the root directory of a virtual domain.... the
> > webmin
> > > letsencrypt module (under webmin configuration/ssl) will give you an
> > > error!!!! (in other words.... if I have in the config something like
> > > "rootdir /something/virtualdomain instead of /something/virtualdomain/ ,
> > I
> > > will get an error saying that "/something/virtualdomain" does not
> > > exists.... that's when I use the option of "A different Apache virtual
> > > host" and choose that virtualhost... if, instead, I use "Other directory"
> > > and I include the final slash (/) on that... webmin is able to get the
> > > certificate). NOTA BENE: after "playing" with the "letsencrypt" CLI... I
> > > found out that letsencrypt does not "understand" the "old style"
> > > httpd.conf!... it only detect the last "Virtual Domain" defined in
> > > httpd.conf and in ssl.conf... even when Webmin can "see" all the Virtuals
> > > defined in those conf files!
> >
> > That's odd, the code doesn't assume that the root directory ends with a /.
> > What's the exact error you are getting?
> >
> >
> the error:
> 
> Requesting a new certificate for www.mydomain.org, using the website
> directory "/path-to/mydomain" ..
> 
> .. request failed :
> 
> Updating letsencrypt and virtual environment dependencies...You are using
> pip version 8.0.3, however version 8.1.1 is available.
> You should consider upgrading via the 'pip install --upgrade pip' command.
> ....
> Running with virtualenv: /root/.local/share/letsencrypt/bin/letsencrypt
> certonly -a webroot -d www.mydomain.org --webroot-path "/path-to/mydomain"
> --duplicate --config /tmp/.webmin/802539_17261_1_letsencrypt.cgi
> The webroot plugin is not working; there may be problems with your existing
> configuration.
> The error was: PluginError('"/path-to/mydomain" does not exist or is not a
> directory',)
> 
> 
> and I used the option of " A different Apache virtual host" and I selected "
> www.mydomain.org"
> 
> (of course... mydomain.org is not the real name I used ;) ) (real domain
> name changed to that to protect the inocent ;) )

I think I see the bug - in your Apache config, does the DocumentRoot line for
/path-to/mydomain have quotes around the path? If so, try removing them.

> > > BTW... the problem with "--duplicate"... is that. you end up with
> > > /etc/letsencrypt/live/mydomain-00n and
> > > /etc/letsencypt/archive/mydomain-00n.... while if you don't use the flag
> > > --duplicate... there is only one /etc/letsencrypt/live/mydomain and one
> > > /etc/letsencrypt/archive/mydomain... and in the last one you get
> > cert1.pem,
> > > cert2.pem.... certN.pem and in the "live" area cert.pem is a symlink to
> > > "certN.pem" in the archive area... then, once you define your
> > certificates
> > > in ssl.conf as /etc/letsencrypt/live/mydomain/cert.pem you don't need to
> > do
> > > anything else but restart httpd to get the new certificate showing in the
> > > browsers!... Also... the first time that I used a letsencrypt certificate
> > > for webmin... I was able to do it on the "SSL Settings" tab (webmin
> > > cofiguration/ssl) by pointig the Private key file to
> > > /etc/letsencrypt/live/mymaindomain/privkey.pem and the Certificate File
> > as
> > > a "Separate file" pointing to
> > /etc/letsencript/live/mymaindomain/cert.pem.
> >
> > This shouldn't be an issue though for Webmin, as it copies the output files
> > to it's own directory. Or do you have some other Apache config that is
> > referring
> > to the files under /etc/letsencrypt directly?
> >
> >
> exactly, I still don't understand why you need to use the --duplicate
> flag... doing that force me to have webmin fetching one cert for itself...
> and then have a script using letsencrypt CLI to update the one for
> apache.... or, change apache's ssh configuration each time, or change links
> each time, etc.... I don't see why you can't copy
> /etc/letsencrypt/live/www.mydomain/privkey.pem to the /etc/webmin/
> directory... or instruct webmin to use that key directly!... Also: in the
> example I gave you.. I selected "No" on the "Copy new key and certificate
> to Webmin?" Any chance to have a configuration option of *not* using
> --duplicate switch? even if using it is the default!

So it sounds like what you really want is a way to have the cert copied
to the Apache config for the domain? This exists in Virtualmin already, but
not in plain Webmin.

> Thanks!
> Marcos
> 
> 
> > > Thaks for all the work that you do with Webmin!!! (that I have been using
> > > since the last millennium ;) )
> > >
> > > Peace, with Justice!
> > > Si, se puede!
> > > Marcos
> > >
> > > "For what can war, but endless war, still breed?" (John Milton)
> >



------------------------------------------------------------------------------
Transform Data into Opportunity.
Accelerate data analysis in your applications with
Intel Data Analytics Acceleration Library.
Click to learn more.
http://pubads.g.doubleclick.net/gampad/clk?id=278785471&iu=/4140
-
Forwarded by the Webmin mailing list at [email protected]
To remove yourself from this list, go to
http://lists.sourceforge.net/lists/listinfo/webadmin-list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.