Notice! acme.sh will not work with ipv6 when trying to aquire letsencrypt certs. I think it's a pf firewall
config problem, but haven't been able to figure it out yet, so to aquire letsencrypt certs with acme.sh
you'll need to disable ipv6 in /etc/rc.conf and remove any AAAA DNS entries in your DNS Zone.
pkg install acme.shConfigure the email address you want associated with your Let's Encrypt account:
acme.sh --register-account -m admin@example.orgConfigure what SSL server you want to use. For some strange reason acme.sh defaults to ZeroSSL, but like most people, I'm using Let's Encrypt:
acme.sh --set-default-ca --server letsencrypt
acme.sh --issue -d mail.example.org -d www.example.org -d example.org --keylength ec-384 -w /usr/local/www/apache24/dataFor Nginx web server run the command below and adjust for your domain:
acme.sh --issue -d mail.example.org -d www.example.org -d example.org --keylength ec-384 -w /usr/local/www/nginx
Comment out the self signed cert and key: Adjust for your domain. #SSLCertificateFile "/etc/ssl/example.org/example.org.crt" #SSLCertificateKeyFile "/etc/ssl/example.org/example.org.key" Add the Let's Encrypt cert and key: Adjust for your domain. SSLCertificateFile "/root/.acme.sh/mail.example.org_ecc/fullchain.cer" SSLCertificateKeyFile "/root/.acme.sh/mail.example.org_ecc/mail.example.org.key" Uncomment the following at about line #134: #Header always set Strict-Transport-Security "max-age=31536000; includeSubDomains"For Nginx web server edit /usr/local/etc/nginx/conf.d/mailserver.conf like below:
Comment out the self signed cert and key: #ssl_certificate /etc/ssl/example.org/example.org.crt; #ssl_certificate_key /etc/ssl/example.org/example.org.key; Add the Let's Encrypt cert and key, and of course adjust for your domain: ssl_certificate /root/.acme.sh/mail.example.org_ecc/fullchain.cer; ssl_certificate_key /root/.acme.sh/mail.example.org_ecc/mail.example.org.key; Uncomment the following at about line #27: # add_header Strict-Transport-Security "max-age=31536000; includeSubDomains; preload" always;
service apache24 restartFor Nginx:
service nginx restartYour web server should be using the Let's Encrypt certs now.
Commit out the self signed certs: #smtpd_tls_CAfile = /etc/ssl/cert.pem #smtpd_tls_key_file = /etc/ssl/the-slacker.org/the-slacker.org.key #smtpd_tls_cert_file = /etc/ssl/the-slacker.org/the-slacker.org.crt Add the Let's Encrypt certs: smtpd_tls_CAfile = /root/.acme.sh/mail.example.org_ecc/ca.cer smtpd_tls_key_file = /root/.acme.sh/mail.example.org_ecc/mail.example.org.key smtpd_tls_cert_file = /root/.acme.sh/mail.example.org_ecc/fullchain.cerRestart Postfix:
service postfix restartDovecot:
Commit out the self signed certs: #ssl_cert = </etc/ssl/the-slacker.org/the-slacker.org.crt #ssl_key = </etc/ssl/the-slacker.org/the-slacker.org.key Add the Let's Encrypt certs: ssl_cert = </root/.acme.sh/mail.example.org_ecc/fullchain.cer ssl_key = </root/.acme.sh/mail.example.org_ecc/mail.example.org.keyRestart Dovecot:
service dovecot restartWebmin:
Commit out the self signed certs: #keyfile=/usr/local/etc/webmin/miniserv.pem Add the Let's Encrypt certs: keyfile=/root/.acme.sh/mail.example.org_ecc/mail.example.org.key certfile=/root/.acme.sh/mail.example.org_ecc/fullchain.cerRestart Webmin:
service webmin restart
touch /var/log/acme.renew.logThen create a weekly periodic script to check if certs need renewing.
echo '#!/bin/sh /usr/local/sbin/acme.sh --renew -d mail.example.org -d www.example.org -d example.org > /var/log/acme.renew.log grep -q 'Skipping' /var/log/acme.renew.log if [ $? -eq 1 ]; then service apache24 restart >/dev/null 2>&1 service nginx restart >/dev/null 2>&1 service webmin restart >/dev/null 2>&1 service dovecot restart >/dev/null 2>&1 service postfix restart >/dev/null 2>&1 fi' > /usr/local/etc/periodic/weekly/000.acme-cert-renewThen make the renew script executable:
chmod 0755 /usr/local/etc/periodic/weekly/000.acme-cert-renewYou can test the weekly periodic Let's Encrypt renew script by running the following:
periodic weekly cat /var/log/acme.renew.logThat should do it for Let's Encrypt for now.
Apache v2.4.69
SlackerMail v0.65.6