Update README.md
This commit is contained in:
parent
f98b51881f
commit
79a24f86c1
|
|
@ -1,3 +1,25 @@
|
||||||
### acme.include
|
### acme.include
|
||||||
|
|
||||||
Include for which redirects request which are actually for the _ACME/Let's encrypt_ to the port the ACME-worker is listennix on
|
Include which redirects requests which are actually for the _ACME/Let's encrypt_ .
|
||||||
|
This way you can have apache running on port 80, but still process request from the _Let's encrypt_ service
|
||||||
|
which also come to port 80.
|
||||||
|
|
||||||
|
Example apache definition for a typical HTTP/80-virtual server would look like this now:
|
||||||
|
```
|
||||||
|
<VirtualHost cdn.mh3000.net:80>
|
||||||
|
Include /etc/apache2/vhosts.d/acme.include
|
||||||
|
RedirectMatch permanent ^(.*)$ https://cdn.mh3000.net/
|
||||||
|
TransferLog "/var/log/apache2/access_cdnmh3000-nonssl.log"
|
||||||
|
</VirtualHost>
|
||||||
|
```
|
||||||
|
|
||||||
|
This works like this:
|
||||||
|
- the include redirects request to the /.well-known/acme-challenge path to localhost:9432 where your
|
||||||
|
ACME-worker shoud listen for requests
|
||||||
|
- All other requests will be redirect to the SSL-version of your site.
|
||||||
|
|
||||||
|
E.g. with `acme.sh` you must specify then parameters `[OTHER STUFF] --issue --standalone --httpport 9432 -d [DOMAIN]`
|
||||||
|
at initial certificate request. Renews will automatically the also use the alternate httpport.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue