Resource icon

Scripted installation of Nextcloud 28 in iocage jail 2018-03-23

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
Yesterday some certificates got revoked by lets encrypt. Have you checked your certificates against non-complaince with ALPN TLS versions by letsencrypt? (https://tls-alpn-check.letsencrypt.org/)
You can do that with: curl -X POST -d 'fqdn=YOURFQDN' https://tls-alpn-check.letsencrypt.org/checkhost

i check the link that u gave, it said that I have to renew my SSL certificate ? please tell me what command that I have to run on my freenas to renew or reissued letsenscrypt SSL from my freenas-iocage-nextcloud .

Or any other things that i've should do ?

Please advice how to solve this problem.

Thanks n regards,
 
Last edited:

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
i check the link that u gave, it said that I have to renew my SSL certificate ? please tell me what command that I have to run on my freenas to renew or reissued letsenscrypt SSL from my freenas-iocage-nextcloud .

Or any other things that i've should do ?

Please advice how to solve this problem.

Thanks n regards,
My nexcloud page certificated still revoked, what i have to do to fix it? Please help
 
Joined
Jan 27, 2020
Messages
577
My nexcloud page certificated still revoked, what i have to do to fix it? Please help
Inside your nextcloud jail, certbot renew
This script does not make use of certbot.
 
Last edited:

gt2416

Patron
Joined
Feb 4, 2018
Messages
262

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
I

Inside your nextcloud jail, certbot renew
certbot renew , not working on my freenas nextcloud, it shown like below :

certbot.JPG


when i try to open from mozilla , it shown like this :

revoked.JPG


please more advice

Regards,
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
Inside your nextcloud jail, certbot renew
No version of my script has ever used certbot. Old versions (when I was using Apache as the webserver) used acme.sh; Caddy now handles the cert automatically. And it will see that it's been revoked and renew it automatically.
 

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
No version of my script has ever used certbot. Old versions (when I was using Apache as the webserver) used acme.sh; Caddy now handles the cert automatically. And it will see that it's been revoked and renew it automatically.
hi mr.danb35, please let me know how to fix the problem,
when i checked with this link : https://tls-alpn-check.letsencrypt.org/ .
the result is :

[cloud.mynextcloud.com]: The certificate retrieved from your web server has serial 033c5e7ad28270exxx1ec89434bc70bbe351 and was found in our affected data set. Please renew your certificate as soon as possible.
Help is available at https://community.letsencrypt.org/t/questions-about-renewing-before-tls-alpn-01-revocations/170449

and when i checked the status of ssl of my nextcloud , it seem the renewal will be at March 11, 2022

ssl.JPG


did i have to run this command : iocage exec nextcloud /root/remove-staging.sh ?
please help how to solve this problem.

Thanks & Regards,
 
Last edited:
Joined
Jan 27, 2020
Messages
577
No version of my script has ever used certbot. Old versions (when I was using Apache as the webserver) used acme.sh; Caddy now handles the cert automatically. And it will see that it's been revoked and renew it automatically.
uh yes, you're right. I assumed a non-ssl setup with your script behind a reverse-proxy that handles certs with certbot, like in my setup. @InGenetic, sorry that was bad advice.
 

rio236

Dabbler
Joined
Aug 19, 2016
Messages
38
Hello.
I got this error:/freenas-iocage-nextcloud/nextcloud-config: DNS_TOKEN:...: not found
My Config File:
JAIL_IP="192.168.1.50"
DEFAULT_GW_IP="192.168.1.1"
POOL_PATH="/mnt/tank2"
TIME_ZONE="America/New_York"
HOST_NAME="nextcloud.example.com"
DNS_CERT=1
DNS_PLUGIN=cloudflare
DNS_TOKEN:xxxxxx
CERT_EMAIL="admin@example.com"

I have setup an API Token at Cloudflare for domain example.com
Zone Zone Read
Zone DNS Edit

Please help.
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
please help how to solve this problem.
As I've said at least twice in the last few days, Caddy will renew the affected cert automatically. It will do this when it tries to renew OCSP and gets the response that the cert is revoked, which would ordinarily happen no more than four days after the cert was revoked.
it seem the renewal will be at March 11, 2022
No, that isn't what that says; it says the cert expires on 11 March. Certs are ordinarily renewed 30 days before expiration, so that would happen starting on 9 February--but as I said above, it should actually happen sooner.

What version of Caddy are you running? From inside the jail, run caddy version
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
As I've said at least twice in the last few days, Caddy will renew the affected cert automatically. It will do this when it tries to renew OCSP and gets the response that the cert is revoked, which would ordinarily happen no more than four days after the cert was revoked.

No, that isn't what that says; it says the cert expires on 11 March. Certs are ordinarily renewed 30 days before expiration, so that would happen starting on 9 February--but as I said above, it should actually happen sooner.

What version of Caddy are you running? From inside the jail, run caddy version
i try to run caddy version , but the result is like below :
shell.JPG


please advice

Thanks n regards,
 

rio236

Dabbler
Joined
Aug 19, 2016
Messages
38
Hello.
I'm able to browse to nextcloud.example.com
What needs to be done to browse to example.com/nextcloud?
DNS_CERT is through Cloudflare.

Thank you
 

danb35

Hall of Famer
Joined
Aug 16, 2011
Messages
15,504
What needs to be done to browse to example.com/nextcloud?
Really isn't a supported configuration with this script, but some edits to the Caddyfile should do the job.
 

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
What about pkg info caddy?
hi mr.danb35
here the result of "pkg info caddy"

1643855616336.png


by the way , this's my caddy version :

root@nextcloud:~ # caddy --version
v1.0.4

root@nextcloud:~ #

and i've got this email from letsencrypt last week :

Hello,

Please immediately renew your TLS certificate(s) that were issued from Let's Encrypt using the TLS-ALPN-01 validation method and the following ACME registration (account) ID(s):


836515xx

We've determined that an error made it possible for TLS-ALPN-01 challenges, completed before today, to not comply with certificate issuance requirements. We have remediated this problem and will revoke all unexpired certificates that used this validation method at 16:00 UTC on 28 January 2022. Please renew your certificates now to ensure an uninterrupted experience for your site visitors.

We apologize for any inconvenience this may cause. If you need support in the renewal process, please comment on our forum post. Our staff and community members are available to help:


Thank you,

The Let's Encrypt Team


mr.danb35, i want to ask about how to use ssl commercial for my nextcloud ? do you have any refference which ssl with a cheap price but ok for my nextcloud ?

i've just thinking how if i use the commercial ssl , is it will better than letsencrypt or same ?
can i use this SSL for my nextcloud ?

sectigo.JPG

please advice me ..if i can use this SSL, please let me know how to implementation this SSL on my nextcloud.

nb : so there're 2 questions from me :

1. urgently needed is how to renew my letsencrypt , my caddy version is v.1.0.4
2, For the future, maybe, if i want to use commercial ssl , how to step by step to use a commercial ssl

Thanks & Regards,
 
Last edited:

InGenetic

Contributor
Joined
Dec 18, 2013
Messages
183
In the jail, is there anything in /etc/ssl/caddy?
hi mr.danb35,
i can't find caddy folder , where exactly that folder located ?
i just can find below :

root@nextcloud:~ # cd /etc/ssl/
cert.pem@ openssl.cnf
root@nextcloud:~ # cd /etc/ssl/

caddy1.JPG


caddy2.JPG


i can find that folder on windows explorer, but can not find on linux putty
is that the right folder ?

regards,
 
Last edited:
Top