Peter Baldwin wrote:
Nick Howitt wrote:
Hi Peter,
When flex-443.conf picks up the certificates, is there any reason for using the fullchain.pem file as the chain file and not chain.pem? The fullchain.pem is a combined cert.pem and chain.pem and you are already picking up cert.pem as the SSLCertificateFile.
Right again Nick! I pushed that change through git last week - https://github.com/eglooca/app-lets-encrypt/commit/cd882a9e7b2d4369f3ad69aff969c16f3a944b51#diff-8e7476918fbf8094bf778783de7dbf30
Please notice that the "correct" certificate file is "fullchain.pem" not "cert.pem". Please have a look at the README file generated by certbot:
Also, in the crontab script above, the "fullchain.pem" is copied to /etc/clearos/certificate_manager.d/domain.crt