> On Oct 17, 2016, at 10:19 AM, Michael Klishin <
mkli...@pivotal.io> wrote:
>
> If you want to use an existing certificate, then simply skip all the parts that set up a CA and generate a self-signed CA/certificates/keys.
>
> You can disable non-TLS listeners, see
http://www.rabbitmq.com/networking.html.
Not having luck yet. I tried to drop the example and tweaked the paths in /etc/rabbitmq/rabbitmq-env.conf
:/etc/rabbitmq$ cat rabbitmq-env.conf
# Defaults to rabbit. This can be useful if you want to run more than one node
# per machine - RABBITMQ_NODENAME should be unique per erlang-node-and-machine
# combination. See the clustering on a single machine guide for details:
#
http://www.rabbitmq.com/clustering.html#single-machine
#NODENAME=rabbit
# By default RabbitMQ will bind to all interfaces, on IPv4 and IPv6 if
# available. Set this if you only want to bind to one network interface or#
# address family.
#NODE_IP_ADDRESS=127.0.0.1
# Defaults to 5672.
#NODE_PORT=5672
[
{rabbit, [
{ssl_listeners, [5671]},
{ssl_options, [{cacertfile,"/etc/letsencrypt/live/
xxx.yyy.com/fullchain.pem"},
{certfile,"/etc/letsencrypt/live/
xxx.yyy.com/cert.pem"},
{keyfile,"/etc/letsencrypt/live/
xxx.yyy.com/privkey.pem"},
{verify,verify_peer},
{fail_if_no_peer_cert,false}]}
]}
].
But that seems to be a bad file syntax?
:/etc/rabbitmq$ sudo systemctl restart rabbitmq-server
Job for rabbitmq-server.service failed because the control process exited with error code. See "systemctl status rabbitmq-server.service" and "journalctl -xe" for details.
:/etc/rabbitmq$ sudo journalctl -flu rabbitmq-server
-- Logs begin at Sun 2016-10-16 12:55:49 CDT. --
Oct 17 13:30:38 server5 systemd[1]: Starting RabbitMQ Messaging Server...
Oct 17 13:30:38 server5 rabbitmq[30184]: /usr/lib/rabbitmq/bin/rabbitmq-server-wait: 15: [: missing ]
Oct 17 13:30:38 server5 systemd[1]: rabbitmq-server.service: Control process exited, code=exited status=2
Oct 17 13:30:38 server5 systemd[1]: Failed to start RabbitMQ Messaging Server.
Oct 17 13:30:38 server5 systemd[1]: rabbitmq-server.service: Unit entered failed state.
Oct 17 13:30:38 server5 systemd[1]: rabbitmq-server.service: Failed with result 'exit-code’.
I’m running the stock version of rabbitmq (3.5.7) on Ubuntu 16.04. Could there be a version/documentation mismatch?