Outils pour utilisateurs

Outils du site


commun:certificat_ssl

Différences

Ci-dessous, les différences entre deux révisions de la page.

Lien vers cette vue comparative

Prochaine révision
Révision précédente
commun:certificat_ssl [2018/09/18 08:38] – créée francoiscommun:certificat_ssl [2022/01/04 09:21] (Version actuelle) – [Automatic renewal] francois
Ligne 3: Ligne 3:
 Utilisation du service "let's encrypt" Utilisation du service "let's encrypt"
  
-<code>+<code bash>
 francois@maison ~]$ sudo certbot --apache                                 francois@maison ~]$ sudo certbot --apache                                
 Saving debug log to /var/log/letsencrypt/letsencrypt.log Saving debug log to /var/log/letsencrypt/letsencrypt.log
Ligne 76: Ligne 76:
 [francois@maison ~]$ [francois@maison ~]$
 </code> </code>
 +
 +===== Automatic renewal =====
 +
 +Create a systemd ''certbot.service'':
 +
 +''/etc/systemd/system/certbot.service''
 +<code ini>
 +[Unit]
 +Description=Let's Encrypt renewal
 +
 +[Service]
 +Type=oneshot
 +ExecStart=/usr/bin/certbot renew --quiet --agree-tos
 +</code>
 +
 +If you do not use a plugin to manage the web server configuration automatically, the web server has to be reloaded manually to reload the certificates each time they are renewed. This can be done by adding --deploy-hook ''systemctl reload httpd.service'' to the ExecStart command.
 +
 +> Before adding a timer, check that the service is working correctly and is not trying to prompt anything.
 +
 +Add a timer to check for certificate renewal twice a day and include a randomized delay so that everyone's requests for renewal will be spread over the day to lighten the Let's Encrypt server load [2]:
 +
 +''/etc/systemd/system/certbot.timer''
 +
 +<code ini>
 +[Unit]
 +Description=Twice daily renewal of Let's Encrypt's certificates
 +
 +[Timer]
 +OnCalendar=0/12:00:00
 +RandomizedDelaySec=1h
 +Persistent=true
 +
 +[Install]
 +WantedBy=timers.target
 +</code>
 +
 +Enable and start certbot.timer. 
 +
 +Ajouter un sous-domaine
 +  sudo certbot -d blog.beafrancois.fr,dav.beafrancois.fr,maison.beafrancois.fr,service.beafrancois.fr,musique.beafrancois.fr,nuage.beafrancois.fr,fichiers.beafrancois.fr,git.beafrancois.fr,wiki.beafrancois.fr,shell.beafrancois.fr --expand
commun/certificat_ssl.1537259933.txt.gz · Dernière modification : (modification externe)

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki