Hello together,
at first: thanks for this fantastic XMPP server software!
Im using Let's encrypt certificates and wanted to point to the pem files:
ssl = {
key = "/etc/letsencrypt/live/
myserver.ddns.net/privkey.pem";
certificate =
"/etc/letsencrypt/live/
myserver.ddns.net/fullchain.pem";
}
I've created a group "le-certs", did "chown -R root:le-certs
/etc/letsencrypt/" and did "chmod 440" for fullchain1.pem and
privkey1.pem in "/etc/letsencrypt/archive/
myserver.ddns.net".
Unfortunately I always get service status errors this way:
Oct 16 02:22:43 myserver prosody[2691]: Starting Prosody XMPP Server:
prosody.
Oct 16 02:22:43 myserver systemd[1]: Started LSB: Prosody XMPP Server.
Oct 16 02:22:43 myserver prosody[2701]: certmanager: SSL/TLS: Failed to
load '/etc/letsencrypt/live/
myserver.ddns.net/privkey.pem': Pre...
dns.net)
Oct 16 02:22:43 myserver prosody[2701]:
conference.myserver.ddns.net:tls: Unable to initialize TLS: error
loading private key (system lib)
Oct 16 02:22:43 myserver prosody[2701]: certmanager: SSL/TLS: Failed to
load '/etc/letsencrypt/live/
myserver.ddns.net/privkey.pem': Pre...
dns.net)
Oct 16 02:22:43 myserver prosody[2701]:
conference.myserver.ddns.net:tls: Unable to initialize TLS: error
loading private key (system lib)
Oct 16 02:22:43 myserver prosody[2701]: certmanager: SSL/TLS: Failed to
load '/etc/letsencrypt/live/
myserver.ddns.net/privkey.pem': Che...
dns.net)
Oct 16 02:22:43 myserver prosody[2701]: myserver.ddns.net:tls: Unable to
initialize TLS: error loading private key (Permission denied)
Oct 16 02:22:43 myserver prosody[2701]: certmanager: SSL/TLS: Failed to
load '/etc/letsencrypt/live/
myserver.ddns.net/privkey.pem': Pre...
dns.net)
Oct 16 02:22:43 myserver prosody[2701]: myserver.ddns.net:tls: Unable to
initialize TLS: error loading private key (system lib)
If I copy the Lets Encrypt scripts to /etc/prosody/certs/ everything
works fine.
Does
https://groups.google.com/forum/?hl=en#!topic/prosody-users/TmMW2Er9U7Q
mean that I have to update the certificates manually every three months?
Thanks alot
sj7