notes

Unnamed repository; edit this file 'description' to name the repository.
Log | Files | Refs

certbot.txt (2053B)


      1 ===============================================================================
      2 Certbot / SSL Certificates
      3 ===============================================================================
      4 
      5 1. Check what certificate your origin is actually presenting
      6 
      7 # From outside the container, test the origin directly (bypass Cloudflare):
      8 
      9 openssl s_client -connect example.com:443 -servername server.com </dev/null 2>/dev/null | openssl x509 -noout -dates -subject
     10 
     11 # Or if your origin IP is different from what DNS resolves to:
     12 
     13 openssl s_client -connect <your-origin-ip>:443 -servername server.com </dev/null 2>/dev/null | openssl x509 -noout -dates -subject
     14 
     15 
     16 2. Verify your web server config points to the right paths
     17 
     18 # For nginx
     19 grep -r "ssl_certificate" /etc/nginx/conf.d/ /etc/nginx/sites-enabled/
     20 
     21 # For Apache
     22 grep -r "SSLCertificate" /etc/apache2/sites-enabled/
     23 
     24 
     25 3. Check if the certificate files exist and are readable
     26 
     27 # Inside the certbot container
     28 ls -la /etc/letsencrypt/live/example.com/
     29 
     30 # Permissions should look roughly like:
     31 # -rw-r--r-- on the .pem files
     32 
     33 
     34 4. Reload your web server
     35 
     36 # Nginx
     37 docker exec <your-nginx-container> nginx -s reload
     38 
     39 # Apache
     40 docker exec <your-apache-container> apachectl reload
     41 
     42 
     43 5. The most likely culprit: certbot hasn't actually renewed
     44 
     45 Try a forced renewal to test the full cycle:
     46 
     47 docker exec -it certbot-manager certbot renew --force-renewal
     48 # Then reload your web server
     49 
     50 ===============================================================================
     51 Auto-renewal:
     52 
     53 In order to have auto-renewal running in the background, you certbot-manager
     54 docker container has to be running in daemon mode, then it will continuously
     55 check for certfificate validity every 12 hours:
     56 
     57 docker compose -f compose-renew.yml up --build -d
     58 
     59 
     60 and then dry run renewal to check which domain is due for renewal:
     61 
     62 docker exec -it certbot-manager certbot renew --dry-run
     63 
     64 
     65 Make sure the manager is actually running persistently:
     66 
     67 docker compose -f compose-renew.yml up -d
     68 docker compose -f compose-renew.yml logs -f certbot-manager