ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Certbot

    Scheduled Pinned Locked Moved IT Discussion
    138 Posts 8 Posters 29.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Alex Sage @StrongBad
      last edited by

      @StrongBad said in Certbot:

      @alex.olynyk said in Certbot:

      I setup a CNAME internally because i gave owncloud a different name internally. owncloud.rose.internal

      Won't that cause issues? ownCloud requires DNS to be consistent between internal and external, doesn't it?

      I would think so....

      1 Reply Last reply Reply Quote 0
      • wirestyle22W
        wirestyle22
        last edited by wirestyle22

        Any ideas?

        1 Reply Last reply Reply Quote 0
        • alex.olynykA
          alex.olynyk
          last edited by

          can i post my DNS config so you can have a look?

          scottalanmillerS 1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @alex.olynyk
            last edited by

            @alex.olynyk said in Certbot:

            can i post my DNS config so you can have a look?

            Yes

            1 Reply Last reply Reply Quote 0
            • wirestyle22W
              wirestyle22
              last edited by

              I'd appreciate any information right now

              1 Reply Last reply Reply Quote 0
              • alex.olynykA
                alex.olynyk
                last edited by

                0_1464201682618_Capture.PNG

                DashrenderD 1 Reply Last reply Reply Quote 0
                • wirestyle22W
                  wirestyle22
                  last edited by wirestyle22

                  I'm in a different situation. I'm hosting my OwnCloud server with Vultr on CentOS 7. I followed the directions but I get the errors that I listed above. Unsure what I need to do on CentOS.

                  1. Do I need to specify the ServerName or does CertBot make that irrelevant?
                  2. Do I need to setup a vhost or is the ssl.conf what I am supposed to use by default?
                  3. Is the failed authorization procedure due to Google or is it my settings?
                  alex.olynykA A 2 Replies Last reply Reply Quote 0
                  • alex.olynykA
                    alex.olynyk @wirestyle22
                    last edited by

                    @wirestyle22 I had to specify the servername
                    i used the ssl.conf default

                    1 Reply Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @alex.olynyk
                      last edited by

                      @alex.olynyk said in Certbot:

                      0_1464201682618_Capture.PNG

                      Where is your Roseradiology.com DNS domain? I don't see it in the list.

                      1 Reply Last reply Reply Quote 0
                      • alex.olynykA
                        alex.olynyk
                        last edited by

                        we dont have one. its just rose.internal

                        1 Reply Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender
                          last edited by

                          You need to create one. That's what allows you to use different, internal IPs for that roseradiology.com domain while inside your network.

                          that's what makes split horizon DNS.

                          A 1 Reply Last reply Reply Quote 0
                          • A
                            Alex Sage @Dashrender
                            last edited by Alex Sage

                            @Dashrender But Why? Why host any roseradiology.com DNS locally? Speed?

                            StrongBadS 1 Reply Last reply Reply Quote 1
                            • StrongBadS
                              StrongBad @Alex Sage
                              last edited by

                              @aaronstuder I am confused here, too. I don't see where the benefit is in this setup.

                              A 1 Reply Last reply Reply Quote 0
                              • A
                                Alex Sage @StrongBad
                                last edited by Alex Sage

                                @StrongBad The only thing I can think of is speed? Maybe it's a bit faster? However many routers have loopback NAT, so no difference there.

                                JaredBuschJ 1 Reply Last reply Reply Quote -1
                                • A
                                  Alex Sage @wirestyle22
                                  last edited by

                                  @wirestyle22 Can you start a new topic? It's hard to keep track here.

                                  1 Reply Last reply Reply Quote 0
                                  • A
                                    Alex Sage
                                    last edited by

                                    @alex-olynyk remove roseradiology.com from your local DNS complerely, then try again after flushing DNS. I bet it works.

                                    alex.olynykA 1 Reply Last reply Reply Quote 1
                                    • alex.olynykA
                                      alex.olynyk @Alex Sage
                                      last edited by

                                      @aaronstuder removed and flushed but no change

                                      A 1 Reply Last reply Reply Quote 0
                                      • A
                                        Alex Sage @alex.olynyk
                                        last edited by Alex Sage

                                        @alex.olynyk Did you remove all records, or just the owncloud one? You have to remove the whole domain.

                                        alex.olynykA 1 Reply Last reply Reply Quote 0
                                        • DashrenderD
                                          Dashrender
                                          last edited by

                                          Unless I completely misunderstood something in the beginning, the OP indicated that he had roseradiology.com on his internal DNS as well. So working from that, I gave the above response.

                                          Now that we see that he does not have that already in place, I would agree, avoid it if at all possible - but you have to make sure things work first.

                                          This means making sure his firewall/router supports hairpin routing.

                                          It works as follows:
                                          an internal client makes a request for the IP to OC.roseradiology.com, which is responded to from the internet DNS server with an IP on his firewall (assuming the OP is using NATing).
                                          The client then tries to connect to that IP, which is on the outside of his firewall.
                                          The firewall gets a packet and realizes that it has a rule that says this packet needs to go back inside the network to the designated internal IP (cisco PIX firewalls can NOT do this). Assuming this works - the traffic is sent back inside the network
                                          and all is fine.

                                          alex.olynykA 1 Reply Last reply Reply Quote 0
                                          • alex.olynykA
                                            alex.olynyk @Alex Sage
                                            last edited by

                                            @aaronstuder 0_1464206471496_Capture.PNG
                                            removed domain

                                            1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 7
                                            • 4 / 7
                                            • First post
                                              Last post