| 154 | | 1. `getssl` Konfiguration testen: \\ `getssl twiki.mtronig.de` |
| 155 | | |
| | 155 | 1. `getssl` Konfiguration testen: \\ `getssl twiki.mtronig.de`; \\ ggf. den Test forcieren: \\ `getssl -f twiki.mtronig.de` |
| | 156 | Das Ergebnis soll so aussehen: |
| | 157 | {{{ |
| | 158 | # getssl -f twiki.mtronig.de |
| | 159 | |
| | 160 | Registering account |
| | 161 | Verify each domain |
| | 162 | Verifying twiki.mtronig.de |
| | 163 | twiki.mtronig.de is already validated |
| | 164 | Verification completed, obtaining certificate. |
| | 165 | Requesting Finalize Link |
| | 166 | Requesting Order Link |
| | 167 | Requesting certificate |
| | 168 | Full certificate saved in /root/.getssl/twiki.mtronig.de/fullchain.crt |
| | 169 | Certificate saved in /root/.getssl/twiki.mtronig.de/twiki.mtronig.de.crt |
| | 170 | copying domain certificate to /var/www/twiki.mtronig.de/ssl/server.crt |
| | 171 | copying private key to /var/www/twiki.mtronig.de/ssl/server.key_decrypted |
| | 172 | copying CA certificate to /var/www/twiki.mtronig.de/ssl/ca-bundle.pem |
| | 173 | reloading SSL services |
| | 174 | * Gracefully restarting apache2 ... [ ok ] |
| | 175 | twiki.mtronig.de - certificate installed OK on server |
| | 176 | certificate obtained for twiki.mtronig.de |
| | 177 | # _ |
| | 178 | }}} |
| | 179 | 1. "staging"-Konfiguration auf volle Konfiguration umstellen, indem die Zeile `CA="https://acme-staging-v02.api..."` deaktiviert wird (darf schon inaktiv sein, weil die globale Konfiguration für getssl diese CA vorgibt) und stattdessen die Zeile `CA="https://acme-v02.api.letsencrypt.org"` aktiviert wird. |
| | 180 | 1. Produktiv-Zertifikat holen: \\ `getssl twiki.mtronig.de` \\ Das Ergebnis soll etwa so aussehen: |
| | 181 | {{{ |
| | 182 | # getssl twiki.mtronig.de |
| | 183 | Registering account |
| | 184 | Verify each domain |
| | 185 | Verifying twiki.mtronig.de |
| | 186 | copying challenge token to /var/www/letsencrypt/Yfh65tFtentC8QnrHM3eSH3WFfOmmcVTNlJk3XGYaRk |
| | 187 | sending request to ACME server saying we're ready for challenge |
| | 188 | checking if challenge is complete |
| | 189 | Pending |
| | 190 | checking if challenge is complete |
| | 191 | Verified twiki.mtronig.de |
| | 192 | Verification completed, obtaining certificate. |
| | 193 | Requesting Finalize Link |
| | 194 | Requesting Order Link |
| | 195 | Requesting certificate |
| | 196 | Full certificate saved in /root/.getssl/twiki.mtronig.de/fullchain.crt |
| | 197 | Certificate saved in /root/.getssl/twiki.mtronig.de/twiki.mtronig.de.crt |
| | 198 | copying domain certificate to /var/www/twiki.mtronig.de/ssl/server.crt |
| | 199 | copying private key to /var/www/twiki.mtronig.de/ssl/server.key_decrypted |
| | 200 | copying CA certificate to /var/www/twiki.mtronig.de/ssl/ca-bundle.pem |
| | 201 | reloading SSL services |
| | 202 | * Gracefully restarting apache2 ... [ ok ] |
| | 203 | twiki.mtronig.de - certificate installed OK on server |
| | 204 | certificate obtained for twiki.mtronig.de |
| | 205 | # _ |
| | 206 | }}} |
| | 207 | 1. //fertig - freu! // |
| | 208 | |