Comment on Looking to move from Caddy

lemmyvore@feddit.nl ⁨1⁩ ⁨week⁩ ago

I’m also using Certbot with DeSEC. I simply run it daily with anacron. If it doesn’t need to renew the certs yet it will say so and stop. That’s basically it.

I think it’s a very good idea for your LE renewal to be independent of whatever reverse proxy or web server you’re using.

Please keep in mind that Certbot is a Python app so you can manage it with venv. Here’s how I install it in a dedicated dir (let’s say /srv/letsencrypt because using /etc is not appropriate and it bugs me 😆):

#!/bin/bash
set -e
apt install python3-venv
/usr/bin/python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install --upgrade pip
python3 -m pip install --upgrade certbot certbot-dns-desec

And to update it:

#!/bin/bash
set -e
source .venv/bin/activate
python3 -m pip install --upgrade pip
python3 -m pip install --upgrade certbot certbot-dns-desec

As for renewing certs (the script is longer, I’m making sure to create dirs and so on but this is the gist of it):

source .venv/bin/activate

./.venv/bin/certbot \
--config-dir "$CFGDIR" \
--logs-dir "$LOGDIR" \
--work-dir "$TMPDIR" \
--domain "*.${DOMAIN}" \
--domain "*.${DOMAIN}" \
--authenticator dns-desec \
--dns-desec-credentials "${SECDIR}/${DOMAIN}.ini" \
--non-interactive --agree-tos \
--email "$EMAIL" \
certonly

openssl x509 -text -in "${CFGDIR}/live/${DOMAIN}/fullchain.pem" |\
grep -e 'Not Before' -e 'Not After'

For DeSEC you need secrets/${DOMAIN}.ini to contain:

dns_desec_token = YOURTOKENHERE

Please note that DeSEC lets you restrict what the token can do, but setting the rights on the token has to be done through their API so you need a separate token for the API 😅.

To use the certs from Caddy, point it at the files under the config/live/${DOMAIN}/ dir (which are symlinks that are maintained by Certbot), NOT the ones under archive/.

tls /path/to/certbot/config/live/example.com/fullchain.pem /path/to/certbot/config/live/example.com/privkey.pem

Or, if you want to also add mTLS to the mix:

tls /path/to/certbot/config/live/example.com/fullchain.pem /path/to/certbot/config/live/example.com/privkey.pem {
    client_auth {
        mode verify_if_given # or whatever access mode you want
        trust_pool file /path/to/custom/ca.pem
    }
}

Let me know if you have questions.

original
Sort:hotnewtop