Certbot

From NixOS Wiki
Revision as of 13:37, 29 August 2022 by imported>Onny (Initial page with simple example)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Installation

Install certbot in your current environment

# nix-env -iA nixos.certbot

Usage

DNS challenge

The following command will generate a SSL certificate key pair for the domain example.org using the DNS authentication mechanism. After running this command, you'll get asked by the script to paste a specific key into your DNS records for example.org.

# certbot certonly --manual --preferred-challenges dns -d example.org --register-unsafely-without-email --agree-tos

If everthing went well you'll have the certificate and key file stored as /etc/letsencrypt/live/example.org/fullchain.pem and /etc/letsencrypt/live/example.org/privkey.pem