Comment on Looking to move from Caddy
lemmyvore@feddit.nl 1 week ago
I’m also using Certbot with DeSEC. I simply run it daily with anacron. If it doesn’t need to renew the certs yet it will say so and stop. That’s basically it.
I think it’s a very good idea for your LE renewal to be independent of whatever reverse proxy or web server you’re using.
Please keep in mind that Certbot is a Python app so you can manage it with venv. Here’s how I install it in a dedicated dir (let’s say /srv/letsencrypt because using /etc is not appropriate and it bugs me 😆):
#!/bin/bash set -e apt install python3-venv /usr/bin/python3 -m venv .venv source .venv/bin/activate python3 -m pip install --upgrade pip python3 -m pip install --upgrade certbot certbot-dns-desec
And to update it:
#!/bin/bash set -e source .venv/bin/activate python3 -m pip install --upgrade pip python3 -m pip install --upgrade certbot certbot-dns-desec
As for renewing certs (the script is longer, I’m making sure to create dirs and so on but this is the gist of it):
source .venv/bin/activate ./.venv/bin/certbot \ --config-dir "$CFGDIR" \ --logs-dir "$LOGDIR" \ --work-dir "$TMPDIR" \ --domain "*.${DOMAIN}" \ --domain "*.${DOMAIN}" \ --authenticator dns-desec \ --dns-desec-credentials "${SECDIR}/${DOMAIN}.ini" \ --non-interactive --agree-tos \ --email "$EMAIL" \ certonly openssl x509 -text -in "${CFGDIR}/live/${DOMAIN}/fullchain.pem" |\ grep -e 'Not Before' -e 'Not After'
For DeSEC you need secrets/${DOMAIN}.ini to contain:
dns_desec_token = YOURTOKENHERE
Please note that DeSEC lets you restrict what the token can do, but setting the rights on the token has to be done through their API so you need a separate token for the API 😅.
To use the certs from Caddy, point it at the files under the config/live/${DOMAIN}/ dir (which are symlinks that are maintained by Certbot), NOT the ones under archive/.
tls /path/to/certbot/config/live/example.com/fullchain.pem /path/to/certbot/config/live/example.com/privkey.pem
Or, if you want to also add mTLS to the mix:
tls /path/to/certbot/config/live/example.com/fullchain.pem /path/to/certbot/config/live/example.com/privkey.pem { client_auth { mode verify_if_given # or whatever access mode you want trust_pool file /path/to/custom/ca.pem } }
Let me know if you have questions.
confusedpuppy@lemmy.dbzer0.com 1 week ago
This is great, thank you for taking the time for this write up :) The provided scripts are a huge help to me
So far my only question I have is about the directories you use. I was wondering if you could provide the directories you use or even just an example so I could better understand the file tree. I’m very particular with my files and have a whole system dedicated to maintaining neat and organized files
I agree about not using /etc for server related stuff. I keep all my server/container related stuff in /srv so it’s easier for me to manage
lemmyvore@feddit.nl 1 week ago
The dirs are subdirs of
/srv/letsencrypt. I like to take advantage of explicit dir assignment if the software allows it, so I don’t have any surprises if the defaults change.confusedpuppy@lemmy.dbzer0.com 6 days ago
Awesome, thanks so much, this is a big head start for me
I have a good idea how I want to organize things now