Skip Home Changes Edit Add Diff Zip Upload

Certificates for HTTPS

We use certbot to generate the certificates. To regenerate them if something broke:

sudo certbot --expand -d grenzland.club -d wiki.grenzland.club

Running certbot requires a site on port 80.

Show the log:

sudo journalctl -u certbot.service

The error in question:

Failed to renew certificate grenzland.club with error: Unable to find a virtual host listening on port 80 which is currently needed for Certbot to prove to the CA that you control your domain. Please add a virtual host for port 80.

This site is provided by /etc/apache2/sites-enabled/000-default.conf. All it does is redirect http://grenzland.club to https://grenzland.club.

If scripts need to run after certbot, put them in the appropriate subdirectory of /etc/letsencrypt/renewal-hooks/. Typically that is /etc/letsencrypt/renewal-hooks/deploy/prosody.sh since it uses the same certificates as the web server.

Also /etc/letsencrypt/renewal-hooks/deploy/ngircd.sh because ngircd needs to reload its config and certs (which it does when it receives SIGHUP).

== ngircd

If the IRC server doesn’t know about the new certs, reload its config:

sudo kill -HUP `sudo cat /var/run/ngircd/ngircd.pid`