Welcome to Centmin Mod Community
Register Now

Letsencrypt Official acmetool.sh testing thread for Centmin Mod 123.09beta01

Discussion in 'Domains, DNS, Email & SSL Certificates' started by eva2000, Jul 26, 2016.

  1. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Can't find what can cause that redirect as there is no related option and i don't have any page rule at all there....


    Ok i will let them know ....
     
  2. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    maybe a cloudflare page rule is needed to turn off their SSL if https version of site is accessed i.e.

    upload_2016-9-23_23-44-12.png

    confirm with cloudflare though
     
  3. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
  4. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Found a comment that it seems that i will be able to use Let's encrypt from server to Cloudflare and from Cloudflare to user i must use Cloudflare's ssl?

    Don't know if it is true....
     
  5. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    yes you want cloudflare full ssl and have letsencrypt or self-signed ssl on nginx side so cloudflare and server communication is encrypted too
     
  6. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    So it is normal to see at my browser cloudflare's ssl and not Let's encrypt?

    Confused :(

    Check now:

    centmintest.com
     
  7. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    yes if you enable cloudflare ssl
     
  8. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    But if i don't enable it it doesn't work :(
     
  9. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
  10. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    yes but it was not ok but maybe i have some cache issues related?

    I will check again from another device and another ISP just to be sure....
     
  11. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Cloudflare respond:

    But maybe they run the test when i was enable for a while the full ssl from Cloudflare to test it....

    That's why i think they can see that:

     
    Last edited: Sep 24, 2016
  12. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    yeah they tested againt your cloudflare ssl enabled config
     
  13. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Ok i let them know about it....

    Let's see if i will be able to find a solution for this...
     
  14. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Searching around i found some info that i am not so sure that are correct on Cenminmod implementation of Let's encrypt....


    1)I can't renew Lets encrypt certificate without disabling cloudflare?

    2)If i use Let's encrypt it will protect from server to Cloudflare and from there to the public i MUST use Cloudflare's SSL and that's the reason that i see on my browser the Cloudflare Certificate.(i think this is correct or not?)

    3)The only downside for Cloudflare and Let's encrypt is that you can only generate single-domain certificates, no wildcards, and you can't get EV certificates that show your company name in the address bar.


    Also how can i verify that the Let's encrypt is working on my server from ssh ?
     
  15. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    only true for letsencrypt verification via standalone mode in certbot official client, does not apply to certbot official client or acmetool.sh's use of acme.sh in webroot authentication mode

    yes that is normal if you enable cloudflare ssl, cloudflare sits in front of your server

    yes both cloudflare free/pro and letsencrypt can't do EV SSL. I think cloudflare enterprise plans can

    you can use local host file edit to bypass ISP DNS and map domain to the origin real server ip and/or use curl with --resolve option
    Code (Text):
    curl -Isv --resolve 'centmintest.com:443:127.0.0.1' https://centmintest.com

    where 127.0.0.1 is your origin real server ip
     
  16. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Ok i did some tests and seems to get an idea how it works :)

    I have only one question :

    Why it doesn't redirect from www to none?

    Code:
    https://www.centmintest.com
    I am using this :

    Code:
     server {
     
       server_name centmintest.com www.centmintest.com;
       return 302 https://$server_name$request_uri;
       include /usr/local/nginx/conf/staticfiles.conf;
     }
    I know that i may be able to do that with a page rule on Cloudflare but why it doesn't work from Nginx config file?
     
  17. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    see Nginx Vhost & NSD DNS Setup - CentminMod.com LEMP Nginx web stack for CentOS

     
  18. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Working great now but i think that code should be there as default commented but exist....
     
  19. pamamolf

    pamamolf Well-Known Member

    4,126
    429
    83
    May 31, 2014
    Ratings:
    +841
    Local Time:
    8:23 PM
    Nginx-1.29.x
    MariaDB 10.6.x
    Also i have another recommendation :)

    Keep existing http config file renamed like domain.com.backup in place and create a new one for ssl so if something goes wrong or if a user want to revert to http to be very easy and fast.
     
  20. eva2000

    eva2000 Administrator Staff Member

    59,272
    12,508
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +19,140
    Local Time:
    3:23 AM
    Nginx 1.31.x
    MariaDB 10.x/11.4+/12.3+
    non-https one is moved to backup directory defined by ACMEBACKUPDIR='/usr/local/nginx/conf/acmevhostbackup' for https default runs as folks can run it multiple times so multiple backups
    depends on what the end user wants
     
    Last edited: Sep 25, 2016