diff --git a/certbot/default-quic b/certbot/default-quic index cf1f8cf..69ea319 100644 --- a/certbot/default-quic +++ b/certbot/default-quic @@ -1,5 +1,4 @@ certbot certonly --webroot --webroot-path /srv/nginx --no-eff-email \ - --key-type ecdsa --must-staple \ - --deploy-hook "certbot-ocsp-fetcher -o /var/cache/certbot-ocsp-fetcher" \ + --key-type ecdsa --cert-name hostname.of.your.server \ -d hostname.of.your.server \ No newline at end of file diff --git a/certbot/miniflux b/certbot/miniflux index 87811b2..0921c32 100644 --- a/certbot/miniflux +++ b/certbot/miniflux @@ -1,5 +1,4 @@ certbot certonly --webroot --webroot-path /srv/nginx --no-eff-email \ - --key-type ecdsa --must-staple \ - --deploy-hook "certbot-ocsp-fetcher -o /var/cache/certbot-ocsp-fetcher" \ + --key-type ecdsa --cert-name miniflux.yourdomain.tld \ -d miniflux.yourdomain.tld \ No newline at end of file diff --git a/certbot/uptime-kuma b/certbot/uptime-kuma index fe73e06..2fc8e2b 100644 --- a/certbot/uptime-kuma +++ b/certbot/uptime-kuma @@ -1,5 +1,4 @@ certbot certonly --webroot --webroot-path /srv/nginx --no-eff-email \ - --key-type ecdsa --must-staple \ - --deploy-hook "certbot-ocsp-fetcher -o /var/cache/certbot-ocsp-fetcher" \ + --key-type ecdsa --cert-name uptime.yourdomain.tld \ -d uptime.yourdomain.tld \ No newline at end of file diff --git a/etc/nginx/conf.d/sites_default_quic.conf b/etc/nginx/conf.d/sites_default_quic.conf index 9d2a0f6..1d1503a 100644 --- a/etc/nginx/conf.d/sites_default_quic.conf +++ b/etc/nginx/conf.d/sites_default_quic.conf @@ -13,5 +13,4 @@ server { ssl_certificate /etc/letsencrypt/live/hostname.of.your.server/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/hostname.of.your.server/privkey.pem; ssl_trusted_certificate /etc/letsencrypt/live/hostname.of.your.server/chain.pem; - ssl_stapling_file /var/cache/certbot-ocsp-fetcher/hostname.of.your.server.der; } \ No newline at end of file diff --git a/etc/nginx/conf.d/sites_miniflux.conf b/etc/nginx/conf.d/sites_miniflux.conf index e7388b1..6f5a384 100644 --- a/etc/nginx/conf.d/sites_miniflux.conf +++ b/etc/nginx/conf.d/sites_miniflux.conf @@ -9,7 +9,6 @@ server { ssl_certificate /etc/letsencrypt/live/miniflux.yourdomain.tld/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/miniflux.yourdomain.tld/privkey.pem; ssl_trusted_certificate /etc/letsencrypt/live/miniflux.yourdomain.tld/chain.pem; - ssl_stapling_file /var/cache/certbot-ocsp-fetcher/miniflux.yourdomain.tld.der; include snippets/universal_paths.conf; include snippets/hsts.conf; diff --git a/etc/nginx/conf.d/sites_uptime-kuma.conf b/etc/nginx/conf.d/sites_uptime-kuma.conf index 2e03760..52308f2 100644 --- a/etc/nginx/conf.d/sites_uptime-kuma.conf +++ b/etc/nginx/conf.d/sites_uptime-kuma.conf @@ -11,7 +11,6 @@ server { ssl_certificate /etc/letsencrypt/live/uptime.yourdomain.tld/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/uptime.yourdomain.tld/privkey.pem; ssl_trusted_certificate /etc/letsencrypt/live/uptime.yourdomain.tld/chain.pem; - ssl_stapling_file /var/cache/certbot-ocsp-fetcher/uptime.yourdomain.tld.der; include snippets/universal_paths.conf; include snippets/hsts.conf; diff --git a/setup.sh b/setup.sh index 407bb5f..8a83f8f 100644 --- a/setup.sh +++ b/setup.sh @@ -54,16 +54,6 @@ unpriv curl https://raw.githubusercontent.com/GrapheneOS/infrastructure/main/sys chmod 644 /etc/systemd/system/nginx.service.d/override.conf sudo systemctl daemon-reload -# Setup certbot-ocsp-fetcher -unpriv curl https://raw.githubusercontent.com/tomwassenberg/certbot-ocsp-fetcher/main/certbot-ocsp-fetcher | sudo tee /usr/local/bin/certbot-ocsp-fetcher -## Explicitly using /var/usrlocal/bin here because SELinux does not follow symlinks -sudo semanage fcontext -a -t bin_t /var/usrlocal/bin/certbot-ocsp-fetcher -sudo restorecon -Rv /var/usrlocal/bin/certbot-ocsp-fetcher -sudo chmod u+x /var/usrlocal/bin/certbot-ocsp-fetcher -sudo semanage fcontext -a -t httpd_config_t "/var/cache/certbot-ocsp-fetcher(/.*)?" -sudo mkdir -p /var/cache/certbot-ocsp-fetcher/ -sudo chmod 755 /var/cache/certbot-ocsp-fetcher/ - # Setup nginx-create-session-ticket-keys unpriv curl https://raw.githubusercontent.com/GrapheneOS/infrastructure/main/nginx-create-session-ticket-keys | sudo tee /usr/local/bin/nginx-create-session-ticket-keys ## Explicitly using /var/usrlocal/bin here because SELinux does not follow symlinks