Koozali.org: home of the SME Server

Help please, certificate nightmare

Offline groutley

  • ****
  • 213
  • +0/-0
    • http://www.routley.homeip.net
Re: Help please, certificate nightmare
« Reply #30 on: November 23, 2023, 07:56:03 AM »
Wow.. I struggled all day to understand why it would not add enable ‘letsencryptSSLcert’ for host ‘smtp’.
I couldnt see anything in the logs that came close to suggesting an issue when the console-save ran.
There was no typo.. couldnt be.. I had recalled the previous command that successfully did this for ‘mail’ and all I had changed was ‘mail’ to ‘smtp’..
 This evening I had a mic drop moment!
I looked at ‘db hosts show’ and it did not have a ‘smtp’ host..
So a few days ago, I went and deleted all the hostnames, including the ‘smtp’ hostname..
Now I overlooked this, because SME recreated most of the ‘self’ alias hostnames itself.
But apparently ‘smtp’ is not one of them, and must be one I created many many years ago, on probably SME3 or 4!
Would you believe, when I added the hostname, the db setprop hosts command then successfully added the ‘letsencryptSSLcert’ propert.. and after the console save the ‘/etc/dehydrated/domains.txt’
Showed the ‘smtp’ host and the dehydrated -c successfully updated the cert with that host !
Yay!
Thank you for all your help and expertise, your help has been invaluable in getting this sorted for me.
 Thank you, thank you thank you.. merci.. I just cannot say it enough.

Offline ReetP

  • *
  • 3,740
  • +5/-0
Re: Help please, certificate nightmare
« Reply #31 on: November 23, 2023, 12:01:52 PM »
Fab and glad you got it sorted.  :hammer:

Well done for being patient and supplying the requested info.

One thing to consider - not just for you but anyone else following this - is that when you have issues, document things as best you can right at the start. (trying to educate here, not criticise!!)

If you read back here you can see the sort of info we requested and it is probably all quite obvious now! If some of it had been provided right at the start it would have probably shortened the debug process.

I did write this some while ago and worth a read to understand the methods. The 'Documenting things' is the real key (and not running off making random changes in the hope of fixing things without telling us what you are doing!).

https://forums.koozali.org/index.php/topic,54724.0.html

The more you document things at the start, the easier and quicker it is to fix!!

Anyways, once again I am pleased we got it working, and well done. :pint:
...
1. Read the Manual
2. Read the Wiki
3. Don't ask for support on Unsupported versions of software
4. I have a job, wife, and kids and do this in my spare time. If you want something fixed, please help.

Bugs are easier than you think: http://wiki.contribs.org/Bugzilla_Help

If you love SME and don't want to lose it, join in: http://wiki.contribs.org/Koozali_Foundation