# new xyzca as both mail and website server:# better switch to root user instead of using `sudo acme.sh ...`?# https://github.com/acmesh-official/acme.sh/wiki/sudosudo -i
# I guess maybe register if first time on the server? not sure
acme.sh --home /etc/acme.sh --register-account -m [email protected]# need to change from `server_name localhost;` to `server_name flylightning.xyz;` in /etc/nginx/nginx.conf# when add new DNS subdomain, maybe sometimes maybe need --force, also need `acme.sh --home /etc/acme.sh --cron --force` afterwards, not sure why
acme.sh --home /etc/acme.sh --issue --nginx -d flylightning.xyz -d git.flylightning.xyz -d mirrors.flylightning.xyz -d mail.flylightning.xyz
acme.sh --home /etc/acme.sh --install-cert -d flylightning.xyz --key-file /etc/postfix/flylightning.key --fullchain-file /etc/postfix/flylightning.pem --reloadcmd "systemctl force-reload nginx"
# if only email server, if no webserver# better switch to root user instead of using `sudo acme.sh ...`?# https://github.com/acmesh-official/acme.sh/wiki/sudosudo -i
# I guess maybe register if first time on the server? not sure
acme.sh --home /etc/acme.sh --register-account -m [email protected]# acme.sh default zerossl does not support port 443 alpn mode, need to use letsencrypt but still has issues see https://github.com/acmesh-official/acme.sh/issues/4802# so I choose to use port 80 builtin standalone webserver, need open 80 port, also need socat# https://github.com/acmesh-official/acme.sh/wiki/How-to-issue-a-cert
acme.sh --home /etc/acme.sh --issue --standalone -d mail2.flylightning.xyz
acme.sh --home /etc/acme.sh --install-cert -d mail2.flylightning.xyz --key-file /etc/postfix/flylightning.key --fullchain-file /etc/postfix/flylightning.pem
@shc #10 好的,感谢大佬推荐,如果搭建过程有问题可以向你请教吗?
好的呀
mark一下,还得考虑换主机重装的便利性
bd
https://www.nodeseek.com/post-497791-1#10:
部分配置文件:
我现在个人网站和邮局在一个小鸡上,所以会涉及到nginx,nginx配置见https://git.flylightning.xyz/config_local_arch/tree/etc/nginx/nginx.conf?h=ca&id=8beb5edc064c05487989b54ec76a0ca1cd301497,小鸡以前单纯邮局是不需要nginx的,acme.sh配置也会更简单。现在的acme.sh命令我自己的笔记也乱的很,你要觉得有用就看一下吧:
# new xyzca as both mail and website server: # better switch to root user instead of using `sudo acme.sh ...`? # https://github.com/acmesh-official/acme.sh/wiki/sudo sudo -i # I guess maybe register if first time on the server? not sure acme.sh --home /etc/acme.sh --register-account -m [email protected] # need to change from `server_name localhost;` to `server_name flylightning.xyz;` in /etc/nginx/nginx.conf # when add new DNS subdomain, maybe sometimes maybe need --force, also need `acme.sh --home /etc/acme.sh --cron --force` afterwards, not sure why acme.sh --home /etc/acme.sh --issue --nginx -d flylightning.xyz -d git.flylightning.xyz -d mirrors.flylightning.xyz -d mail.flylightning.xyz acme.sh --home /etc/acme.sh --install-cert -d flylightning.xyz --key-file /etc/postfix/flylightning.key --fullchain-file /etc/postfix/flylightning.pem --reloadcmd "systemctl force-reload nginx"我有一个backup mx server,但那个配置文件更乱,因为小鸡有俩个ipv4。你想看这个小鸡的部分配置文件的话看这个branch:https://git.flylightning.xyz/config_local_arch/tree/?h=ib。这个小鸡只有邮局,没有网站,所以不涉及nginx,所以acme.sh命令更简单:
# if only email server, if no webserver # better switch to root user instead of using `sudo acme.sh ...`? # https://github.com/acmesh-official/acme.sh/wiki/sudo sudo -i # I guess maybe register if first time on the server? not sure acme.sh --home /etc/acme.sh --register-account -m [email protected] # acme.sh default zerossl does not support port 443 alpn mode, need to use letsencrypt but still has issues see https://github.com/acmesh-official/acme.sh/issues/4802 # so I choose to use port 80 builtin standalone webserver, need open 80 port, also need socat # https://github.com/acmesh-official/acme.sh/wiki/How-to-issue-a-cert acme.sh --home /etc/acme.sh --issue --standalone -d mail2.flylightning.xyz acme.sh --home /etc/acme.sh --install-cert -d mail2.flylightning.xyz --key-file /etc/postfix/flylightning.key --fullchain-file /etc/postfix/flylightning.pem因为一鸡多用,所以nftables.conf也乱的很。第一个小鸡:https://git.flylightning.xyz/config_local_arch/tree/etc/nftables.conf?h=ca&id=9d785f1dedab279d0d7ea111b5e845b2bfd27ae5。第二个小鸡:https://git.flylightning.xyz/config_local_arch/tree/etc/nftables.conf?h=ib&id=fcf2d80580c8cea99e2e9e4f059374c39804a8c4。其实也就打开几个端口,但我手快复制了网址也就贴上来了。虽说也就几个端口,但坑也很多,主要坑在商家,见:https://www.nodeseek.com/post-239409-4#31:
网上很多教程,我推荐这几个,我就是靠这几个链接花了几天功夫一点点折腾出来的:
这个可以用来测试你的邮局:https://mxtoolbox.com/SuperTool.aspx
废话太多了,我歪曲理解了一下这个帖子https://www.nodeseek.com/post-511452-1,我废话这么多很符合自慰的特征,所以最后谢谢大家欣赏我的自慰。