Renewing Vidjil's SSL Certificate: Difference between revisions

From CPB Wiki
Jump to navigation Jump to search
(Instructions. Experimenting with makdown)
(Wiki markup)
 
Line 20: Line 20:
<code>sudo cp /etc/letsencrypt/live/vidjil.boldrini.org.br/privkey.pem  /home/vidjil/code/2020-vidjil/docker/vidjil-client/ssl/privkey.pem</code>
<code>sudo cp /etc/letsencrypt/live/vidjil.boldrini.org.br/privkey.pem  /home/vidjil/code/2020-vidjil/docker/vidjil-client/ssl/privkey.pem</code>
</blockquote>
</blockquote>
* make sure file `privkey.pem` has permissions 0600 and owner `root`
* make sure file <code>privkey.pem</code> has permissions 0600 and owner <code>root</code>.
* do <code>docker-compose -f docker-compose-wrapper.yml up -d</code> to restart Vidjil.
* do <code>docker-compose -f docker-compose-wrapper.yml up -d</code> to restart Vidjil.
* visit <code>vidjil.boldrini.org.br</code> to confirm the new certificate in on.
* visit <code>vidjil.boldrini.org.br</code> to confirm the new certificate in on.
* mark on your calendar a date for the next renewal.
* mark on your calendar a date for the next renewal.

Latest revision as of 11:42, 11 January 2024

Our Vidjil server certificates are provided by Let's Encrypt.

To renew the certificates:

  • this operation must be done between 1 and 8 days before expiration.
  • certified machine name: vidjil.boldrini.org.br
  • go to the <docker-dir> and impersonate a super-user: sudo su joao.m (<docker-dir> is currently /home/vidjil/code/2020-vidjil/docker).
  • do docker-compose -f docker-compose-wrapper.yml down to prevent Vidjil from disturbing standalone verification.
  • renew the certificate:

sudo certbot certonly --standalone -d vidjil.boldrini.org.br

  • issue the extra commands below to make sure the renewal is seen by Vidjil:

sudo cp /etc/letsencrypt/live/vidjil.boldrini.org.br/fullchain.pem /home/vidjil/code/2020-vidjil/docker/vidjil-client/ssl/fullchain.pem

sudo cp /etc/letsencrypt/live/vidjil.boldrini.org.br/privkey.pem /home/vidjil/code/2020-vidjil/docker/vidjil-client/ssl/privkey.pem

  • make sure file privkey.pem has permissions 0600 and owner root.
  • do docker-compose -f docker-compose-wrapper.yml up -d to restart Vidjil.
  • visit vidjil.boldrini.org.br to confirm the new certificate in on.
  • mark on your calendar a date for the next renewal.