My Community Dashboard

  • Peter Baldwin wrote:

    Nick Howitt wrote:

    Hi Peter,
    When flex-443.conf picks up the certificates, is there any reason for using the fullchain.pem file as the chain file and not chain.pem? The fullchain.pem is a combined cert.pem and chain.pem and you are already picking up cert.pem as the SSLCertificateFile.


    Right again Nick! I pushed that change through git last week - https://github.com/eglooca/app-lets-encrypt/commit/cd882a9e7b2d4369f3ad69aff969c16f3a944b51#diff-8e7476918fbf8094bf778783de7dbf30

    Please notice that the "correct" certificate file is "fullchain.pem" not "cert.pem". Please have a look at the README file generated by certbot:

    Also, in the crontab script above, the "fullchain.pem" is copied to /etc/clearos/certificate_manager.d/domain.crt