{"id":2121,"date":"2021-02-01T18:36:01","date_gmt":"2021-02-02T01:36:01","guid":{"rendered":"https:\/\/www.itayemi.com\/blog\/?p=2121"},"modified":"2022-07-20T15:39:03","modified_gmt":"2022-07-20T21:39:03","slug":"using-lets-encrypt-ssl-certificates","status":"publish","type":"post","link":"https:\/\/www.itayemi.com\/blog\/2021\/02\/01\/using-lets-encrypt-ssl-certificates\/","title":{"rendered":"Using Let&#8217;s encrypt SSL certificates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Letsencrypt certificates are only valid for 90 days so you have to continually renew them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8211; Install letsencrypt (certbot)<br># sudo yum install -y https:\/\/dl.fedoraproject.org\/pub\/epel\/epel-release-latest-7.noarch.rpm<br># sudo yum install -y https:\/\/dl.fedoraproject.org\/pub\/epel\/epel-release-latest-8.noarch.rpm<br># sudo yum install -y letsencrypt<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">- Generate initial certificate for the domain interactively<br># certbot certonly -d 'itayemi.com,*.itayemi.com' --manual<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">&#8212;&#8212;&#8212;&#8212;- output truncated by me &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Please deploy a DNS TXT record under the name<br>_acme-challenge.itayemi.com with the following value:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">w8zN-xGQjCtT8kEOkA-Wt3INaRLZzWmRBXwDnBoEoHs<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">( &#8211; done in cPanel cosole for domain itayemi.com, then press ENTER to continue the certbot setup )<br>&#8212;&#8212;&#8212;&#8212;- output truncated by me &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create a file containing just this data:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">s8yfXSlTZXiFJNR_pd-jKfxJQ06StoCJFSGxDy5oBCM.vrNHNIC3FVyuv2kJU8JcnmZK_lfarmjV_FDWrtWY1wc<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And make it available on your web server at this URL:<\/p>\n\n\n\n<figure class=\"wp-block-embed\"><div class=\"wp-block-embed__wrapper\">\nhttp:\/\/itayemi.com\/.well-known\/acme-challenge\/s8yfXSlTZXiFJNR_pd-jKfxJQ06StoCJFSGxDy5oBCM\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">( &#8211; done in cPanel cosole for domain itayemi.com, then press ENTER to continue the certbot setup )<br>&#8212;&#8212;&#8212;&#8212;- output truncated by me &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8212;&#8212;&#8212;&#8212;- Summary output at the end of the certbot certification creation command &#8212;&#8212;&#8212;&#8211; <\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Congratulations! Your certificate and chain have been saved at:<br>\/etc\/letsencrypt\/live\/itayemi.com\/fullchain.pem<br>Your key file has been saved at:<br>\/etc\/letsencrypt\/live\/itayemi.com\/privkey.pem<br>Your certificate will expire on 2022-03-07. To obtain a new or<br>tweaked version of this certificate in the future, simply run<br>certbot again. To non-interactively renew <em>all<\/em> of your<br>certificates, run &#8220;certbot renew&#8221;<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">&#8212;&#8212;&#8212;&#8212;&#8212; End of initial certificate creation for itayemi.com &#8212;&#8212;&#8212;&#8211;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><s>&#8212;&#8212;&#8212;&#8212;&#8212; Setting up auto-renewal (doesn&#8217;t work) &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<\/s><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><s># sudo crontab -e<br># sudo crontab -l<br># auto renewal for itayemi.com certificate created initially on 12\/7\/2021<br>45 2 5 3,6,9,12 * \/bin\/certbot renew<\/s><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8212;&#8212;&#8212;&#8212;&#8212;- INSTALLING the letsencrypt certificate in cPanel &#8212;&#8212;&#8212;&#8212;<br>         (repeat every 3 months when the certificate is about to expire. start by generating a new certificate using the &#8220;certbot certonly &#8230;&#8221; command above)<br>       &#8211; Copy out the updated files (generated by the &#8220;certbot renew&#8221; cron job) \/etc\/letsencrypt\/live\/itayemi.com\/cert.pem and \/etc\/letsencrypt\/live\/itayemi.com\/privkey.pem from the local server<br>       &#8211; Login to hihostnow.com.ng (Client Area) -> Select &#8220;Services&#8221; -> &#8220;My Services&#8221; from the menu<br>       &#8211; Click on the &#8220;Status&#8221; button to the right of the target service e.g., itayemi.com<br>       &#8211; Expand the &#8220;Actions&#8221; menu (left-side of page) and click on &#8220;Login to cPanel&#8221;<br>       &#8211; In itayemi.com cPanel, select &#8220;SSL\/TLS&#8221; (under the &#8220;Security&#8221; section)<br>       &#8211; Select &#8220;INSTALL AND MANAGE SSL FOR YOUR SITE (HTTPS) &#8211; Manage SSL sites&#8221;<br>       &#8211; For each listed FQDNs\/certificate row, select the &#8220;Update Certificate&#8221; link under the &#8220;Actions&#8221; column; populate the &#8220;Certificate: (CRT)&#8221; textbox with the content of the file \/etc\/letsencrypt\/live\/itayemi.com\/cert.pem on the Linux system, and populate the &#8220;Private Key (KEY)&#8221; field with the content of the file \/etc\/letsencrypt\/live\/itayemi.com\/privkey.pem, then click the &#8220;Install Certificate&#8221; button.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Letsencrypt certificates are only valid for 90 days so you have to continually renew them. &#8211; Install letsencrypt (certbot)# sudo yum install -y https:\/\/dl.fedoraproject.org\/pub\/epel\/epel-release-latest-7.noarch.rpm# sudo yum install -y https:\/\/dl.fedoraproject.org\/pub\/epel\/epel-release-latest-8.noarch.rpm# sudo yum install -y letsencrypt &#8211; Generate initial certificate for the &hellip; <a href=\"https:\/\/www.itayemi.com\/blog\/2021\/02\/01\/using-lets-encrypt-ssl-certificates\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":336,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1288,1290,1291,1295,1293,1289,1286,1292,1294,1287],"class_list":["post-2121","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-certbot-auto","tag-cpanel","tag-crontab","tag-dns","tag-expiry","tag-itayemi-com","tag-letsencrypt","tag-private-key","tag-renewal","tag-ssl-certificate"],"_links":{"self":[{"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/posts\/2121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/users\/336"}],"replies":[{"embeddable":true,"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/comments?post=2121"}],"version-history":[{"count":17,"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/posts\/2121\/revisions"}],"predecessor-version":[{"id":2250,"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/posts\/2121\/revisions\/2250"}],"wp:attachment":[{"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/media?parent=2121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/categories?post=2121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.itayemi.com\/blog\/wp-json\/wp\/v2\/tags?post=2121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}