{"id":2377,"date":"2022-06-01T19:44:39","date_gmt":"2022-06-01T23:44:39","guid":{"rendered":"https:\/\/matthannan.net\/blog\/?p=2377"},"modified":"2022-06-01T21:45:10","modified_gmt":"2022-06-02T01:45:10","slug":"lets-encrypt-v3","status":"publish","type":"post","link":"https:\/\/matthannan.net\/blog\/lets-encrypt-v3\/","title":{"rendered":"Let&#8217;s Encrypt V3"},"content":{"rendered":"\n<p>The Acme script that I use, like many people out there, to keep my Let&#8217;s Encrypt TLS\/SSL certificate updated has recently had a breaking change of an upgrade. Namecheap, my hosting provider, is using an older version of OpenSSL. While this does not sound awesome, it is the upgrade from the previous version of OpenSSL that had a mega bug in it, so this isn&#8217;t too terrible. Still, not great and I hope that NameCheap gets on the stick and upgrades soon.<\/p>\n\n\n\n<p>Anyway, the Acme is busted. Because of the older OpenSSL installed, it needs an extra argument passed in the command to point back from a domain called ZeroSSL.com to letsencrypt. I am still searching for the killer tutorial to get me back to where we were three months ago. Honestly, the previous install was working so well that I&#8217;ve forgotten all about what a plain pain in the ass this stuff is.<\/p>\n\n\n\n<p>Here are the commands that I am using now. I fully nuked my previous Acme install and reinstalled fresh. <\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>user@host$ .acme.sh\/acme.sh --issue --server letsencrypt -d www.nycnyne.net -d nycnyne.net -w \/home\/swephc\/public_html\/nycnyne.net\/\nuser@host$ .acme.sh\/acme.sh --issue --server letsencrypt -d www.matthannan.net -d matthannan.net -w \/home\/swephc\/public_html\/<\/code><\/pre>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Acme script that I use, like many people out there, to keep my Let&#8217;s Encrypt TLS\/SSL certificate updated has recently had a breaking change of an upgrade. Namecheap, my hosting provider, is using an older version of OpenSSL. While &hellip; <a href=\"https:\/\/matthannan.net\/blog\/lets-encrypt-v3\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[5],"tags":[616,368,404,367],"class_list":["post-2377","post","type-post","status-publish","format-standard","hentry","category-geek","tag-certificates","tag-lets-encrypt","tag-royal-pita","tag-ssl"],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p2NxlE-Cl","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"jetpack-related-posts":[{"id":1257,"url":"https:\/\/matthannan.net\/blog\/ssl-with-lets-encrypt-on-namecheap\/","url_meta":{"origin":2377,"position":0},"title":"SSL with Let&#8217;s Encrypt on Namecheap","author":"matthannan","date":"24 November 2017","format":false,"excerpt":"My hosting provider does not fully support Let's Encrypt for free SSL certificates. This site shows how to set it up manually. (edit) It worked! I have two domains on my host: matthannan.net and nycnyne.net, which is my forum site for my old friends now scattered. I enabled the 1-year-free\u2026","rel":"","context":"In &quot;Geek&quot;","block_context":{"text":"Geek","link":"https:\/\/matthannan.net\/blog\/category\/geek\/"},"img":{"alt_text":"secure lock","src":"https:\/\/i0.wp.com\/matthannan.net\/blog\/wp-content\/uploads\/2017\/11\/secure.png?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":1683,"url":"https:\/\/matthannan.net\/blog\/lets-encrypt-again-part-3\/","url_meta":{"origin":2377,"position":1},"title":"Let&#8217;s Encrypt, again, Part 3","author":"matthannan","date":"20 November 2019","format":false,"excerpt":"Another 3 months has past and I needed to renew my certs. The previous method for taking care of NycNyne is still a relatively simple one liner, but matthannan.net continues to be a nightmare. Well, a hassle, anyway. I went with the links in the Part 2 of this series\u2026","rel":"","context":"In &quot;Geek&quot;","block_context":{"text":"Geek","link":"https:\/\/matthannan.net\/blog\/category\/geek\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1605,"url":"https:\/\/matthannan.net\/blog\/lets-encrypt-again\/","url_meta":{"origin":2377,"position":2},"title":"Let&#8217;s Encrypt, again","author":"matthannan","date":"18 August 2019","format":false,"excerpt":"This has become buried at nycnyne.net, so I wanted to get this added here. Three more months and I am playing with Let's Encrypt at Namecheap again. I can get nycnyne.net working again with this one-liner and a copy\/paste the key to the cPanel. acme.sh --issue -d nycnyne.net -d www.nycnyne.net\u2026","rel":"","context":"In &quot;Geek&quot;","block_context":{"text":"Geek","link":"https:\/\/matthannan.net\/blog\/category\/geek\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":1608,"url":"https:\/\/matthannan.net\/blog\/lets-encrypt-again-part-2\/","url_meta":{"origin":2377,"position":3},"title":"Let&#8217;s Encrypt, again, Part 2","author":"matthannan","date":"18 August 2019","format":false,"excerpt":"This site gave me a good starting point. I ran the commands in my WLS Debian instance and then uploaded the keys via cPanel copy & paste, per this site starting at Step 9. I am a little concerned about this, as matthannan.net is, basically, what everything runs off of,\u2026","rel":"","context":"In &quot;Geek&quot;","block_context":{"text":"Geek","link":"https:\/\/matthannan.net\/blog\/category\/geek\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/matthannan.net\/blog\/wp-content\/uploads\/2019\/08\/LE_mhnet.png?resize=350%2C200","width":350,"height":200},"classes":[]},{"id":2478,"url":"https:\/\/matthannan.net\/blog\/more-lets-encrypt-v3-part-b-subparagraph-g\/","url_meta":{"origin":2377,"position":4},"title":"More Let&#8217;s Encrypt V3, Part B, Subparagraph G","author":"matthannan","date":"31 August 2022","format":false,"excerpt":"Well, it has been three months since I last had to wrestle with Let's Encrypt certs. As expected, they did not auto-renew. I issued the commands found in the previous post on this topic and noticed something. [name@server ~]$ .acme.sh\/acme.sh --issue --server letsencrypt -d www.nycnyne.net -d nycnyne.net -w \/home\/name\/public_html\/nycnyne.net\/ [Wed\u2026","rel":"","context":"In &quot;Geek&quot;","block_context":{"text":"Geek","link":"https:\/\/matthannan.net\/blog\/category\/geek\/"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":2259,"url":"https:\/\/matthannan.net\/blog\/synology-nas-vpn-server\/","url_meta":{"origin":2377,"position":5},"title":"Synology NAS VPN Server","author":"matthannan","date":"9 May 2021","format":false,"excerpt":"It has been a long while since I wrote about VPN servers. This is because of the change of job, and then working from home for over a year because of COVID-19. But I have kept playing with the technology over the years. The old SoftEther VPN is long gone.\u2026","rel":"","context":"In &quot;Geek&quot;","block_context":{"text":"Geek","link":"https:\/\/matthannan.net\/blog\/category\/geek\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/matthannan.net\/blog\/wp-content\/uploads\/2021\/05\/image-2.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/matthannan.net\/blog\/wp-content\/uploads\/2021\/05\/image-2.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/matthannan.net\/blog\/wp-content\/uploads\/2021\/05\/image-2.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/posts\/2377","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/comments?post=2377"}],"version-history":[{"count":2,"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/posts\/2377\/revisions"}],"predecessor-version":[{"id":2381,"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/posts\/2377\/revisions\/2381"}],"wp:attachment":[{"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/media?parent=2377"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/categories?post=2377"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/matthannan.net\/blog\/wp-json\/wp\/v2\/tags?post=2377"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}