<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title><![CDATA[iRedMail — easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
		<link>https://forum.iredmail.org/topic12500-easy-lets-encrypt-guide-for-ubuntu-1604-iredmail-server-with-nginx.html</link>
		<atom:link href="https://forum.iredmail.org/feed-rss-topic12500.xml" rel="self" type="application/rss+xml" />
		<description><![CDATA[The most recent posts in easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx.]]></description>
		<lastBuildDate>Thu, 28 Sep 2017 16:07:07 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58933.html#p58933</link>
			<description><![CDATA[<p>cert.pem -&gt; server.crt<br />privkey.pem -&gt; server.key</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Thu, 28 Sep 2017 16:07:07 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58933.html#p58933</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58840.html#p58840</link>
			<description><![CDATA[<p>Any thoughts on this?</p><div class="quotebox"><cite>AndyInNYC wrote:</cite><blockquote><p>the tutorial doesn&#039;t mention these files.&nbsp; Again, letsencrypt only generated the following:<br />cert.pem<br />chain.pem<br />fullchain.pem<br />privkey.pem</p><p>These files aren&#039;t mentioned.&nbsp; I need server.cert, server.key, etc.</p><p>Can you repoint me to where any document mentions these 4 files and how to use them to set up SSL?</p><p>Thanks.</p><br /><p>Andrew</p></blockquote></div>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Fri, 22 Sep 2017 11:41:29 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58840.html#p58840</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58784.html#p58784</link>
			<description><![CDATA[<p>the tutorial doesn&#039;t mention these files.&nbsp; Again, letsencrypt only generated the following:<br />cert.pem<br />chain.pem<br />fullchain.pem<br />privkey.pem</p><p>These files aren&#039;t mentioned.&nbsp; I need server.cert, server.key, etc.</p><p>Can you repoint me to where any document mentions these 4 files and how to use them to set up SSL?</p><p>Thanks.</p><br /><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Tue, 19 Sep 2017 15:41:15 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58784.html#p58784</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58748.html#p58748</link>
			<description><![CDATA[<div class="quotebox"><cite>AndyInNYC wrote:</cite><blockquote><p>These don&#039;t seem to be sufficient in name and quantity to follow the directions in the tutorial (am I supposed to run the openssl command also?).</p></blockquote></div><p>Those 4 files are enough. Follow our tutorial to use them:<br /><a href="http://www.iredmail.org/docs/use.a.bought.ssl.certificate.html">http://www.iredmail.org/docs/use.a.boug … icate.html</a></p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 19 Sep 2017 02:51:13 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58748.html#p58748</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58740.html#p58740</link>
			<description><![CDATA[<p>After using --dry-run, I ran the command<br />letsencrypt certonly --standalone -d lifeassetsllc.com -d mail.lifeassetsllc.com<br />the command ran successfully, but it only generated<br />cert.pem&nbsp; chain.pem&nbsp; fullchain.pem&nbsp; privkey.pem</p><p>These don&#039;t seem to be sufficient in name and quantity to follow the directions in the tutorial (am I supposed to run the openssl command also?).</p><p>Help?</p><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Mon, 18 Sep 2017 19:08:41 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58740.html#p58740</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58733.html#p58733</link>
			<description><![CDATA[<p>Again, there isn&#039;t a &#039;website&#039; set up for any of the domains.&nbsp; I&#039;m using the default Apache setup to access SOGo and Roundcube via <a href="https://mail.lifeassetsllc.com/SOGo.">https://mail.lifeassetsllc.com/SOGo.</a>&nbsp; That&#039;s likely the only way I&#039;m accessing the system for now and for a long time (I&#039;ll worry about putting other websites there with certificates another time).</p><p>How, using that base assumption, do I get the Let&#039;s Encrypt certificate to work and install properly with iRedMail given the errors I&#039;m seeing?</p><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Mon, 18 Sep 2017 12:24:27 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58733.html#p58733</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58723.html#p58723</link>
			<description><![CDATA[<p>You specified 4 domain names, do they all use &quot;/var/www/lifeassetsllc&quot; as web document root?<br />If not, you must specified web document root (-w) for each domain.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Mon, 18 Sep 2017 07:34:12 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58723.html#p58723</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58716.html#p58716</link>
			<description><![CDATA[<div class="quotebox"><cite>ZhangHuangbin wrote:</cite><blockquote><p>*) I suggest trying with &#039;--dry-run&#039; option, so that you won&#039;t reach the max try limit set by letsencrypt server.<br />*) You specified 4 domain names, do they all use &quot;/var/www/lifeassetsllc&quot; as web document root? If not, you must specified web document root for each domain.</p></blockquote></div><p>The machine presently only serves mail and uses the SOGo and RoundCube web interfaces - it&#039;s completely stock.&nbsp; I don&#039;t care if the let&#039;s encrypt certificate only works for the email (but for all of the hosted domains if that matters).</p><p>I&#039;m missing something - should I just use - d lifeassetsllc.com and -d mail.lifeassetsllc.com?</p><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Sun, 17 Sep 2017 20:03:11 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58716.html#p58716</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58703.html#p58703</link>
			<description><![CDATA[<p>*) I suggest trying with &#039;--dry-run&#039; option, so that you won&#039;t reach the max try limit set by letsencrypt server.<br />*) You specified 4 domain names, do they all use &quot;/var/www/lifeassetsllc&quot; as web document root? If not, you must specified web document root for each domain.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Sun, 17 Sep 2017 13:48:30 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58703.html#p58703</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58691.html#p58691</link>
			<description><![CDATA[<p>Ah, so close but so far</p><p>So I used the command:<br /></p><div class="codebox"><pre><code>sudo certbot certonly --webroot -w /var/www/lifeassetsllc -d lifeassetsllc.com -d www.lifeassetsllc.com -d www.lifeasetsllc.com -d mail.lifeassetsllc.com</code></pre></div><p>and got back a string of errors:</p><div class="codebox"><pre><code>root@mail:/# sudo certbot certonly --webroot -w /var/www/lifeassetsllc -d lifeassetsllc.com -d [url=http://www.lifeassetsllc.com]www.lifeassetsllc.com[/url] -d [url=http://www.lifeasetsllc.com]www.lifeasetsllc.com[/url] -d mail.lifeassetsllc.com
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for lifeassetsllc.com
http-01 challenge for [url=http://www.lifeassetsllc.com]www.lifeassetsllc.com[/url]
http-01 challenge for [url=http://www.lifeasetsllc.com]www.lifeasetsllc.com[/url]
http-01 challenge for mail.lifeassetsllc.com
Using the webroot path /var/www/lifeassetsllc for all unmatched domains.
Waiting for verification...
Cleaning up challenges
Failed authorization procedure. [url=http://www.lifeassetsllc.com]www.lifeassetsllc.com[/url] (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [url]http://www.lifeassetsllc.com/.well-known/acme-challenge/zy_hc1QOh33Kiiz6gtI1ERuFxkufly0mBmxidqA5Nqg:[/url] &quot;&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML 2.0//EN&quot;&gt;
&lt;html&gt;&lt;head&gt;
&lt;title&gt;404 Not Found&lt;/title&gt;
&lt;/head&gt;&lt;body&gt;
&lt;h1&gt;Not Found&lt;/h1&gt;
&lt;p&quot;, lifeassetsllc.com (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [url]http://lifeassetsllc.com/.well-known/acme-challenge/rPmwYEuYgeljSKOCyEgIB5ebK_W1K2qA8-3iFVepj00:[/url] &quot;&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML 2.0//EN&quot;&gt;
&lt;html&gt;&lt;head&gt;
&lt;title&gt;404 Not Found&lt;/title&gt;
&lt;/head&gt;&lt;body&gt;
&lt;h1&gt;Not Found&lt;/h1&gt;
&lt;p&quot;, [url=http://www.lifeasetsllc.com]www.lifeasetsllc.com[/url] (http-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: DNS problem: NXDOMAIN looking up A for [url=http://www.lifeasetsllc.com]www.lifeasetsllc.com[/url], mail.lifeassetsllc.com (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from [url]http://mail.lifeassetsllc.com/.well-known/acme-challenge/xPvkYSQpejAvtZf9d8k3CoORxFy7MChPjpbpzLZCw5o:[/url] &quot;&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML 2.0//EN&quot;&gt;
&lt;html&gt;&lt;head&gt;
&lt;title&gt;404 Not Found&lt;/title&gt;
&lt;/head&gt;&lt;body&gt;
&lt;h1&gt;Not Found&lt;/h1&gt;
&lt;p&quot;

IMPORTANT NOTES:
 - The following errors were reported by the server:

   Domain: [url=http://www.lifeasetsllc.com]www.lifeasetsllc.com[/url]
   Type:   connection
   Detail: DNS problem: NXDOMAIN looking up A for [url=http://www.lifeasetsllc.com]www.lifeasetsllc.com[/url]

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address. Additionally, please check that
   your computer has a publicly routable IP address and that no
   firewalls are preventing the server from communicating with the
   client. If you&#039;re using the webroot plugin, you should also verify
   that you are serving files from the webroot path you provided.
 - The following errors were reported by the server:

   Domain: [url=http://www.lifeassetsllc.com]www.lifeassetsllc.com[/url]
   Type:   unauthorized
   Detail: Invalid response from
   [url]http://www.lifeassetsllc.com/.well-known/acme-challenge/zy_hc1QOh33Kiiz6gtI1ERuFxkufly0mBmxidqA5Nqg:[/url]
   &quot;&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML 2.0//EN&quot;&gt;
   &lt;html&gt;&lt;head&gt;
   &lt;title&gt;404 Not Found&lt;/title&gt;
   &lt;/head&gt;&lt;body&gt;
   &lt;h1&gt;Not Found&lt;/h1&gt;
   &lt;p&quot;

   Domain: lifeassetsllc.com
   Type:   unauthorized
   Detail: Invalid response from
   [url]http://lifeassetsllc.com/.well-known/acme-challenge/rPmwYEuYgeljSKOCyEgIB5ebK_W1K2qA8-3iFVepj00:[/url]
   &quot;&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML 2.0//EN&quot;&gt;
   &lt;html&gt;&lt;head&gt;
   &lt;title&gt;404 Not Found&lt;/title&gt;
   &lt;/head&gt;&lt;body&gt;
   &lt;h1&gt;Not Found&lt;/h1&gt;
   &lt;p&quot;

   Domain: mail.lifeassetsllc.com
   Type:   unauthorized
   Detail: Invalid response from
   [url]http://mail.lifeassetsllc.com/.well-known/acme-challenge/xPvkYSQpejAvtZf9d8k3CoORxFy7MChPjpbpzLZCw5o:[/url]
   &quot;&lt;!DOCTYPE HTML PUBLIC &quot;-//IETF//DTD HTML 2.0//EN&quot;&gt;
   &lt;html&gt;&lt;head&gt;
   &lt;title&gt;404 Not Found&lt;/title&gt;
   &lt;/head&gt;&lt;body&gt;
   &lt;h1&gt;Not Found&lt;/h1&gt;
   &lt;p&quot;

   To fix these errors, please make sure that your domain name was
   entered correctly and the DNS A/AAAA record(s) for that domain
   contain(s) the right IP address.
root@mail:/#</code></pre></div><p>The url stuff was inserted by the forum system, not me.&nbsp; Thoughts on what I have wrong?</p><p>I created a directory named /var/www/lifeassetsllc</p><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Sat, 16 Sep 2017 14:22:41 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58691.html#p58691</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58680.html#p58680</link>
			<description><![CDATA[<div class="quotebox"><cite>AndyInNYC wrote:</cite><blockquote><p>[Question 1]:  Do I use *all* of my domains on this line as if I were going to host all my websites here (which I may)?  Any downside to this?</p></blockquote></div><p>Yes you must list all domain names (AND their web document root directory) on command line.<br /></p><div class="quotebox"><cite>AndyInNYC wrote:</cite><blockquote><p>[Question 2]:  for lifeassetsllc.com do I also use a -d mail.lifeassetsllc.com?</p></blockquote></div><p>I suppose you need to use &#039;mail.lifeassetsllc.com&#039; as mail server address in MUA, if yes, then YES you need to add mail.lifeassetsllc.com.<br /></p><div class="quotebox"><cite>AndyInNYC wrote:</cite><blockquote><p>[Question 3]:   Where does this command dump the new files since I need to copy/link in the iRedMail tutorial?  What should they be named if I have to go look for them?</p></blockquote></div><p>/etc/letsencrypt<br /></p><div class="quotebox"><cite>AndyInNYC wrote:</cite><blockquote><p>[Question 4]:   To prevent disaster, do i need only back up the files which I will edit per the tutorial?</p></blockquote></div><p>As a sysadmin, backup always saves your life. <img src="https://forum.iredmail.org/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /></p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Sat, 16 Sep 2017 08:51:16 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58680.html#p58680</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58664.html#p58664</link>
			<description><![CDATA[<p>I read the tutorial, and it still left me a little confused.</p><p>Here&#039;s my plan:</p><p>Following the Let&#039;s Encrypt guide for &#039;Other Ubuntu 16.04&#039; (which hopefully will not mess with any iRedMail config files), I have :&nbsp; <a href="https://certbot.eff.org/#ubuntuxenial-other">https://certbot.eff.org/#ubuntuxenial-other</a></p><p>This has me apt-get the following:<br />sudo apt-get update<br />sudo apt-get install software-properties-common<br />sudo add-apt-repository ppa:certbot/certbot<br />sudo apt-get update<br />sudo apt-get install certbot</p><p>[Seems clear]</p><p>My machine&#039;s name/incoming/outgoing mail server is mail.lifeassetsllc.com.&nbsp; I host email for lifeassetsllc.com, server1.com, server2.com and server3.com.&nbsp; I may have a WordPress site for my wife on server3.com (i can point the DNS records to this machine).</p><p>The Let&#039;s Encrypt link says to use the command:<br />sudo certbot certonly --webroot -w /var/www/example -d example.com -d <a href="http://www.example.com">www.example.com</a> -w /var/www/thing -d thing.is -d m.thing.is</p><p>[Question 1]:&nbsp; Do I use *all* of my domains on this line as if I were going to host all my websites here (which I may)?&nbsp; Any downside to this?<br />[Question 2]:&nbsp; for lifeassetsllc.com do I also use a -d mail.lifeassetsllc.com?<br />[Question 3]:&nbsp; &nbsp;Where does this command dump the new files since I need to copy/link in the iRedMail tutorial?&nbsp; What should they be named if I have to go look for them?</p><p>Now, I need to edit the config files per the iRedMail tutorial for Postfix, Dovecot, Apache and MySQL.&nbsp; The tutorial seems clear on this.<br />[Question 4]:&nbsp; &nbsp;To prevent disaster, do i need only back up the files which I will edit per the tutorial?</p><br /><p>Post these edits, I either restart all the services or just reboot the server.</p><p>Assuming I understand the answers as they come in to Questions 1-4, is there anything I&#039;m missing in my steps above?</p><p>Thanks so much</p><br /><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Fri, 15 Sep 2017 14:31:52 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58664.html#p58664</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58560.html#p58560</link>
			<description><![CDATA[<p>Hi AndyInNYC:</p><p>please read our tutorial here:<br /><a href="http://www.iredmail.org/docs/use.a.bought.ssl.certificate.html">http://www.iredmail.org/docs/use.a.boug … icate.html</a></p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Tue, 12 Sep 2017 05:57:04 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58560.html#p58560</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post58556.html#p58556</link>
			<description><![CDATA[<p>I&#039;d like to install LE on my iRedMail server - I&#039;m loathe to do anything which will damage/undo a working system.&nbsp; I&#039;m running Apache versus Nginx.</p><p>I have mail.myserver.com as the mail server which runs mail for 6 domains (all log in via <a href="https://mail.myserver.com/SOGo">https://mail.myserver.com/SOGo</a> or in Outlook using mail.myserver.com as in/out mail servers.</p><p>So, a) what do I need to change in the first post to make the installation work for me?<br />&nbsp; &nbsp; &nbsp; b) what files should I backup first in case something goes wrong?<br />&nbsp; &nbsp; &nbsp; &nbsp;c) I&#039;m assuming I only need to run LE for <a href="http://www.myserver.com">www.myserver.com</a> and mail.myserver.com?</p><p>Thanks all.</p><br /><p>Andrew</p>]]></description>
			<author><![CDATA[null@example.com (AndyInNYC)]]></author>
			<pubDate>Mon, 11 Sep 2017 22:57:19 +0000</pubDate>
			<guid>https://forum.iredmail.org/post58556.html#p58556</guid>
		</item>
		<item>
			<title><![CDATA[Re: easy let's encrypt guide for ubuntu 16.04 iredmail server with nginx]]></title>
			<link>https://forum.iredmail.org/post56687.html#p56687</link>
			<description><![CDATA[<p>Stop openldap service first, then try this command:</p><div class="codebox"><pre><code>strace /usr/sbin/slapd -u ldap -g ldap -f /etc/ldap/slapd.conf</code></pre></div><p>It will trace the files read by OpenLDAP, i think it will print some useful info for debugging.</p>]]></description>
			<author><![CDATA[null@example.com (ZhangHuangbin)]]></author>
			<pubDate>Wed, 07 Jun 2017 13:52:38 +0000</pubDate>
			<guid>https://forum.iredmail.org/post56687.html#p56687</guid>
		</item>
	</channel>
</rss>
