Compare commits

..

4 Commits

Author SHA1 Message Date
c9253b5d08 Fix format 2026-01-02 22:14:00 +01:00
1770301a87 Add requirement augeas-libs 2026-01-01 22:45:25 +01:00
33754a20fc Add dh params size 2026-01-01 21:02:12 +01:00
9e8290b7df Add certonly non interactive options 2026-01-01 20:39:58 +01:00
2 changed files with 4 additions and 6 deletions

View File

@@ -25,5 +25,3 @@ add_header Cross-Origin-Resource-Policy "same-site"
add_header Permissions-Policy "geolocation=(), camera=(), microphone=()" always;
add_header Server "webserver" always;
add_header X-Robots-Tag "noindex, nofollow" always;

View File

@@ -10,7 +10,7 @@ URL: https://git.netoik.io/samuel/netoik-rp
Source0: %{name}-%{version}.tar.gz
Buildarch: noarch
BuildRequires: make
Requires: nginx python3 python-devel augeas-devel gcc openssl
Requires: nginx python3 python-devel (augeas-devel or augeas-libs) gcc openssl
%description
Install the reverse proxy called nginx with a predefined configuration and with TLS certificates attached to netoik.io
@@ -32,16 +32,16 @@ if [ $1 == 1 ]; then
# Create virutal env with certbot
%{_bindir}/env python3 -m venv /opt/certbot
/opt/certbot/bin/pip install --upgrade pip certbot certbot-nginx certbot-dns-ovh
%{_bindir}/env ln --symbolic --force --target-directory %{_sbindir} /opt/certbot/bin/certbot
%{_bindir}/env ln --symbolic --force --target-directory %{_sbindir} /opt/certbot/bin/certbot
# Create certificate with certbot
%{_bindir}/env certbot certonly --dns-ovh --dns-ovh-credentials "%{_sysconfdir}/certbot/ovh.ini" -d "*.netoik.io" -d "*.samuel-campos.fr"
%{_bindir}/env certbot certonly --non-interactive --agree-tos --email "samuel.campos@netoik.io" --dns-ovh --dns-ovh-credentials "%{_sysconfdir}/certbot/ovh.ini" -d "*.netoik.io" -d "*.samuel-campos.fr"
# Add crontab rule for automatic renew
%{_bindir}/env printf "\nAutomatic certbot renew\n0 12 * * * root sleep $((RANDOM % 3600)) && certbot renew -q\n" >> %{_sysconfdir}/crontab
# Create ssl dh params
%{_bindir}/env openssl dhparam -out %{_sysconfdir}/letsencrypt/ssl-dhparams.pem
%{_bindir}/env openssl dhparam -out %{_sysconfdir}/letsencrypt/ssl-dhparams.pem 2048
# Stop nginx to be sure changes are taken in account
%{_bindir}/env systemctl stop nginx