3 ms·
Thanks, I did use Let's Encrypt and had certbot setup but didn't realise the renew process required port 80 open (I had blocked it on my firewall).
by poglet 4y ago
Thanks, I did use Let's Encrypt and had certbot setup but didn't realise the renew process required port 80 open (I had blocked it on my firewall).
- drexlspivey 4y agoYou don’t need port 80 open, you can do DNS based challenge. 1) Transfer your domain to someone who provides a DNS API like DigitalOcean or Cloudflare 2) download the appropriate plugin for certbot (certbot-dns-digitalocean, certbot-dns-cloudflare) 3) get an API token and config the plugin with it 4) set up a post-renew-hook to do a `service nginx reload` to reload the new cert sample instructions for DO https://www.digitalocean.com/community/tutorials/how-to-acquire-a-let-s-encrypt-certificate-using-dns-validation-with-certbot-dns-digitalocean-on-ubuntu-20-04 https://www.digitalocean.com/community/tutorials/how-to-acqu...
- poglet 4y agoThanks for your reply, this was really helpful I will give it a shot.