From: "=?utf-8?q?Dan_Napier=2C_MS=2C_CIH=2C_CAC?=" Received: from [192.168.100.201] (HELO mail.2rosenthals.com) by 2rosenthals.com (CommuniGate Pro SMTP 5.4.10) with ESMTP id 10610492 for ecs-isp@2rosenthals.com; Fri, 16 Aug 2024 14:00:04 -0400 Received: from [192.168.200.201] (port=34941 helo=mail2.2rosenthals.com) by mail.2rosenthals.com with esmtp (Exim 4.97.1) (envelope-from ) id 1sf1F3-000000004km-1at9 for ecs-isp@2rosenthals.com; Fri, 16 Aug 2024 14:00:02 -0400 Received: from kaliss.dnacih.com ([47.180.217.131]:54290) by mail2.2rosenthals.com with esmtp (Exim 4.97.1) (envelope-from ) id 1sf1F0-000000003CX-0ibw for ecs-isp@2rosenthals.com; Fri, 16 Aug 2024 13:59:59 -0400 X-SASI-Hits: BODYTEXTH_SIZE_10000_LESS 0.000000, BODYTEXTH_SIZE_3000_MORE 0.000000, BODYTEXTP_SIZE_3000_LESS 0.000000, BODY_SIZE_10000_PLUS 0.000000, CS_SUSP_TLD_BODY 0.000000, DATE_TZ_NA 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, FROM_NAME_PHRASE 0.000000, HTML_NO_HTTP 0.100000, INT_PROD_DOM_OBFU 0.100000, INVALID_MSGID_NO_FQDN 0.000000, INVOICE_ATTACHMENT 0.100000, LEGITIMATE_SIGNS 0.000000, LINK_TLD 0.100000, MSG_THREAD 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, TXT_ATTACHED 0.000000, USER_AGENT 0.000000, __ANY_URI 0.000000, __ATTACHMENT_NOT_IMG 0.000000, __ATTACH_CTE_QUOTED_PRINTABLE 0.000000, __BODY_NO_MAILTO 0.000000, __BODY_TEXT_X4 0.000000, __BODY_VOICEMAIL 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTYPE_HAS_BOUNDARY 0.000000, __CTYPE_MULTIPART 0.000000, __CTYPE_MULTIPART_MIXED 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __FORWARDED_MSG 0.000000, __FRAUD_BEC 0.000000, __FRAUD_MONEY_CURRENCY 0.000000, __FRAUD_MONEY_CURRENCY_DOLLAR 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FROM_UTF_Q 0.000000, __FUR_HEADER 0.000000, __HAS_ATTACHMENT 0.000000, __HAS_ATTACHMENT1 0.000000, __HAS_FROM 0.000000, __HAS_HTML 0.000000, __HAS_MSGID 0.000000, __HAS_REPLYTO 0.000000, __HELO_LOCALHOST 0.000000, __HELO_LOCALHOST2 0.000000, __HIGHBIT_ASCII_MIX 0.000000, __HTML_BAD_END 0.000000, __HTML_ENTITIES_X4 0.000000, __HTTPS_URI 0.000000, __INVOICE_MULTILINGUAL 0.000000, __MAIL_CHAIN 0.000000, __MIME_ATTACHMENT_1_N 0.000000, __MIME_ATTACHMENT_N_2 0.000000, __MIME_HTML 0.000000, __MIME_TEXT_H 0.000000, __MIME_TEXT_H1 0.000000, __MIME_TEXT_H2 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_TEXT_P2 0.000000, __MIME_VERSION 0.000000, __MSGID_DOMAIN_NOT_IN_HDRS 0.000000, __MULTIPLE_URI_TEXT 0.000000, __PART_TYPE_HTML 0.000000, __PHISH_PHRASE1_A 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __RUS_OBFU_PHONE 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __STOCK_PHRASE_7 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TAG_EXISTS_HTML 0.000000, __TOLL_FREE_PHONE_US 0.000000, __TO_IN_SUBJECT 0.000000, __TO_IN_SUBJECT2 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_ENDS_IN_SLASH 0.000000, __URI_HAS_HYPHEN_USC 0.000000, __URI_IN_BODY 0.000000, __URI_IN_BODY_HTTP_X10 0.000000, __URI_MAILTO 0.000000, __URI_NOT_IMG 0.000000, __URI_NS 0.000000, __URI_WITHOUT_PATH 0.000000, __URI_WITH_PATH 0.000000, __USER_AGENT 0.000000, __UTF8_SUBJ 0.000000, __X_VIRUS_SCANNED 0.000000 X-SASI-Probability: 11% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.8.16.171816 X-SASI-Hits: BODYTEXTH_SIZE_10000_LESS 0.000000, BODYTEXTH_SIZE_3000_MORE 0.000000, BODYTEXTP_SIZE_3000_LESS 0.000000, BODY_SIZE_10000_PLUS 0.000000, CS_SUSP_TLD_BODY 0.000000, DATE_TZ_NA 0.000000, DKIM_ALIGNS 0.000000, DKIM_SIGNATURE 0.000000, FROM_NAME_PHRASE 0.000000, HTML_NO_HTTP 0.100000, INT_PROD_DOM_OBFU 0.100000, INVALID_MSGID_NO_FQDN 0.000000, INVOICE_ATTACHMENT 0.100000, LEGITIMATE_SIGNS 0.000000, LINK_TLD 0.100000, MSG_THREAD 0.000000, REPLYTO_SAMEAS_FROM 0.000000, SENDER_NO_AUTH 0.000000, SUSP_DH_NEG 0.000000, TO_IN_SUBJECT 0.500000, TXT_ATTACHED 0.000000, USER_AGENT 0.000000, __ANY_URI 0.000000, __ATTACHMENT_NOT_IMG 0.000000, __ATTACH_CTE_QUOTED_PRINTABLE 0.000000, __BODY_NO_MAILTO 0.000000, __BODY_TEXT_X4 0.000000, __BODY_VOICEMAIL 0.000000, __BOUNCE_CHALLENGE_SUBJ 0.000000, __BOUNCE_NDR_SUBJ_EXEMPT 0.000000, __CP_URI_IN_BODY 0.000000, __CT 0.000000, __CTYPE_HAS_BOUNDARY 0.000000, __CTYPE_MULTIPART 0.000000, __CTYPE_MULTIPART_MIXED 0.000000, __DKIM_ALIGNS_1 0.000000, __DKIM_ALIGNS_2 0.000000, __FORWARDED_MSG 0.000000, __FRAUD_BEC 0.000000, __FRAUD_MONEY_CURRENCY 0.000000, __FRAUD_MONEY_CURRENCY_DOLLAR 0.000000, __FROM_DOMAIN_NOT_IN_BODY 0.000000, __FROM_NAME_NOT_IN_BODY 0.000000, __FROM_UTF_Q 0.000000, __FUR_HEADER 0.000000, __HAS_ATTACHMENT 0.000000, __HAS_ATTACHMENT1 0.000000, __HAS_FROM 0.000000, __HAS_HTML 0.000000, __HAS_MSGID 0.000000, __HAS_REPLYTO 0.000000, __HELO_LOCALHOST 0.000000, __HELO_LOCALHOST2 0.000000, __HIGHBIT_ASCII_MIX 0.000000, __HTML_BAD_END 0.000000, __HTML_ENTITIES_X4 0.000000, __HTTPS_URI 0.000000, __INVOICE_MULTILINGUAL 0.000000, __MAIL_CHAIN 0.000000, __MIME_ATTACHMENT_1_N 0.000000, __MIME_ATTACHMENT_N_2 0.000000, __MIME_HTML 0.000000, __MIME_TEXT_H 0.000000, __MIME_TEXT_H1 0.000000, __MIME_TEXT_H2 0.000000, __MIME_TEXT_P 0.000000, __MIME_TEXT_P1 0.000000, __MIME_TEXT_P2 0.000000, __MIME_VERSION 0.000000, __MSGID_DOMAIN_NOT_IN_HDRS 0.000000, __MULTIPLE_URI_TEXT 0.000000, __PART_TYPE_HTML 0.000000, __PHISH_PHRASE1_A 0.000000, __REPLYTO_SAMEAS_FROM_ACC 0.000000, __REPLYTO_SAMEAS_FROM_ADDY 0.000000, __REPLYTO_SAMEAS_FROM_DOMAIN 0.000000, __RUS_OBFU_PHONE 0.000000, __SANE_MSGID 0.000000, __SCAN_D_NEG 0.000000, __SCAN_D_NEG2 0.000000, __SCAN_D_NEG_HEUR 0.000000, __SCAN_D_NEG_HEUR2 0.000000, __STOCK_PHRASE_7 0.000000, __SUBJ_ALPHA_END 0.000000, __SUBJ_ALPHA_NEGATE 0.000000, __SUBJ_REPLY 0.000000, __TAG_EXISTS_HTML 0.000000, __TOLL_FREE_PHONE_US 0.000000, __TO_IN_SUBJECT 0.000000, __TO_IN_SUBJECT2 0.000000, __TO_MALFORMED_2 0.000000, __TO_NAME 0.000000, __TO_NAME_DIFF_FROM_ACC 0.000000, __TO_REAL_NAMES 0.000000, __URI_ENDS_IN_SLASH 0.000000, __URI_HAS_HYPHEN_USC 0.000000, __URI_IN_BODY 0.000000, __URI_IN_BODY_HTTP_X10 0.000000, __URI_MAILTO 0.000000, __URI_NOT_IMG 0.000000, __URI_NS 0.000000, __URI_WITHOUT_PATH 0.000000, __URI_WITH_PATH 0.000000, __USER_AGENT 0.000000, __UTF8_SUBJ 0.000000, __X_VIRUS_SCANNED 0.000000 X-SASI-Probability: 11% X-SASI-RCODE: 200 X-SASI-Version: Antispam-Engine: 5.1.4, AntispamData: 2024.8.16.173620 X-ASG-Debug-ID: 1723831189-101376704f69490001-4YkuuC Received: from scotty.dnacih.com (scotty.dnacih.com [64.60.60.125]) by kaliss.dnacih.com with ESMTP id B9DUViEFh1ZuQmBv for ; Fri, 16 Aug 2024 10:59:49 -0700 (PDT) X-Barracuda-Envelope-From: dan@cihcsp.com X-Barracuda-Effective-Source-IP: scotty.dnacih.com[64.60.60.125] X-Barracuda-Apparent-Source-IP: 64.60.60.125 Received: from [127.0.0.1] (localhost [127.0.0.1]) by localhost (Mailerdaemon) with ESMTPA id 0C44C6C1E03 for ; Fri, 16 Aug 2024 10:59:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cihcsp.com; s=dkim; t=1723831188; h=from:reply-to:subject:date:message-id:to:mime-version:content-type; bh=DPmCmX18NTlHhq4ZkB0iFNu43Mef7pkU+x7NMsiUGf0=; b=PGAFBxLt6fvvwbpECexrc0PzvjjVoZb0lAj9+zrYXEI+fsfMQg0I0AuYuM7YMNuMpbZM6W Mp8g8DrgPwTifAXVJp8ulrNZAJFDpPIFGASx+Njnz7feAAwBl+vTs8w7pJPD+iTXSi0zRl xvgiUH6z7BaL7pegEfx/CeljwIS7x6HGZk8QnHZyiwAnLuvncKO3NaBwQuU4R42UtBFcC4 bHXy747nOCI3Za+1K0yyN5uphy8r0GpuJjbK6C4RuPhcAE9H797T8T4Q2NRllUbOWSt+Jj Rkr3ZIInUsebw+zhC5Se8zBrTtTC5D5hEwnl06DchBPp97mR+q9M98PZPh4yyA== Content-Type: multipart/mixed; boundary="----=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444501-1------" Reply-To: dan@cihcsp.com Date: Fri, 16 Aug 2024 10:59:45 -0700 To: "eCS ISP Mailing List" MIME-Version: 1.0 Message-ID: <35f355-66bf9380-1-1adb7180@72572691> Subject: =?utf-8?q?Re=3A?= [eCS-ISP] Apache HTTPS User-Agent: SOGoMail 5.10.0 X-ASG-Orig-Subj: =?utf-8?q?Re=3A?= [eCS-ISP] Apache HTTPS X-Last-TLS-Session-Version: None X-Barracuda-Connect: scotty.dnacih.com[64.60.60.125] X-Barracuda-Start-Time: 1723831189 X-Barracuda-URL: https://47.180.217.131:443/cgi-mod/mark.cgi X-Barracuda-BRTS-Status: 1 X-Virus-Scanned: by bsmtpd at dnacih.com X-Barracuda-Scan-Msg-Size: 14688 X-Barracuda-Spam-Score: 0.40 X-Barracuda-Spam-Status: No, SCORE=0.40 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=7.0 tests=BSF_SC0_SA085b, HTML_MESSAGE X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.129131 Rule breakdown below pts rule name description ---- ---------------------- -------------------------------------------------- 0.00 HTML_MESSAGE BODY: HTML included in message 0.40 BSF_SC0_SA085b Custom Rule SA085b ------=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444501-1------ Content-Type: multipart/alternative; boundary="----=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444260-0------" ------=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444260-0------ Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Content-Length: 6942 Steven Here is as far as I get,=C2=A0 I is asking for a TXT line in the dns se= rver? =C2=A0uacme.exe: challenge https://acme-v02.api.letsencrypt.org/acme/ch= all-v3/38943333 6946/-1Wx1w failed with status invalid uacme.exe: the server reported the following error: { "type": "urn:ietf:params:acme:error:dns", "detail": "DNS problem: NXDOMAIN looking up TXT for =5Facme-challen= ge.ns1.dnac ih.com - check that a DNS record exists for this domain", "status": 400 } uacme.exe: failed to authorize order at https://acme-v02.api.letsencryp= t.org/acm e/order/1887586636/295703974986 On Tuesday, July 23, 2024 04:30 PDT, "Massimo S." wrote: =C2=A0Now the apache httpd.conf part: this rewrite http requests to the https vhost: ServerAdmin webmaster@yourwebsite.com ServerName www.yourwebsite.com ServerAlias yourwebsite.com RewriteEngine on RewriteCond %{HTTP=5FHOST} ^(www\.)?yourwebsite\.com [NC] RewriteCond %{HTTPS} off RewriteRule ^/(.*)$ https://www.yourwebsite.com/$1 [R,L] now the https vhost: ServerAdmin webmaster@yourwebsite.com DocumentRoot d:/apache/htdocs/yourwebsite ServerName www.yourwebsite.com ServerAlias yourwebsite.com SSLEngine on SSLCertificateFile c:/mptn/etc/ssl/uacme/www.yourwebsite.com/cert.pem SSLCertificateKeyFile c:/mptn/etc/ssl/uacme/private/www.yourwebsite.com= /key.pem you don't need the chain certificate since UACME create automatically a= certificate with also the chain certificate inside it to verify your certificate you can use this web tool: https://decoder.link/sslchecker/www.yourwebsite.com/443 that's all massimo Il 23/07/2024 12:20, Massimo S. ha scritto: > I use Paul's port of UACME, it can renew the www.yourwebsite.com (3rd= level) cert and both the 2nd level > yourwebsite.com at the same time too. > > > This is a simple reissue of just www.yourwebsite.. certificate. > I run uacme in a separate tree, not under the apache tree, i don't su= ggest > you to run it under \apache tree. > You need port 80 (HTTP) open on your webserver for this operation. > You need to create all these paths you can see down here. > You don't need Let's Encrypt chain certificates files, since uacme al= ready by it's own > create a certificate with the chain certificate inside of the .cert, = so > you have always the latest chain certificate from Let's Encrypt autom= atically. > > I run the scripts scheduled once each 2 months (LE Certs only last 3 = months), > so in case of issues i still have 1 month to fix them. > **don't forget** to add a Call SysSleep of about 10 seconds between a= reissue > and another (if you runs tenths of renewals like me) or you can get p= roblems, > i mean renewal that fails. > In your script after the renewal/s you can place the code to restart = apache. > > > > renewal (issue) script: > > @attrib c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key.pem -R > @copy c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key=5Fold.pem > c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key=5Fold2.pem > @copy c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key.pem > c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key=5Fold.pem > @del c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key.pem /N > @attrib c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert.pem -R > @copy c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert=5Fold.pem > c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert=5Fold2.pem > @copy c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert.pem c:\mptn\etc\s= sl\uacme\www.youwebsite.com\cert=5Fold.pem > @del c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert.pem /N > uacme issue www.youwebsite.com -h hook=5Fyourwebsite=5Fcom.cmd 2>>d:\= services\uacme\re.log > > > > hook script: > > parse arg var1 var2 var3 var4 var5 > myfile =3D 'X:\apache\htdocs\yourwebsite\.well-known\acme-challenge\'= ||var4 > call SysFileDelete 'X:\apache\htdocs\yourwebsite\.well-known\acme-cha= llenge\'||var4 > rc=3D LINEOUT(myfile,var5) > > > > i'm keeping 2 bkup of private keys + certs (you can see all those cop= ies) > hope it's all explained well > > massimo > > > Il 22/07/2024 15:33, Dan Napier ha scritto: >> Has anyone installed let=E2=80=99s Encrypt Certbot on OS2 .=C2=A0 Wh= at did you use ? >> >> HTTPS is needed.=C2=A0 Or how are you installing the certs? >> >> Dan Napier, MS, CIH >> >> DNA Industrial Hygiene >> >> 2520 Artesia Boulevard >> >> Redondo Beach, CA 90278-3210 >> >> 310-644-1924 X 103 >> >> CSLB #773462 >> >> DNA Industrial Hygiene 800-644-1924 >> > > =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D > This message is sent to you because you are subscribed to > =C2=A0the mailing list . > To unsubscribe, E-mail to: > To switch to the DIGEST mode, E-mail to > To switch to the INDEX mode, E-mail to > Send administrative queries to=C2=A0 > To subscribe (new addresses), E-mail to: = and reply to the confirmation email. > Web archives are publicly available at: http://lists.2rosenthals.com > > This list is hosted by Rosenthal & Rosenthal, LLC > P.O. Box 281, Deer Park, NY 11729-0281. Non- > electronic communications related to content > contained in these messages should be directed > to the above address. (CAN-SPAM Act of 2003) > > =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D > =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D This message is sent to you because you are subscribed to the mailing list . To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to To switch to the INDEX mode, E-mail to Send administrative queries to To subscribe (new addresses), E-mail to: a= nd reply to the confirmation email. Web archives are publicly available at: http://lists.2rosenthals.com This list is hosted by Rosenthal & Rosenthal, LLC P.O. Box 281, Deer Park, NY 11729-0281. Non- electronic communications related to content contained in these messages should be directed to the above address. (CAN-SPAM Act of 2003) =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D =C2=A0 --=C2=A0 Certified Industrial Hygienist Certified Asbestos Consultant Dan Napier, MS, CIH, CAC 92-0614 8/24/24 2520 Artesia Boulevard Redondo Beach, CA 90278-3210 310-644-1924 x 103 CSLB 773462 ------=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444260-0------ Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable Content-Length: 8596 Steven

Here is as far as I get,  I is asking for = a TXT line in the dns server?
 
uacme.exe: challenge http=
s://acme-v02.api.letsencrypt.org/acme/chall-v3/38943333
6946/-1Wx1w failed with status invalid
uacme.exe: the server reported the following error:
{
    "type": "urn:ietf:params:acme:error:dns",
    "detail": "DNS problem: NXDOMAIN looking up TXT for =5Facme-challen=
ge.ns1.dnac
ih.com - check that a DNS record exists for this domain",
    "status": 400
}
uacme.exe: failed to authorize order at https://acme-v02.api.letsencryp=
t.org/acm
e/order/1887586636/295703974986




On Tuesday, July 23, 2024 04:30 PDT, "Mas= simo S." <ecs-isp@2rosenthals.com> wrote:
 
Now the apache htt= pd.conf part:


this rewrite http requests to the https = vhost:

<VirtualHost *:80>
ServerAdmin webmaster@y= ourwebsite.com
ServerName www.yourwebsite.com
ServerAlias you= rwebsite.com
RewriteEngine on
RewriteCond %{HTTP=5FHOST} ^(ww= w\.)?yourwebsite\.com [NC]
RewriteCond %{HTTPS} off
RewriteRu= le ^/(.*)$ https://www.yourwebsite.com/$1 [R,L]
</VirtualHost&g= t;


now the https vhost:

<VirtualHost *:4= 43>
ServerAdmin webmaster@yourwebsite.com
DocumentRoot d:/= apache/htdocs/yourwebsite
ServerName www.yourwebsite.com
Serv= erAlias yourwebsite.com

SSLEngine on
SSLCertificateFile= c:/mptn/etc/ssl/uacme/www.yourwebsite.com/cert.pem
SSLCertificate= KeyFile c:/mptn/etc/ssl/uacme/private/www.yourwebsite.com/key.pem
=
</VirtualHost>


you don't need the chain ce= rtificate since UACME create automatically a certificate with also the = chain
certificate inside it


to verify your certif= icate you can use this web tool:

https://decoder.link/sslche= cker/www.yourwebsite.com/443

that's all

massimo

Il 23/07/2024 12:20, Massimo S. ha scritto:
> I= use Paul's port of UACME, it can renew the www.yourwebsite.com (3rd le= vel) cert and both the 2nd level
> yourwebsite.com at the same = time too.
>
>
> This is a simple reissue of jus= t www.yourwebsite.. certificate.
> I run uacme in a separate tr= ee, not under the apache tree, i don't suggest
> you to run it = under \apache tree.
> You need port 80 (HTTP) open on your webs= erver for this operation.
> You need to create all these paths = you can see down here.
> You don't need Let's Encrypt chain cer= tificates files, since uacme already by it's own
> create a cer= tificate with the chain certificate inside of the .cert, so
> y= ou have always the latest chain certificate from Let's Encrypt automati= cally.
>
> I run the scripts scheduled once each 2 mont= hs (LE Certs only last 3 months),
> so in case of issues i stil= l have 1 month to fix them.
> **don't forget** to add a Call Sy= sSleep of about 10 seconds between a reissue
> and another (if = you runs tenths of renewals like me) or you can get problems,
>= i mean renewal that fails.
> In your script after the renewal/= s you can place the code to restart apache.
>
>
&g= t;
> renewal (issue) script:
>
> @attrib c:\mpt= n\etc\ssl\uacme\private\www.youwebsite.com\key.pem -R
> @copy c= :\mptn\etc\ssl\uacme\private\www.youwebsite.com\key=5Fold.pem
>= c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key=5Fold2.pem
&= gt; @copy c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key.pem
> c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key=5Fold.pem> @del c:\mptn\etc\ssl\uacme\private\www.youwebsite.com\key.pem /= N
> @attrib c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert.pem -= R
> @copy c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert=5Fold.p= em
> c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert=5Fold2.pem> @copy c:\mptn\etc\ssl\uacme\www.youwebsite.com\cert.pem c:\mpt= n\etc\ssl\uacme\www.youwebsite.com\cert=5Fold.pem
> @del c:\mpt= n\etc\ssl\uacme\www.youwebsite.com\cert.pem /N
> uacme issue ww= w.youwebsite.com -h hook=5Fyourwebsite=5Fcom.cmd 2>>d:\services\u= acme\re.log
>
>
>
> hook script:
&= gt;
> parse arg var1 var2 var3 var4 var5
> myfile =3D '= X:\apache\htdocs\yourwebsite\.well-known\acme-challenge\'||var4
&g= t; call SysFileDelete 'X:\apache\htdocs\yourwebsite\.well-known\acme-ch= allenge\'||var4
> rc=3D LINEOUT(myfile,var5)
>
>= ;
>
> i'm keeping 2 bkup of private keys + certs (you c= an see all those copies)
> hope it's all explained well
&g= t;
> massimo
>
>
> Il 22/07/2024 15:33,= Dan Napier ha scritto:
>> Has anyone installed let=E2=80=99= s Encrypt Certbot on OS2 .  What did you use ?
>>
= >> HTTPS is needed.  Or how are you installing the certs?>>
>> Dan Napier, MS, CIH
>>
>&g= t; DNA Industrial Hygiene
>>
>> 2520 Artesia Boul= evard
>>
>> Redondo Beach, CA 90278-3210
>= ;>
>> 310-644-1924 X 103
>>
>> CSLB= #773462
>>
>> DNA Industrial Hygiene 800-644-192= 4
>>
>
> =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D
> This message is sent to you because = you are subscribed to
>  the mailing list <ecs-isp@2ros= enthals.com>.
> To unsubscribe, E-mail to: <ecs-isp-off@2= rosenthals.com>
> To switch to the DIGEST mode, E-mail to &l= t;ecs-isp-digest@2rosenthals.com>
> To switch to the INDEX m= ode, E-mail to <ecs-isp-index@2rosenthals.com>
> Send adm= inistrative queries to  <ecs-isp-request@2rosenthals.com>> To subscribe (new addresses), E-mail to: <ecs-isp-on@2rosent= hals.com> and reply to the confirmation email.
> Web archive= s are publicly available at: http://lists.2rosenthals.com
>
> This list is hosted by Rosenthal & Rosenthal, LLC
> = P.O. Box 281, Deer Park, NY 11729-0281. Non-
> electronic commu= nications related to content
> contained in these messages shou= ld be directed
> to the above address. (CAN-SPAM Act of 2003)>
> =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-= =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D
>

=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D
This message is sent to you because you are subsc= ribed to
the mailing list <ecs-isp@2rosenthals.com>.
To= unsubscribe, E-mail to: <ecs-isp-off@2rosenthals.com>
To sw= itch to the DIGEST mode, E-mail to <ecs-isp-digest@2rosenthals.com&g= t;
To switch to the INDEX mode, E-mail to <ecs-isp-index@2rosen= thals.com>
Send administrative queries to <ecs-isp-request@2= rosenthals.com>
To subscribe (new addresses), E-mail to: <ec= s-isp-on@2rosenthals.com> and reply to the confirmation email.
= Web archives are publicly available at: http://lists.2rosenthals.com
This list is hosted by Rosenthal & Rosenthal, LLC
P.O= . Box 281, Deer Park, NY 11729-0281. Non-
electronic communication= s related to content
contained in these messages should be directe= d
to the above address. (CAN-SPAM Act of 2003)

=3D-=3D-= =3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D= -=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D
 

-- 
Certified Industrial Hygienist
Cer= tified Asbestos Consultant

Dan Napier, MS, CIH, CAC
92-= 0614 8/24/24
2520 Artesia Boulevard
Redondo Beach, CA 90278-3= 210
310-644-1924 x 103
CSLB 773462 ------=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444260-0-------- ------=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444501-1------ Content-Type: text/plain Content-Disposition: attachment; filename="prob1.txt" Content-Transfer-Encoding: quoted-printable Content-Length: 504 uacme.exe: challenge https://acme-v02.api.letsencrypt.org/acme/chall-v3= /38943333 6946/-1Wx1w failed with status invalid uacme.exe: the server reported the following error: { "type": "urn:ietf:params:acme:error:dns", "detail": "DNS problem: NXDOMAIN looking up TXT for =5Facme-challen= ge.ns1.dnac ih.com - check that a DNS record exists for this domain", "status": 400 } uacme.exe: failed to authorize order at https://acme-v02.api.letsencryp= t.org/acm e/order/1887586636/295703974986 ------=_=-_OpenGroupware_org_NGMime-3535701-1723831185.444501-1--------