Milí majitelé routerů Turris,
toto fórum bylo 9. 12. 2016 zmrazeno a nahrazeno naším novým Turris fórem. Ještě chvíli bude dostupné k prohlížení, ale již zde není možné přispívat. Více informací naleznete v oznámení o uzavření fóra.
Dear Turris routers users,
this forum has been frozen on Dec 9th, 2016 and replaced by our new Turris forum. It will be read-only accessible for some time after. For more information, read the announcement about closing the forum.
ApacheServer/1_root_bundle.crt ApacheServer/2_mojedomena.cz.crt NginxServer/1_mojedomena.cz_bundle.crt OtherServer/1_Intermediate.crt OtherServer/2_mojedomena.cz.crt OtherServer/root.crt
(network.c.571) SSL: couldn't read private key from '/etc/lighttpd-self-signed.pem'
#!/bin/bash CERTDIR=/etc/letsencrypt/mojedomena.cz OUTDIR=/etc/letsencrypt/mojedomena.cz DOMAIN=mojedomena.cz mkdir /tmp/acme-challenge/ &>/dev/null mkdir /www/.well-known/ &>/dev/null ln -s /tmp/acme-challenge/ /www/.well-known/acme-challenge 2>/dev/null python /etc/letsencrypt/acme_tiny.py --account-key ${CERTDIR}/account.key --csr ${CERTDIR}/$DOMAIN.csr --acme-dir /www/.well-known/acme-challenge/ 1> ${CERTDIR}/signed.crt || exit wget --no-check-certificate -O - https://letsencrypt.org/certs/lets-encrypt-x4-cross-signed.pem > ${CERTDIR}/intermediate.pem wget --no-check-certificate -O - https://letsencrypt.org/certs/lets-encrypt-x3-cross-signed.pem >> ${CERTDIR}/intermediate.pem wget --no-check-certificate -O - https://letsencrypt.org/certs/lets-encrypt-x2-cross-signed.pem >> ${CERTDIR}/intermediate.pem wget --no-check-certificate -O - https://letsencrypt.org/certs/lets-encrypt-x1-cross-signed.pem >> ${CERTDIR}/intermediate.pem cat ${CERTDIR}/$DOMAIN.key ${CERTDIR}/signed.crt > ${OUTDIR}/$DOMAIN.pem cat ${CERTDIR}/signed.crt ${CERTDIR}/intermediate.pem > ${OUTDIR}/fullchain1.pem #certifikat a privatni klic: /etc/letsencrypt/mojedomena.cz/mojedomena.cz.pem #ca chain pem /etc/letsencrypt/mojedomena.cz/fullchain1.pem /etc/init.d/lighttpd restart exit 0
# This settings enables https with user-generated self-signed certificate from # package https-cert $SERVER["socket"] == ":443" { ssl.engine = "enable" ssl.pemfile = "/etc/letsencrypt/mojedomena.cz/mojedomena.cz.pem" ssl.ca-file = "/etc/letsencrypt/mojedomena.cz/fullchain1.pem" ssl.dh-file = "/etc/letsencrypt/dh4096.pem" ssl.cipher-list = "EECDH+AESGCM:EDH+AESGCM:ECDHE-RSA-AES128-GCM-SHA256:AES256+EECDH:AES256+EDH:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4" ssl.honor-cipher-order = "enable" ssl.ec-curve = "secp384r1" } $SERVER["socket"] == "[::]:443" { ssl.engine = "enable" ssl.pemfile = "/etc/letsencrypt/mojedomena.cz/mojedomena.cz.pem" ssl.ca-file = "/etc/letsencrypt/mojedomena.cz/fullchain1.pem" ssl.dh-file = "/etc/letsencrypt/dh4096.pem" ssl.cipher-list = "EECDH+AESGCM:EDH+AESGCM:ECDHE-RSA-AES128-GCM-SHA256:AES256+EECDH:AES256+EDH:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES256-GCM-SHA384:AES128-GCM-SHA256:AES256-SHA256:AES128-SHA256:AES256-SHA:AES128-SHA:DES-CBC3-SHA:HIGH:!aNULL:!eNULL:!EXPORT:!DES:!MD5:!PSK:!RC4" ssl.honor-cipher-order = "enable" ssl.ec-curve = "secp384r1" }
server.modules += ( "mod_redirect" ) $SERVER["socket"] == ":80" { $HTTP["host"] =~ "(.*)" { $HTTP["host"] !~ "/(\.well-known)/" { url.redirect = ( "^/(.*)" => "https://%1/$1" ) } } }
server.modules += ( "mod_setenv" ) $HTTP["scheme"] == "https" { setenv.add-response-header = ( "Strict-Transport-Security" => "max-age=63072000; includeSubdomains; " ) }
opkg install lighttpd-mod-setenv lighttpd-mod-redirect
Powered by mwForum 2.29.3 © 1999-2013 Markus Wichitill