Просмотр исходного кода

Add support for obtain ECDSA keys

pull/1667/head
Alejo Diaz 4 лет назад
Родитель
Сommit
45a9b1569f
Не найден GPG ключ соответствующий данной подписи Идентификатор GPG ключа: FF146C79074B1CE0
4 измененных файлов: 19 добавлений и 1 удалений
  1. +9
    -0
      docs/configuring-playbook-ssl-certificates.md
  2. +4
    -0
      roles/matrix-nginx-proxy/defaults/main.yml
  3. +2
    -0
      roles/matrix-nginx-proxy/tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml
  4. +4
    -1
      roles/matrix-nginx-proxy/templates/usr-local-bin/matrix-ssl-lets-encrypt-certificates-renew.j2

+ 9
- 0
docs/configuring-playbook-ssl-certificates.md Просмотреть файл

@@ -100,3 +100,12 @@ For automated certificate renewal to work, each port `80` vhost for each domain


See how this is configured for the `matrix.` subdomain in `/matrix/nginx-proxy/conf.d/matrix-synapse.conf` See how this is configured for the `matrix.` subdomain in `/matrix/nginx-proxy/conf.d/matrix-synapse.conf`
Don't be alarmed if the above configuration file says port `8080`, instead of port `80`. It's due to port mapping due to our use of containers. Don't be alarmed if the above configuration file says port `8080`, instead of port `80`. It's due to port mapping due to our use of containers.


## Obtaining SSL certificates with ECDSA private key algorithm

If you'd like to obtain ECDSA keys by Let's Encrypt, define your own custom configuration like this:

```yaml
matrix_ssl_lets_encrypt_use_ecdsa_keys: true
```

+ 4
- 0
roles/matrix-nginx-proxy/defaults/main.yml Просмотреть файл

@@ -489,6 +489,10 @@ matrix_ssl_lets_encrypt_support_email: ~
# If you'd like to not bind on all IP addresses, specify one explicitly (e.g. `a.b.c.d:80`) # If you'd like to not bind on all IP addresses, specify one explicitly (e.g. `a.b.c.d:80`)
matrix_ssl_lets_encrypt_container_standalone_http_host_bind_port: '80' matrix_ssl_lets_encrypt_container_standalone_http_host_bind_port: '80'


# Get SSL certificates with ECDSA private key algorithm.
# Learn more here: https://eff-certbot.readthedocs.io/en/stable/using.html#using-ecdsa-keys
matrix_ssl_lets_encrypt_use_ecdsa_keys: false

matrix_ssl_base_path: "{{ matrix_base_data_path }}/ssl" matrix_ssl_base_path: "{{ matrix_base_data_path }}/ssl"
matrix_ssl_config_dir_path: "{{ matrix_ssl_base_path }}/config" matrix_ssl_config_dir_path: "{{ matrix_ssl_base_path }}/config"
matrix_ssl_log_dir_path: "{{ matrix_ssl_base_path }}/log" matrix_ssl_log_dir_path: "{{ matrix_ssl_base_path }}/log"


+ 2
- 0
roles/matrix-nginx-proxy/tasks/ssl/setup_ssl_lets_encrypt_obtain_for_domain.yml Просмотреть файл

@@ -45,6 +45,7 @@
--http-01-port 8080 --http-01-port 8080
{% if matrix_ssl_lets_encrypt_server %}--server={{ matrix_ssl_lets_encrypt_server|quote }}{% endif %} {% if matrix_ssl_lets_encrypt_server %}--server={{ matrix_ssl_lets_encrypt_server|quote }}{% endif %}
{% if matrix_ssl_lets_encrypt_staging %}--staging{% endif %} {% if matrix_ssl_lets_encrypt_staging %}--staging{% endif %}
{% if matrix_ssl_lets_encrypt_use_ecdsa_keys %}--key-type ecdsa{% endif %}
--standalone --standalone
--preferred-challenges http --preferred-challenges http
--agree-tos --agree-tos
@@ -74,6 +75,7 @@
--http-01-port 8080 --http-01-port 8080
{% if matrix_ssl_lets_encrypt_server %}--server={{ matrix_ssl_lets_encrypt_server|quote }}{% endif %} {% if matrix_ssl_lets_encrypt_server %}--server={{ matrix_ssl_lets_encrypt_server|quote }}{% endif %}
{% if matrix_ssl_lets_encrypt_staging %}--staging{% endif %} {% if matrix_ssl_lets_encrypt_staging %}--staging{% endif %}
{% if matrix_ssl_lets_encrypt_use_ecdsa_keys %}--key-type ecdsa{% endif %}
--standalone --standalone
--preferred-challenges http --preferred-challenges http
--agree-tos --agree-tos


+ 4
- 1
roles/matrix-nginx-proxy/templates/usr-local-bin/matrix-ssl-lets-encrypt-certificates-renew.j2 Просмотреть файл

@@ -22,7 +22,10 @@ docker run \
--work-dir=/tmp \ --work-dir=/tmp \
--http-01-port 8080 \ --http-01-port 8080 \
{% if matrix_ssl_lets_encrypt_staging %} {% if matrix_ssl_lets_encrypt_staging %}
--staging \
--staging \
{% endif %}
{% if matrix_ssl_lets_encrypt_use_ecdsa_keys %}
--key-type ecdsa \
{% endif %} {% endif %}
--standalone \ --standalone \
--preferred-challenges http \ --preferred-challenges http \


Загрузка…
Отмена
Сохранить