Koozali.org: home of the SME Server

letsencrypt

Offline ElFroggio

  • *
  • 262
  • +0/-0
letsencrypt
« on: October 02, 2016, 09:28:18 PM »
SME 9.1.

I'm currently using the SSL certificates management contrib with a rapidssl certificate which is due to expire early next year. I'm looking at let's encrypt https://wiki.contribs.org/Letsencrypt. I don't understand the "John Crisp contrib".

  • Is this instead of the 1st section with dehydrated?
  • Do I need to uninstall my current SSL certificates management contrib?
  • I'm thinking of rolling it out during the XMas/New Year break. If I have any problem at that time, how to I roll back to my still valid rapidssl certificates?

Thanks

Syv

Offline DanB35

  • *****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: letsencrypt
« Reply #1 on: October 03, 2016, 01:01:49 AM »
The John Crisp contrib is self-contained--if you follow those instructions, you won't need to do any of the other steps in the how-to.  And his contrib has been working very well for me for several months.
......

Offline ElFroggio

  • *
  • 262
  • +0/-0
Re: letsencrypt
« Reply #2 on: October 03, 2016, 01:36:23 AM »
The John Crisp contrib is self-contained--if you follow those instructions, you won't need to do any of the other steps in the how-to.  And his contrib has been working very well for me for several months.

Thanks, excellent to know.

But the page doesn't mention if I need to remove the existing SSL certificates?


Thanks

Syv

Offline DanB35

  • *****
  • 764
  • +0/-0
    • http://www.familybrown.org
Re: letsencrypt
« Reply #3 on: October 03, 2016, 01:39:13 AM »
No, you don't need to remove your existing certificates.  The contrib will reconfigure the SME server to use the Let's Encrypt cert once it obtains it.  At that point, you can remove the old cert, but you don't need to.
......

Offline ElFroggio

  • *
  • 262
  • +0/-0
Re: letsencrypt
« Reply #4 on: October 03, 2016, 04:27:13 PM »
Thank you 8-)

Offline ReetP

  • *
  • 3,952
  • +6/-0
Re: letsencrypt
« Reply #5 on: October 04, 2016, 12:09:15 AM »
Sorry I missed all this :-)

I hope it should update itself without issues but nothing in life is guaranteed !

Note the contrib remains with the same name... it just handles creating configs.

It should remove the letsencrypt.sh rpm and install the dehydrated rpm.

There may be residual dirs left e.g. /etc/letsencrpt.sh

If you have any issues you can always revert to the self signed certs by removing the modSSL keys and starting again. I think I mention this on the wiki page.

Please let me know if there are any issues. I can't guantee instant response but will get to it when I can.

B. Rgds
John
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation