Koozali.org: home of the SME Server

Recent Posts

Pages: 1 ... 5 6 [7] 8 9 10
61
Koozali SME Server 11.x / Re: Enabling Letsencrypt on Beta
« Last post by ReetP on August 25, 2025, 03:50:07 PM »
Hopefully fixed here but you will need to either undo all your work, or blow it away and start again.

https://bugs.koozali.org/show_bug.cgi?id=13109#c3
62
Koozali SME Server 11.x / Re: Letsencrypt panel is looking great!
« Last post by ReetP on August 25, 2025, 03:49:08 PM »
63
Koozali SME Server 11.x / Re: Letsencrypt panel is looking great!
« Last post by ReetP on August 25, 2025, 12:15:45 AM »
64
Koozali SME Server 11.x / Re: Enabling Letsencrypt on Beta
« Last post by ReetP on August 25, 2025, 12:13:41 AM »
FWIW for now we need to fix the cert type to default to rsa.

Bug is here.

https://bugs.koozali.org/show_bug.cgi?id=13109

All you actually need to do temporarily is set

45Algorithms

Code: [Select]
KEY_ALGO=rsa
Then:
Code: [Select]
signal-event smeserver-certificates-update

I'll push a more permanent fix in the next day or so.
65
Koozali SME Server 11.x / Re: Enabling Letsencrypt on Beta
« Last post by ReetP on August 23, 2025, 07:40:53 PM »
Note please don't take my comments personally.

The help is gratefully appreciated, but we are few and we don't have time to chase ghosts.

The bug opening methodology lets us track, manage, and fix issues more easily.

It is pretty simple :-)

Note too that is you are testing anything eg the letsencrypt panel then check

tail -f /var/log/smanager/smanager.log
tail -f /var/log/messages

And as ever, ask me for a Rocket account if you want a bit of friendly banter, help and learning.
66
Koozali SME Server 11.x / Re: Enabling Letsencrypt on Beta
« Last post by ReetP on August 23, 2025, 05:28:15 PM »
You are correct, I should have warned people to use these instructions at their own risk.

Indeed. It is a long way from what you should be doing.

Quote
Mine are ephemeral test systems, they are tossed with each new release, not upgraded.

Should be stated, as above.

Quote
I see others here saying that they have enabled letsencrypt but are not telling how, like me they are probably tired of the browser warnings and wanting usernames and passwords saved.

If you check there is a new panel. As we have always said, if it doesn't function as intended, open a bug. Same mantra for years. That's how we work and we can then advise how to fix or whatever. The panel is a new feature and IIRC still needs work. And this is Beta and should be expected.

Regrettably here the answers will get picked up by unsuspecting users (or Heaven forbid AI) and postulated as the correct answer.

Quote
Personally, I have always gone to forums first to seek answers, feeling they are easier to search than searching a bug reporting database.

But we have always said - if it doesn't work as expected, open a bug. This is particularly true currently as it allows us to track and fix issues. It is how we work.

Search for the letsencrypt ones - if yours is not listed, open a new one please. It does not need your fix. Just what has, or has not happened.

On top of which a lot of the templating you have done should already be there, but as we don't know what version you are running we can't tell. smeserver-certificates-11.0-7.el8.sme.noarch should have most of it.

https://src.koozali.org/smeserver/smeserver-certificates

Quote
Rocket chat might be great for you developers, but its published knowledge and insights are hidden away from average users like me. So, I post here, where my questions and limited knowledge are shared with the world.

There is no 'them and us'. We are all Koozali SME users first and foremost. I am no dev. I hack a bit. /ends.

So Rocket.Chat is a messaging system that anyone can join and use. It is just a very easy way for people to communicate and fix issues, often in real time.

There is no magic sauce or secret squirrel stuff there. There are ordinary users and devs (the couple that there actually are).

As it was my own test system originally I kept it locked to prevent spammers. That has continued due to limited licence counts etc. If people want an account they can just ask me. There is no fee or qualification required. But you need will need an account to view information.

It is MUCH easier to discuss this sort of thing there and users can be guided rather than making elementary mistakes.

Again, I have said this on countless posts.

We are grateful for testing, but rather than posting workarounds for problems that may not actually even exist, please follow established procedures or you, us, and many others will be in a right mess.

And then people will be asking us to fix the hack of yours we know nothing about that they read about 'somewhere' and then haven't undone........

Thanks.

67
Koozali SME Server 11.x / Re: Enabling Letsencrypt on Beta
« Last post by compdoc on August 23, 2025, 04:21:58 PM »
You are correct, I should have warned people to use these instructions at their own risk.

Mine are ephemeral test systems, they are tossed with each new release, not upgraded. I see others here saying that they have enabled letsencrypt but are not telling how, like me they are probably tired of the browser warnings and wanting usernames and passwords saved.

Personally, I have always gone to forums first to seek answers, feeling they are easier to search than searching a bug reporting database. Rocket chat might be great for you developers, but its published knowledge and insights are hidden away from average users like me. So, I post here, where my questions and limited knowledge are shared with the world.
68
Koozali SME Server 11.x / Re: Letsencrypt panel is looking great!
« Last post by Jean-Philippe Pialasse on August 23, 2025, 03:47:21 PM »
Quote
/etc/e-smith/templates/etc/dehydrated/config/45Algorithm

this one indeed has to be reverted to force rsa. 

while we have  packages allowing now to handle elliptic curve, there are 2 remaining blockers:
- some template code still need to be updated to use it in sme
- there are still smtp server around that are not able to handle elliptic curve. As we use the same cert for the emails we should focus on backward compatibility to avoid mail sent to be deferred and bounce.
69
Koozali SME Server 11.x / Re: Letsencrypt panel is looking great!
« Last post by ReetP on August 23, 2025, 11:47:58 AM »
70
Koozali SME Server 11.x / Re: Enabling Letsencrypt on Beta
« Last post by ReetP on August 23, 2025, 11:43:25 AM »
Don't do this.

You have now likely borked your system for updates.

The panel should automate this but we are in BETA and it may not work.

The correct procedure is file a bug and wait for a fix.

Pages: 1 ... 5 6 [7] 8 9 10