Alan Orth
a34cb1e666
The certbot-auto client that I've been using for a long time is now only supported if you install it using snap. I don't use snap on my systems so I decided to switch to the acme.sh client, which is imp- lemented in POSIX shell with no dependencies. One bonus of this is that I can start using ECC certificates. This also configures the .well-known directory so we can use webroot when installing and renewing certificates. I have yet to understand how the renewal works with regards to webroot, though. I may have to update the systemd timers to point to /var/lib/letsencrypt/.well-known.
7 lines
140 B
Django/Jinja
7 lines
140 B
Django/Jinja
location ^~ /.well-known/acme-challenge/ {
|
|
allow all;
|
|
root /var/lib/letsencrypt/;
|
|
default_type "text/plain";
|
|
try_files $uri =404;
|
|
}
|