Re: [webmin-l] letsencrypt... "duplicate" flag and "end" slash in path
"Jamie Cameron" <[email protected]>
| Newsgroups | gmane.comp.web.webmin.general |
|---|---|
| Message-ID | <[email protected]> |
On 29/Mar/2016 20:34 Marcos Rubinstein <[email protected]> wrote .. > On Tue, Mar 29, 2016 at 9:54 PM, Jamie Cameron <[email protected]> wrote: > > > On 29/Mar/2016 11:54 Marcos Rubinstein <[email protected]> wrote .. > > > Hi Jamie: > > > > > > why did you decide to use the "--duplicate" file for letsencrypt? > > > > > > and... can I choose *not* to use it? > > > > > > also... > > > > > > for some reason... if in the apache configuration you don't use the / > > > (slash) when defining the root directory of a virtual domain.... the > > webmin > > > letsencrypt module (under webmin configuration/ssl) will give you an > > > error!!!! (in other words.... if I have in the config something like > > > "rootdir /something/virtualdomain instead of /something/virtualdomain/ , > > I > > > will get an error saying that "/something/virtualdomain" does not > > > exists.... that's when I use the option of "A different Apache virtual > > > host" and choose that virtualhost... if, instead, I use "Other directory" > > > and I include the final slash (/) on that... webmin is able to get the > > > certificate). NOTA BENE: after "playing" with the "letsencrypt" CLI... I > > > found out that letsencrypt does not "understand" the "old style" > > > httpd.conf!... it only detect the last "Virtual Domain" defined in > > > httpd.conf and in ssl.conf... even when Webmin can "see" all the Virtuals > > > defined in those conf files! > > > > That's odd, the code doesn't assume that the root directory ends with a /. > > What's the exact error you are getting? > > > > > the error: > > Requesting a new certificate for www.mydomain.org, using the website > directory "/path-to/mydomain" .. > > .. request failed : > > Updating letsencrypt and virtual environment dependencies...You are using > pip version 8.0.3, however version 8.1.1 is available. > You should consider upgrading via the 'pip install --upgrade pip' command. > .... > Running with virtualenv: /root/.local/share/letsencrypt/bin/letsencrypt > certonly -a webroot -d www.mydomain.org --webroot-path "/path-to/mydomain" > --duplicate --config /tmp/.webmin/802539_17261_1_letsencrypt.cgi > The webroot plugin is not working; there may be problems with your existing > configuration. > The error was: PluginError('"/path-to/mydomain" does not exist or is not a > directory',) > > > and I used the option of " A different Apache virtual host" and I selected " > www.mydomain.org" > > (of course... mydomain.org is not the real name I used ;) ) (real domain > name changed to that to protect the inocent ;) ) I think I see the bug - in your Apache config, does the DocumentRoot line for /path-to/mydomain have quotes around the path? If so, try removing them. > > > BTW... the problem with "--duplicate"... is that. you end up with > > > /etc/letsencrypt/live/mydomain-00n and > > > /etc/letsencypt/archive/mydomain-00n.... while if you don't use the flag > > > --duplicate... there is only one /etc/letsencrypt/live/mydomain and one > > > /etc/letsencrypt/archive/mydomain... and in the last one you get > > cert1.pem, > > > cert2.pem.... certN.pem and in the "live" area cert.pem is a symlink to > > > "certN.pem" in the archive area... then, once you define your > > certificates > > > in ssl.conf as /etc/letsencrypt/live/mydomain/cert.pem you don't need to > > do > > > anything else but restart httpd to get the new certificate showing in the > > > browsers!... Also... the first time that I used a letsencrypt certificate > > > for webmin... I was able to do it on the "SSL Settings" tab (webmin > > > cofiguration/ssl) by pointig the Private key file to > > > /etc/letsencrypt/live/mymaindomain/privkey.pem and the Certificate File > > as > > > a "Separate file" pointing to > > /etc/letsencript/live/mymaindomain/cert.pem. > > > > This shouldn't be an issue though for Webmin, as it copies the output files > > to it's own directory. Or do you have some other Apache config that is > > referring > > to the files under /etc/letsencrypt directly? > > > > > exactly, I still don't understand why you need to use the --duplicate > flag... doing that force me to have webmin fetching one cert for itself... > and then have a script using letsencrypt CLI to update the one for > apache.... or, change apache's ssh configuration each time, or change links > each time, etc.... I don't see why you can't copy > /etc/letsencrypt/live/www.mydomain/privkey.pem to the /etc/webmin/ > directory... or instruct webmin to use that key directly!... Also: in the > example I gave you.. I selected "No" on the "Copy new key and certificate > to Webmin?" Any chance to have a configuration option of *not* using > --duplicate switch? even if using it is the default! So it sounds like what you really want is a way to have the cert copied to the Apache config for the domain? This exists in Virtualmin already, but not in plain Webmin. > Thanks! > Marcos > > > > > Thaks for all the work that you do with Webmin!!! (that I have been using > > > since the last millennium ;) ) > > > > > > Peace, with Justice! > > > Si, se puede! > > > Marcos > > > > > > "For what can war, but endless war, still breed?" (John Milton) > > ------------------------------------------------------------------------------ Transform Data into Opportunity. Accelerate data analysis in your applications with Intel Data Analytics Acceleration Library. Click to learn more. http://pubads.g.doubleclick.net/gampad/clk?id=278785471&iu=/4140 - Forwarded by the Webmin mailing list at [email protected] To remove yourself from this list, go to http://lists.sourceforge.net/lists/listinfo/webadmin-list