Difference between revisions of "SBN - Copying Certs"
Jump to navigation
Jump to search
| Line 5: | Line 5: | ||
#*<code>sudo mkdir /etc/letsencrypt/live</code> | #*<code>sudo mkdir /etc/letsencrypt/live</code> | ||
#Sign into your proxy server & make sure you can SSH into the target machine from there. | #Sign into your proxy server & make sure you can SSH into the target machine from there. | ||
| − | #*ssh webserver | + | #*<code>ssh webserver</code> |
#**<code>ssh Machine</code> | #**<code>ssh Machine</code> | ||
| − | #**then exit when you've succeeded (this tells | + | #**then exit when you've succeeded (this tells '''webserver''' how to get there...) |
#Then you can use '''scp''' to copy the certs. | #Then you can use '''scp''' to copy the certs. | ||
#*<code>sudo scp -r /etc/letsencrypt/live/Machine.Domain.TLD user@Machine:~</code> | #*<code>sudo scp -r /etc/letsencrypt/live/Machine.Domain.TLD user@Machine:~</code> | ||
#Then ssh back into the proxy server & move the certs into their proper location | #Then ssh back into the proxy server & move the certs into their proper location | ||
#*<code>sudo mv Machine.Domain.TLD /etc/letsencrypt/live/</code> | #*<code>sudo mv Machine.Domain.TLD /etc/letsencrypt/live/</code> | ||
Revision as of 02:20, 11 July 2020
To copy certs for a machine from your proxy server (Replace Machine.Domain.TLD with the proper name for your machine...) (&, of course, user & webserver may need adjusting...)
- Install certbot on the machine you're putting the certs onto & create the
livedirectory where the certs will live.sudo apt in all certbotsudo mkdir /etc/letsencrypt/live
- Sign into your proxy server & make sure you can SSH into the target machine from there.
ssh webserverssh Machine- then exit when you've succeeded (this tells webserver how to get there...)
- Then you can use scp to copy the certs.
sudo scp -r /etc/letsencrypt/live/Machine.Domain.TLD user@Machine:~
- Then ssh back into the proxy server & move the certs into their proper location
sudo mv Machine.Domain.TLD /etc/letsencrypt/live/