[ale] let's encrypt cert renewals?

Ben Coleman oloryn at benshome.net
Thu May 11 13:52:05 EDT 2017


On 5/11/2017 01:26 PM, Kyle Brieden wrote:
> Ben,
> 
> For what it's worth, I do use the webroot plugin, because when I set up
> LE on my webservers, that seemed to be the only way to support nginx. 
> Now, my crontabs all read like this:
> 
> root at media:~# crontab -l | egrep -v "^#.*$"
> MAILTO=kyle at txmoose.com
> 30 2 * * 1 /opt/certbot-auto renew --post-hook "service nginx reload"
> root at media:~#

Note that your '--post-hook' can be '--renew-hook'.  That way nginx is
only reloaded when there's been a successful renewal.

Ben
-- 
Ben Coleman oloryn at benshome.net | For the wise man, doing right trumps
http://oloryn.benshome.net/     | looking right.  For the fool, looking
Amateur Radio NJ8J              | right trumps doing right.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 834 bytes
Desc: OpenPGP digital signature
URL: <http://mail.ale.org/pipermail/ale/attachments/20170511/41c99144/attachment.sig>


More information about the Ale mailing list