{"id":226,"date":"2018-09-09T13:00:54","date_gmt":"2018-09-09T11:00:54","guid":{"rendered":"https:\/\/blog.chloesoe.ch\/?p=226"},"modified":"2018-09-27T16:46:16","modified_gmt":"2018-09-27T14:46:16","slug":"https-with-free-lets-encrypt-certificate","status":"publish","type":"post","link":"https:\/\/blog.chloesoe.ch\/?p=226","title":{"rendered":"https with free Let&#8217;s Encrypt certificate"},"content":{"rendered":"<p><em>This how to was created, before wildcard certificates were possible.<\/em><\/p>\n<p>Steps:<\/p>\n<ol>\n<li>Install lets encrypt<\/li>\n<li>Get a certificate<\/li>\n<li>Add the certificate path to apache config<\/li>\n<\/ol>\n<h2>Get a certificate with certbot<\/h2>\n<p>Let's encrypt recommends cretbot to create and renew a certificate. For openSUSE we can follow the steps from https:\/\/certbot.eff.org\/#pip-other, below the steps summarized:<\/p>\n<pre><code>wget https:\/\/dl.eff.org\/certbot-auto\nchmod a+x \/opt\/certbot-auto\n\/opt\/certbot-auto certonly -d &lt;SUBDOMAIN&gt;.example.com --webroot -w \/opt\/tomcat\/webapps\/ROOT\/\n<\/code><\/pre>\n<p>You could add multiple domain names with -d <SUBDOMAIN>.example.com if needed.<\/p>\n<p>After that, the certificates are stored at \/etc\/letsencrypt\/live\/<SUBDOMAIN>.example.com . Now change in the SSL configuration of \/etc\/apache2\/conf.d\/example.com this two lines and reload apache2:<\/p>\n<pre><code>SSLCertificateKeyFile \/etc\/letsencrypt\/live\/&lt;SUBDOMAIN&gt;.example.com\/privkey.pem\nSSLCertificateFile \/etc\/letsencrypt\/live\/&lt;SUBDOMAIN&gt;.example.com\/fullchain.pem\n<\/code><\/pre>\n<h2>Automatically renew the certificate<\/h2>\n<p>It is recommended to run the renew script daily (see <a href=\"https:\/\/serverfault.com\/a\/790776\/391060\">https:\/\/serverfault.com\/...<\/a> ). The certificate actually is renewed, if the expire date is &lt; than 30 days. A let's encrypt certificate by default is valid 90 days.<\/p>\n<p>Add a cronjob with crontab -e and add following line:<\/p>\n<pre><code>45 00 * * * \/opt\/certbot-auto renew --no-self-upgrade --post-hook \"systemctl reload apache2\"\n<\/code><\/pre>\n<p>This will run certbot-auto daily and with \"post-hook\" apache2 is reloaded, if the certificate is renewed.<br \/>\nCreate certs for Apache reverse proxy<\/p>\n<p>Certbot has a plugin, to automatically create a certificate for all subdomains. To create the certificat run:<\/p>\n<pre><code>\/opt\/certbot-auto --apache\n<\/code><\/pre>\n<p>The script will ask you, to select the domains, choose all then a certificate is generated and a https config for every subdomain.<\/p>\n<p>If you add a new subdomain you then the certificate could be renewed with the new subdomain included with this command:<\/p>\n<pre><code>\/opt\/certbot-auto certonly --apache --expand\nsystemctl restart apache2.service\n<\/code><\/pre>\n<h2>Windows server with Apache<\/h2>\n<p>Install according to https:\/\/github.com\/Lone-Coder\/letsencrypt-win-simple.<br \/>\nSteps are first downloading and extracting, then run letsencrypt.exe from command line:<\/p>\n<pre><code>letsencrypt.exe --plugin manual --manualhost indowsserver.example.com --webroot C:\\apache2\\htdocs\n<\/code><\/pre>\n<p>Certificates are stored at:<\/p>\n<ul>\n<li>Key: \"C:\/programdata\/letsencrypt-win-simple\/httpsacme-v01.api.letsencrypt.org\/windowsserver.example.com-key.pem\"<\/li>\n<li>Cert: \"C:\/programdata\/letsencrypt-win-simple\/httpsacme-v01.api.letsencrypt.org\/windowsserver.example.com-chain.pem\"<\/li>\n<\/ul>\n<p>This both certificate have to be configured in \"C:\\Apache24\\conf\\example.conf\"<br \/>\nTask Scheduler has a renewing job which runs daily<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This how to was created, before wildcard certificates were possible. Steps: Install lets encrypt Get a certificate Add the certificate path to apache config Get a certificate with certbot Let&#8217;s encrypt recommends cretbot to create and renew a certificate. For openSUSE we can follow the steps from https:\/\/certbot.eff.org\/#pip-other, below the steps summarized: wget https:\/\/dl.eff.org\/certbot-auto chmod&#8230; <a href=\"https:\/\/blog.chloesoe.ch\/?p=226\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">https with free Let&#8217;s Encrypt certificate<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-226","post","type-post","status-publish","format-standard","hentry","category-it-sec"],"_links":{"self":[{"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=\/wp\/v2\/posts\/226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=226"}],"version-history":[{"count":5,"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=\/wp\/v2\/posts\/226\/revisions"}],"predecessor-version":[{"id":231,"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=\/wp\/v2\/posts\/226\/revisions\/231"}],"wp:attachment":[{"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.chloesoe.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}