MRatWork Forum by Mustafa Ramadhan

Sawo Project - Kloxo-MR Discussions => Kloxo-MR Bugs and Requests => Topic started by: Spacedust on 2016-05-04, 11:58:24

Title: letsencrypt installer fails
Post by: Spacedust on 2016-05-04, 11:58:24
Checking for new version...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Requesting root privileges to run letsencrypt...
   /root/.local/share/letsencrypt/bin/letsencrypt --quiet
Version: 1.1-20080819
Missing command line flags. For non-interactive execution, you will need to specify a plugin on the command line.  Run with '--help plugins' to see a list of options, and see https://eff.org/letsencrypt-plugins for more detail on what the plugins do and how to use them.
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-04, 12:32:46
Checking for new version...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Requesting root privileges to run letsencrypt...
   /root/.local/share/letsencrypt/bin/letsencrypt --quiet
Version: 1.1-20080819
Missing command line flags. For non-interactive execution, you will need to specify a plugin on the command line.  Run with '--help plugins' to see a list of options, and see https://eff.org/letsencrypt-plugins for more detail on what the plugins do and how to use them.

No. It's work.

Try 'letsencrypt-auto --verbose'.
Title: Re: letsencrypt installer fails
Post by: Spacedust on 2016-05-04, 12:36:08
It worked from panel ;)
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-08, 03:20:31
i saw the "letsencrypt" menu exist, i try to klik "add" button, but got error message: "Create Certificate failed".


so what i must do?

i must run:
$ git clone https://github.com/letsencrypt/letsencrypt
$ cd letsencrypt
$ ./letsencrypt-auto --help

or kloxo-mr 7 do it automatic?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-08, 03:49:47
i saw the "letsencrypt" menu exist, i try to klik "add" button, but got error message: "Create Certificate failed".


so what i must do?

i must run:
$ git clone https://github.com/letsencrypt/letsencrypt
$ cd letsencrypt
$ ./letsencrypt-auto --help

or kloxo-mr 7 do it automatic?
Go to 'admin > domains > (select one) > ssl configure > add lets encrypt' or 'admin > clients > (select one) > domains > (select one)> ssl configure > add lets encrypt'.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-08, 15:21:29
always get this error message (i try from 2 vps).

(https://dl.dropboxusercontent.com/u/1960706/rd/screenshot/lets01.png)
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-08, 18:40:13
Go to 'log manager' and investigate 'letsencrypt' log.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-09, 04:27:17
there's no letsencrypt log :-(

(https://dl.dropboxusercontent.com/u/1960706/rd/screenshot/log01.jpg)

here's my sysinfo:
Code: [Select]
A. Control Panel:
   - Kloxo-MR: 7.0.0.b-2016050403
   - Web: hiawatha-10.1.0-f.6.mr.el6.i686
   - PHP: php54s-5.4.43-1.ius.el6 (fpm mode)
B. Plateform:
   - OS: CentOS release 6.7 (Final) i686
   - Hostname: serv11.kombathost.com
C. Services:
   1. MySQL: MariaDB-server-10.0.25-1.el6.i686
   2. PHP:
      - Branch: php54-cli-5.4.45-1.ius.el6.i686
      - Multiple:
        * php52m-5.2.17-102.mr.el6
        * php53m-5.3.29-1.ius.el6
        * php54m-5.4.45-2.w6
        * php55m-5.5.32-1.ius.el6
        * php56m-5.6.18-1.ius.el6
        * php70m-7.0.3-1.w6
      - Used: --Use PHP Branch--
   3. Web Used: nginxproxy
     - Hiawatha: --unused--
     - Lighttpd: --uninstalled--
     - Nginx: nginx-1.10.0-1.el6.ngx.i386
     - Httpd: httpd-2.2.31-1.mr.el6.i386
       - PHP Type: php-fpm_event
   4. WebCache: none
     - ATS: --uninstalled--
     - Squid: --uninstalled--
     - Varnish: --uninstalled--
   5. Dns: nsd
     - Bind: --uninstalled--
     - DJBDns: --uninstalled--
     - NSD: nsd-4.1.9-1.mr.el6.i686
     - PowerDNS: --uninstalled--
     - Yadifa: --uninstalled--
   6. Mail: qmail-toaster-1.03-1.3.55.mr.el6.i386
      - pop3/imap4: courier-imap-toaster-4.1.2-1.3.18.mr.el6.i386
      - spam: bogofilter
D. Memory:
                total       used       free     shared    buffers     cached
   Mem:          1024        944         79         73          0        524
   -/+ buffers/cache:        419        604
   Swap:          512         66        445
E. Disk Space:
   Filesystem      Size  Used Avail Use% Mounted on
   /dev/simfs       75G   17G   59G  23% /
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-09, 06:41:59
Sorry, not release yet for it.

Use 'file manager' and go to 'admin > server > localhost > select /var/log/letsencrypt'
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-09, 10:19:05
there's no letsenscrypt log too :-(

(https://dl.dropboxusercontent.com/u/1960706/rd/screenshot/file01.png)
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-09, 10:36:57
Inform here 'letsencrypt-auto --verbose'.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-09, 11:30:37
Inform here 'letsencrypt-auto --verbose'.

Code: [Select]
[root@serv11 ~]# letsencrypt-auto --verbose
-bash: letsencrypt-auto: command not found

i think letsencrypt not run, how to running it?
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-09, 11:40:57
I also have problem with it, same error, erro log says:

Quote
2016-05-09 09:55:18,281:DEBUG:letsencrypt.main:Root logging level set at 20
2016-05-09 09:55:18,283:INFO:letsencrypt.main:Saving debug log to /var/log/letsencrypt/letsencrypt.log
2016-05-09 09:55:18,293:DEBUG:letsencrypt.main:letsencrypt version: 0.5.0
2016-05-09 09:55:18,293:DEBUG:letsencrypt.main:Arguments: ['--verbose']
2016-05-09 09:55:18,294:DEBUG:letsencrypt.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#apache,PluginEntryPoint#webroot,PluginEntryPoint#null,PluginEntryPoint#manual,PluginEntryPoint#standalone)
2016-05-09 09:55:18,305:DEBUG:letsencrypt.plugins.selection:Requested authenticator None and installer None
2016-05-09 09:55:24,891:DEBUG:letsencrypt.plugins.disco:Other error:(PluginEntryPoint#apache): Error parsing runtime variables
Traceback (most recent call last):
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/plugins/disco.py", line 104, in prepare
    self._initialized.prepare()
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt_apache/configurator.py", line 172, in prepare
    self.version)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt_apache/parser.py", line 70, in __init__
    raise errors.PluginError("Error parsing runtime variables")
PluginError: Error parsing runtime variables
2016-05-09 09:55:24,892:DEBUG:letsencrypt.plugins.selection:No candidate plugin
2016-05-09 09:55:24,892:DEBUG:letsencrypt.plugins.selection:Selected authenticator None and installer None
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-09, 12:01:24
Need install with 'sh /script/letsencrypt-installer'.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-09, 12:08:57
Need install with 'sh /script/letsencrypt-installer'.
Code: [Select]
Nothing to do
Checking for new version...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Requesting root privileges to run letsencrypt...
   /root/.local/share/letsencrypt/bin/letsencrypt --version
letsencrypt 0.5.0


And when in admin panel trying to create: Alert: Create Certificate failed
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-09, 12:25:56
Need install with 'sh /script/letsencrypt-installer'.


I have tried the results are successful,

Thanks master2...
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-09, 16:57:59
Need install with 'sh /script/letsencrypt-installer'.

great, work perfectly ;)

thanks Pak MR.

btw, untuk perpanjang sertifikat gimana ya? atau kloxo-MR 7 ini otomatis perpanjang?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-10, 02:04:36
Need install with 'sh /script/letsencrypt-installer'.

great, work perfectly ;)

thanks Pak MR.

btw, untuk perpanjang sertifikat gimana ya? atau kloxo-MR 7 ini otomatis perpanjang?
Sebenarnya hal ini belum selesai. Belum ada perpanjangan otomatis. Nantinya akan ada dengan sendirinya jika sudah tuntas.

Masih ada masalah jika pakai hiawatha sebagai webserver.
Title: Re: letsencrypt installer fails
Post by: NginxHolic on 2016-05-10, 03:12:38
Om Mustafa,

Bagaimana caranya menggunakan Letsencrypt untuk panel kloxo secara otomatis tanpa harus edit manual via SSH?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-10, 09:12:35
Pergi ke domain terkait dan pilih 'ssl configure > add lets encrypt'
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-10, 09:17:49
Sebenarnya hal ini belum selesai. Belum ada perpanjangan otomatis. Nantinya akan ada dengan sendirinya jika sudah tuntas.

Masih ada masalah jika pakai hiawatha sebagai webserver.

kalo manual perpanjang gimana caranya ya Pak?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-10, 09:20:44
Sebenarnya hal ini belum selesai. Belum ada perpanjangan otomatis. Nantinya akan ada dengan sendirinya jika sudah tuntas.

Masih ada masalah jika pakai hiawatha sebagai webserver.

kalo manual perpanjang gimana caranya ya Pak?
Butuh perpanjangan setelah 90 hari. Sementara belum ada. Nanti sudah akan otomatis perpanjangan oleh Kloxo-MR.
Title: Re: letsencrypt installer fails
Post by: NginxHolic on 2016-05-10, 09:52:17
Pergi ke domain terkait dan pilih 'ssl configure > add lets encrypt'

Om, misalnya saya pakai https://subdomain.domain.tld:7777
cara untuk merubah https pakai Letsencrypt adalah dengan tambahkan subdomain.domain.tld under admin account trus baru akses ke Letsencrypt itu ya?

Bagaimana jika saya aksesnya pakai IP address:7777 misalnya?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-10, 11:36:02
Letsencrypt tidak bisa untuk IP atau wildcard domains. Jika anda ingin untuk subdomain, tambahkan pada 'SAN' di domain dan kemudian gunakan feature 'add link'.
Title: Re: letsencrypt installer fails
Post by: NginxHolic on 2016-05-11, 05:10:18
Om Mustafa,

Apakah untuk saat ini hanya apache saja yang di support Letsencrypt?

Saya sudah coba bbrp hari ini tetap error.

Error lognya http://j.mp/1Ta6U0J
pass saya kirim PM.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-11, 05:22:59
saya pake nginx-proxy, lancar pake letsencrypt
Title: Re: letsencrypt installer fails
Post by: NginxHolic on 2016-05-11, 05:34:13
Iya om, saya pakai pure NGINX sayangnya. Apakah pengaruh ya.
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-11, 05:34:46
Saya hanya menemukan masalah pada hiawatha (kelihatannya bug) tapi tidak untuk hiawatha-proxy.
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-11, 05:36:57
Cara 'paling aman' untuk sementara, pindah ke apache, lakukan 'add lets encrypt' dan kemudian kembalikan ke semula (misalnya nginx).
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-11, 12:53:57
share dari saya,
saya coba di centos 6.x dgn nginx-proxy lancar,

saya coba di centos 5.x , switch ke web server apache, hiawatha-proxy, nginx-proxy tidak berhasil;

Code: [Select]
Creating virtual environment...
Running virtualenv with interpreter /usr/bin/python2.7
The --no-site-packages flag is deprecated; it is now the default behavior.
New python executable in /root/.local/share/letsencrypt/bin/python2.7
Also creating executable in /root/.local/share/letsencrypt/bin/python
Installing setuptools...............................done.
Installing pip...............................done.
Installing Python packages...
Had a problem while installing Python packages:
Collecting argparse==1.4.0 (from -r /tmp/tmp.eazMEc1952/letsencrypt-auto-requirements.txt (line 5))
/root/.local/share/letsencrypt/lib/python2.7/site-packages/pip/_vendor/requests/packages/urllib3/util/ssl_.py:315: SNIMissingWarning: An HTTPS request has been made, but the SNI (Subject Name Indication) extension to TLS is not available on this platform. This may cause the server to present an incorrect TLS certificate, which can cause validation failures. For more information, see https://urllib3.readthedocs.org/en/latest/security.html#snimissingwarning.
  SNIMissingWarning
  Downloading argparse-1.4.0-py2.py3-none-any.whl
Collecting pycparser==2.14 (from -r /tmp/tmp.eazMEc1952/letsencrypt-auto-requirements.txt (line 11))
  Downloading pycparser-2.14.tar.gz (223kB)
Collecting cffi==1.4.2 (from -r /tmp/tmp.eazMEc1952/letsencrypt-auto-requirements.txt (line 14))
  Downloading cffi-1.4.2.tar.gz (365kB)
    Complete output from command python setup.py egg_info:
    unable to execute 'gcc44': No such file or directory
    unable to execute 'gcc44': No such file or directory

        No working compiler found, or bogus compiler options
        passed to the compiler from Python's distutils module.
        See the error messages above.
        (If they are about -mno-fused-madd and you are on OS/X 10.8,
        see http://stackoverflow.com/questions/22313407/ .)

    ----------------------------------------
Command "python setup.py egg_info" failed with error code 1 in /tmp/pip-build-CydAeu/cffi
You are using pip version 8.0.3, however version 8.1.2 is available.
You should consider upgrading via the 'pip install --upgrade pip' command.
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-11, 13:46:13
Kelihatannya masalahnya pada versi python. Oleh karena itu sekarang sedang coba untuk ganti program letsencrypt-auto (berbasis python) dengan acme.sh (berbasis bash) sehingga saya berharap bisa compatible untuk CentOS 5 dan 6.

Sembari menunggu konfirmasi dengan 'pembuat' hiawatha tentang masalah gagal akses ke /.well-known.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-11, 15:17:45
Any solution?

Code: [Select]
Nothing to do
Checking for new version...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Requesting root privileges to run letsencrypt...
   /root/.local/share/letsencrypt/bin/letsencrypt --version
letsencrypt 0.5.0


And when in admin panel trying to create: Alert: Create Certificate failed

CentOS 5
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-11, 15:47:56
Any solution?

Code: [Select]
Nothing to do
Checking for new version...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Requesting root privileges to run letsencrypt...
   /root/.local/share/letsencrypt/bin/letsencrypt --version
letsencrypt 0.5.0


And when in admin panel trying to create: Alert: Create Certificate failed

CentOS 5
Using 'file manager', go to '/var/log/letsencrypt' and investigate log file.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-11, 16:02:40
Any solution?

And when in admin panel trying to create: Alert: Create Certificate failed

CentOS 5

check log, on my problem, when i check log there's error on webmail.domain.tld, so i remove webmail.domain.tld from <textarea> when create letsenscrypt certificate.
Title: Re: letsencrypt installer fails
Post by: NginxHolic on 2016-05-11, 16:12:22
Kelihatannya masalahnya pada versi python. Oleh karena itu sekarang sedang coba untuk ganti program letsencrypt-auto (berbasis python) dengan acme.sh (berbasis bash) sehingga saya berharap bisa compatible untuk CentOS 5 dan 6.

Sembari menunggu konfirmasi dengan 'pembuat' hiawatha tentang masalah gagal akses ke /.well-known.

Apakah hal ini termasuk untuk kasus untuk saya om? Atau memang tidak bisa untuk pure nginx?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-11, 16:15:41
Kelihatannya masalahnya pada versi python. Oleh karena itu sekarang sedang coba untuk ganti program letsencrypt-auto (berbasis python) dengan acme.sh (berbasis bash) sehingga saya berharap bisa compatible untuk CentOS 5 dan 6.

Sembari menunggu konfirmasi dengan 'pembuat' hiawatha tentang masalah gagal akses ke /.well-known.

Apakah hal ini termasuk untuk kasus untuk saya om? Atau memang tidak bisa untuk pure nginx?
Saya hanya menemukan masalah pada hiawatha.

Gunakan 'file manager', pergi ke '/var/log/letsencrypt' and periksa log file.
Title: Re: letsencrypt installer fails
Post by: KloxoLittleFish on 2016-05-11, 17:59:24
in - Httpd: httpd-2.2.31-1.mr.el6.x86_64
       - PHP Type: php-fpm_event
works?

log (mydomain is ok domain) :
Quote
2016-05-11 16:04:09,725:INFO:letsencrypt.reporter:Reporting to user: The following errors were reported by the server:

Domain: mydomain.org
Type:   unauthorized
Detail: Invalid response from http://mydomain.org/.well-known/acme-challenge/9ZL8tFvUv7KkANKhd93Lr9LNVhK1Rvw8elfN4EJbrug [37.59.6.154]: 404

To fix these errors, please make sure that your domain name was entered correctly and the DNS A record(s) for that domain contain(s) the right IP address.
2016-05-11 16:04:09,725:INFO:letsencrypt.auth_handler:Cleaning up challenges
2016-05-11 16:04:09,725:DEBUG:letsencrypt.plugins.webroot:Removing /var/run/letsencrypt/.well-known/acme-challenge/9ZL8tFvUv7KkANKhd93Lr9LNVhK1Rvw8elfN4EJbrug
2016-05-11 16:04:09,726:DEBUG:letsencrypt.plugins.webroot:All challenges cleaned up, removing /var/run/letsencrypt/.well-known/acme-challenge
2016-05-11 16:04:09,727:DEBUG:letsencrypt.main:Exiting abnormally:
Traceback (most recent call last):
  File "/root/.local/share/letsencrypt/bin/letsencrypt", line 11, in <module>
    sys.exit(main())
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/main.py", line 692, in main
    return config.func(config, plugins)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/main.py", line 509, in obtain_cert
    _, action = _auth_from_domains(le_client, config, domains, lineage)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/main.py", line 93, in _auth_from_domains
    lineage = le_client.obtain_and_enroll_certificate(domains)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/client.py", line 274, in obtain_and_enroll_certificate
    certr, chain, key, _ = self.obtain_certificate(domains)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/client.py", line 246, in obtain_certificate
    self.config.allow_subset_of_names)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/auth_handler.py", line 74, in get_authorizations
    self._respond(resp, best_effort)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/auth_handler.py", line 131, in _respond
    self._poll_challenges(chall_update, best_effort)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/auth_handler.py", line 195, in _poll_challenges
    raise errors.FailedChallenges(all_failed_achalls)
FailedChallenges: Failed authorization procedure. mydomain.org (http-01): urn:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://mydomain.org/.well-known/acme-challenge/9ZL8tFvUv7KkANKhd93Lr9LNVhK1Rvw8elfN4EJbrug [37.59.6.154]: 404

In the domain directory it is not creating the file .well-known/acme-challenge/9ZL8tFvUv7KkANKhd93Lr9LNVhK1Rvw8elfN4EJbrug. Is that?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-11, 18:33:40
See http://intodns.com/mydomain.org
Title: Re: letsencrypt installer fails
Post by: KloxoLittleFish on 2016-05-11, 22:46:34
it is ok ... no errors in intodns
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-12, 02:53:13
it is ok ... no errors in intodns
What's you mean ok?.

Did mydomain.org your 'real' domain?. If yes, from intodns.com, so many 'red' alert including not match nameserver and no 'a record' for www.
Title: Re: letsencrypt installer fails
Post by: KloxoLittleFish on 2016-05-12, 09:21:26
Hi, 'mydomain.org' is a example domain, my real domains are other and they are ok in intodns. The error (certificate failed) is with all domains that i have.
All domains are working ok, but letsencrypt isn't working.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-12, 12:51:39
Any solution?

Code: [Select]
Nothing to do
Checking for new version...
Creating virtual environment...
Installing Python packages...
Installation succeeded.
Requesting root privileges to run letsencrypt...
   /root/.local/share/letsencrypt/bin/letsencrypt --version
letsencrypt 0.5.0


And when in admin panel trying to create: Alert: Create Certificate failed

CentOS 5
Using 'file manager', go to '/var/log/letsencrypt' and investigate log file.
Code: [Select]
2016-05-09 09:55:18,281:DEBUG:letsencrypt.main:Root logging level set at 20
2016-05-09 09:55:18,283:INFO:letsencrypt.main:Saving debug log to /var/log/letsencrypt/letsencrypt.log
2016-05-09 09:55:18,293:DEBUG:letsencrypt.main:letsencrypt version: 0.5.0
2016-05-09 09:55:18,293:DEBUG:letsencrypt.main:Arguments: ['--verbose']
2016-05-09 09:55:18,294:DEBUG:letsencrypt.main:Discovered plugins: PluginsRegistry(PluginEntryPoint#apache,PluginEntryPoint#webroot,PluginEntryPoint#null,PluginEntryPoint#manual,PluginEntryPoint#standalone)
2016-05-09 09:55:18,305:DEBUG:letsencrypt.plugins.selection:Requested authenticator None and installer None
2016-05-09 09:55:24,891:DEBUG:letsencrypt.plugins.disco:Other error:(PluginEntryPoint#apache): Error parsing runtime variables
Traceback (most recent call last):
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt/plugins/disco.py", line 104, in prepare
    self._initialized.prepare()
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt_apache/configurator.py", line 172, in prepare
    self.version)
  File "/root/.local/share/letsencrypt/lib/python2.7/site-packages/letsencrypt_apache/parser.py", line 70, in __init__
    raise errors.PluginError("Error parsing runtime variables")
PluginError: Error parsing runtime variables
2016-05-09 09:55:24,892:DEBUG:letsencrypt.plugins.selection:No candidate plugin
2016-05-09 09:55:24,892:DEBUG:letsencrypt.plugins.selection:Selected authenticator None and installer None

Buf it happens add to log only after " letsencrypt-auto --verbose"
After trying to add domain, no errors in log file
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-13, 08:40:06
After update kloxo-mr version:

Code: [Select]
sh /script/letsencrypt-installer
mv: cannot stat `certbot-master': No such file or directory
/script/letsencrypt-installer: line 39: /usr/local/lxlabs/kloxo/certbot/letsencrypt-auto: No such file or directory
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-13, 09:22:07
Wait next update.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-16, 10:00:59
And one question. It is possible work with multiple domains but one IP?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-16, 12:51:00
And one question. It is possible work with multiple domains but one IP?
Absolutely YES.
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-17, 11:24:14
Kelihatannya masalahnya pada versi python. Oleh karena itu sekarang sedang coba untuk ganti program letsencrypt-auto (berbasis python) dengan acme.sh (berbasis bash) sehingga saya berharap bisa compatible untuk CentOS 5 dan 6.

Sembari menunggu konfirmasi dengan 'pembuat' hiawatha tentang masalah gagal akses ke /.well-known.

Barusan saya update kloxomr nya master,
yang pakai centos 5 belum berhasil add ssl letsencryp

muncul tulisan : cetificate key file  empty
sewaktu update muncul :  Installing acme.sh
mv: cannot stat `acme.sh-master': No such file or directory


cara fix nya seperti apa ya master.

Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-17, 12:33:36
Tunggu update selanjutnya. Memang ada masalah pada proses install acme.sh untuk letsencrypt.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-17, 14:28:49
And one question. It is possible work with multiple domains but one IP?
Absolutely YES.
After successfully add ssl, is required to do anything to do? Going to domain with https shows not connection secured
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-17, 14:35:30
Don't need other action if create letsencrypt ssl via 'admin > domains > (select one) > ssl configure > add lets encrypt' or 'admin > clients > (select one) > domains > (select one) > ssl configure > add lets encrypt'
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-17, 15:19:44
Don't need other action if create letsencrypt ssl via 'admin > domains > (select one) > ssl configure > add lets encrypt' or 'admin > clients > (select one) > domains > (select one) > ssl configure > add lets encrypt'


tried:

1. 'admin > clients > (select one) > domains > (select one) > ssl configure > add lets encrypt'
2. 'admin > clients > (select one) > clients > (select one) > domains > (select one) > ssl configure > add lets encrypt' (on reseler account other users :))



Tried different ways, but with https shows:
Code: [Select]
Subject *.lxlabs.com
Valid from 24/Feb/2006 to 24/Feb/2007
Issuer *.lxlabs.com

If I set here 'admin —> IP Addresses —> {Domain Configure}' domain name, then it works for that domain, but other not :)
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-17, 16:20:28
I didn't found your issue in my dev servers (centos 5 and 6).
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-18, 06:34:30
After successfully add ssl, is required to do anything to do? Going to domain with https shows not connection secured

you can try to restart service like:
Code: [Select]
sh /script/restart-all y; sh /script/fix-all
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-18, 10:45:30
you can try to restart service like:
Code: [Select]
sh /script/restart-all y; sh /script/fix-all

Not helped.


Maybe I will give up, because now can't add ssl for new domains writes
Code: [Select]
Alert: Certificate key file emptyError log:
Code: [Select]
[Wed May 18 11:55:15 EEST 2016] Skip register account key
[Wed May 18 11:55:15 EEST 2016] Creating csr
[Wed May 18 11:55:15 EEST 2016] Multi domain='DNS:www.ubernemokamai.tk,DNS:cp.*****.**,DNS:webmail.*******.**'
unable to load Private Key
31489:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:647:Expecting: ANY PRIVATE KEY
[Wed May 18 11:55:15 EEST 2016] Create CSR error.

And for domains, server always takes SERVER PANEL (created new self-asign SSL, to replace lxlabs ssl which I mentioned above) ssl sertificate, but not letsencrypt sertificates. And here for me is main problem and I don't know what to do. Tried reboot, restart processes, /scripts/fix-all
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-18, 11:26:54
Inform here 'acme.sh --help; cat /var/log/acme.sh/acme.sh.log'.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-18, 11:52:48
Inform here 'acme.sh --help; cat /var/log/acme.sh/acme.sh.log'.

Code: [Select]
[root@server~]# acme.sh --help; cat /var/log/acme.sh/acme.sh.log
https://github.com/Neilpang/acme.sh
v2.2.4
Usage: acme.sh  command ...[parameters]....
Commands:
  --help, -h               Show this help message.
  --version, -v            Show version info.
  --install                Install acme.sh to your system.
  --uninstall              Uninstall acme.sh, and uninstall the cron job.
  --issue                  Issue a cert.
  --installcert            Install the issued cert to apache/nginx or any other                                                                                                                                server.
  --renew, -r              Renew a cert.
  --renewAll               Renew all the certs
  --revoke                 Revoke a cert.
  --installcronjob         Install the cron job to renew certs, you don't need t                                                                                                                               o call this. The 'install' command can automatically install the cron job.
  --uninstallcronjob       Uninstall the cron job. The 'uninstall' command can d                                                                                                                               o this automatically.
  --cron                   Run cron job to renew all the certs.
  --toPkcs                 Export the certificate and key to a pfx file.
  --createAccountKey, -cak Create an account private key, professional use.
  --createDomainKey, -cdk  Create an domain private key, professional use.
  --createCSR, -ccsr       Create CSR , professional use.

Parameters:
  --domain, -d   domain.tld         Specifies a domain, used to issue, renew or                                                                                                                                revoke etc.
  --force, -f                       Used to force to install or force to renew a                                                                                                                                cert immediately.
  --staging, --test                 Use staging server, just for test.
  --debug                           Output debug info.

  --webroot, -w  /path/to/webroot   Specifies the web root folder for web root m                                                                                                                               ode.
  --standalone                      Use standalone mode.
  --apache                          Use apache mode.
  --dns [dns_cf|dns_dp|dns_cx|/path/to/api/file]   Use dns mode or dns api.

  --keylength, -k [2048]            Specifies the domain key length: 2048, 3072,                                                                                                                                4096, 8192 or ec-256, ec-384.
  --accountkeylength, -ak [2048]    Specifies the account key length.

  These parameters are to install the cert to nginx/apache or anyother server af                                                                                                                               ter issue/renew a cert:

  --certpath /path/to/real/cert/file  After issue/renew, the cert will be copied                                                                                                                                to this path.
  --keypath /path/to/real/key/file  After issue/renew, the key will be copied to                                                                                                                                this path.
  --capath /path/to/real/ca/file    After issue/renew, the intermediate cert wil                                                                                                                               l be copied to this path.
  --fullchainpath /path/to/fullchain/file After issue/renew, the fullchain cert                                                                                                                                will be copied to this path.

  --reloadcmd "service nginx reload" After issue/renew, it's used to reload the                                                                                                                                server.

  --accountconf                     Specifies a customized account config file.
  --home                            Specifies the home dir for acme.sh .
  --certhome                        Specifies the home dir to save all the certs                                                                                                                               .
  --useragent                       Specifies the user agent string. it will be                                                                                                                                saved for future use too.
  --accountemail                    Specifies the account email for registering,                                                                                                                                Only valid for the '--install' command.
  --accountkey                      Specifies the account key path, Only valid f                                                                                                                               or the '--install' command.
  --days                            Specifies the days to renew the cert when us                                                                                                                               ing '--issue' command. The max value is 80 days.


[Wed May 18 11:55:15 EEST 2016] Skip register account key
[Wed May 18 11:55:15 EEST 2016] Creating csr
[Wed May 18 11:55:15 EEST 2016] Multi domain='DNS:www.******.**,DNS:cp.*****.**,DNS:webmail.*****.**'
unable to load Private Key
31489:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:647:Expec                                                                                                                               ting: ANY PRIVATE KEY
[Wed May 18 11:55:15 EEST 2016] Create CSR error.
[root@server~]#
acme.sh.log shows only last try :) It deletes old logs
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-18, 12:10:13
Look like something wrong with openssl, inform here 'yum list|grep openssl'.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-18, 12:27:28
Look like something wrong with openssl, inform here 'yum list|grep openssl'.
Code: [Select]
[root@server~]# yum list|grep openssl
openssl.i686                          0.9.8e-39.el5_11      installed
openssl.x86_64                        0.9.8e-39.el5_11      installed
openssl-devel.i386                    0.9.8e-39.el5_11      installed
openssl-devel.x86_64                  0.9.8e-39.el5_11      installed
apr-util-openssl.x86_64               1.5.4-1.mr.el5        mratwork-release-version-arch
globus-gsi-openssl-error.i386         3.5-2.el5             mratwork-epel
globus-gsi-openssl-error.x86_64       3.5-2.el5             mratwork-epel
globus-gsi-openssl-error-devel.i386   3.5-2.el5             mratwork-epel
globus-gsi-openssl-error-devel.x86_64 3.5-2.el5             mratwork-epel
globus-gsi-openssl-error-doc.x86_64   3.5-2.el5             mratwork-epel
globus-openssl-module.i386            4.6-2.el5             mratwork-epel
globus-openssl-module.x86_64          4.6-2.el5             mratwork-epel
globus-openssl-module-devel.i386      4.6-2.el5             mratwork-epel
globus-openssl-module-devel.x86_64    4.6-2.el5             mratwork-epel
globus-openssl-module-doc.x86_64      4.6-2.el5             mratwork-epel
openssl-perl.x86_64                   0.9.8e-39.el5_11      updates
openssl097a.i386                      0.9.7a-12.el5_10.1    base
openssl097a.x86_64                    0.9.7a-12.el5_10.1    base
openssl101e.i386                      1.0.1e-7.el5          mratwork-epel
openssl101e.x86_64                    1.0.1e-7.el5          mratwork-epel
openssl101e-devel.i386                1.0.1e-7.el5          mratwork-epel
openssl101e-devel.x86_64              1.0.1e-7.el5          mratwork-epel
openssl101e-perl.x86_64               1.0.1e-7.el5          mratwork-epel
openssl101e-static.i386               1.0.1e-7.el5          mratwork-epel
openssl101e-static.x86_64             1.0.1e-7.el5          mratwork-epel
xmlsec1-openssl.i386                  1.2.9-8.1.2           base
xmlsec1-openssl.x86_64                1.2.9-8.1.2           base
xmlsec1-openssl-devel.i386            1.2.9-8.1.2           base
xmlsec1-openssl-devel.x86_64          1.2.9-8.1.2           base
[root@server~]#
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-18, 12:45:20
Inform here 'cat /home/kloxo/ssl/*_acme.sh'
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-18, 12:51:01
Inform here 'cat /home/kloxo/ssl/*_acme.sh'
Code: [Select]
fi[root@server ~]# cat /home/kloxo/ssl/*_acme.sh
#!/bin/sh

/usr/bin/acme.sh --issue --webroot /var/run/letsencrypt  \
        --domain MYDOMAIN.lt  \
        --domain www.MYDOMAIN.lt  \
        --domain cp.MYDOMAIN.lt  \
        --domain webmail.MYDOMAIN.lt  \
        --keylength 2048 --accountemail admin@MYDOMAIN.lt  >> /var/log/acme.sh/acme.sh.log \
        &> /var/log/acme.sh/acme.sh.log

if [ -f /root/.acme.sh/MYDOMAIN.lt/ca.cer ] ; then
        cd /root/.acme.sh/MYDOMAIN.lt
        cat MYDOMAIN.lt.key MYDOMAIN.lt.cer ca.cer > MYDOMAIN.lt.pem
fi#!/bin/sh

/usr/bin/acme.sh --issue --webroot /var/run/letsencrypt  \
        --domain MYDOMAIN.info  \
        --domain www.MYDOMAIN.info  \
        --domain cp.MYDOMAIN.info  \
        --domain webmail.MYDOMAIN.info  \
        --keylength 2048 --accountemail admin@MYDOMAIN.info  >> /var/log/acme.sh/acme.sh.log \
        &> /var/log/acme.sh/acme.sh.log

if [ -f /root/.acme.sh/MYDOMAIN.info/ca.cer ] ; then
        cd /root/.acme.sh/MYDOMAIN.info
        cat MYDOMAIN.info.key MYDOMAIN.info.cer ca.cer > MYDOMAIN.info.pem
fi#!/bin/sh

/usr/bin/acme.sh --issue --webroot /var/run/letsencrypt  \
        --domain simple.MYDOMAIN.net  \
        --domain www.simple.MYDOMAIN.net  \
        --domain cp.simple.MYDOMAIN.net  \
        --domain webmail.simple.MYDOMAIN.net  \
        --keylength ec-384 --accountemail admin@simple.MYDOMAIN.net  >> /var/log/acme.sh/acme.sh.log \
        &> /var/log/acme.sh/acme.sh.log

if [ -f /root/.acme.sh/simple.MYDOMAIN.net/ca.cer ] ; then
        cd /root/.acme.sh/simple.MYDOMAIN.net
        cat simple.MYDOMAIN.net.key simple.MYDOMAIN.net.cer ca.cer > simple.MYDOMAIN.net.pem
fi#!/bin/sh

/usr/bin/acme.sh --issue --webroot /var/run/letsencrypt  \
        --domain MYDOMAIN.lt  \
        --domain www.MYDOMAIN.lt  \
        --domain cp.MYDOMAIN.lt  \
        --domain webmail.MYDOMAIN.lt  \
        --keylength 2048 --accountemail admin@MYDOMAIN.lt  >> /var/log/acme.sh/acme.sh.log \
        &> /var/log/acme.sh/acme.sh.log

if [ -f /root/.acme.sh/MYDOMAIN.lt/ca.cer ] ; then
        cd /root/.acme.sh/MYDOMAIN.lt
        cat MYDOMAIN.lt.key MYDOMAIN.lt.cer ca.cer > MYDOMAIN.lt.pem
fi#!/bin/sh

/usr/bin/acme.sh --issue --webroot /var/run/letsencrypt  \
        --domain MYDOMAIN.tk  \
        --domain www.MYDOMAIN.tk  \
        --domain cp.MYDOMAIN.tk  \
        --domain webmail.MYDOMAIN.tk  \
        --keylength 2048 --accountemail admin@MYDOMAIN.tk  >> /var/log/acme.sh/acme.sh.log \
        &> /var/log/acme.sh/acme.sh.log

if [ -f /root/.acme.sh/MYDOMAIN.tk/ca.cer ] ; then
        cd /root/.acme.sh/MYDOMAIN.tk
        cat MYDOMAIN.tk.key MYDOMAIN.tk.cer ca.cer > MYDOMAIN.tk.pem
fi[root@server ~]#
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-18, 14:19:10
Inform here dns setting for 1 of your domains.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-18, 15:15:26
This?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-18, 15:36:51
Make sure no warning in intodns.com related to ns.
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-19, 07:12:39
Make sure no warning in intodns.com related to ns.
No warnings :(
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-19, 07:27:33
Are iv.lt and xxx.info exists in the same server like xxx.lt?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-19, 07:29:52
And ehat's appear if your access to 'http://yourdomain/.well-known/acme-challenge'?
Title: Re: letsencrypt installer fails
Post by: digidata on 2016-05-19, 08:26:52
Are iv.lt and xxx.info exists in the same server like xxx.lt?
iv.lt is my server provider, because I have only one IP, but some domains requires 2 dns, so I use them provided DNS for this (they synchronise).  xxx.info and xxx.lt is in the same server

(https://i.gyazo.com/f5b99a879b621b61a7d714763dc25bdb.png)

I can give domain names, IP that you need, but in PM, not want to be public :)
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-19, 13:55:25
Ok, give info to PM.
Title: Re: letsencrypt installer fails
Post by: Spacedust on 2016-05-19, 14:42:50
I have the same.
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-19, 14:58:07
If found 'Error 403 - Forbidden' that mean your domain can raised (domain.com, www.domain.com, cp.domain.com and webmail.domain.com).

If found 'File not found' that mean something trouble for this domain. Maybe rewrite rule make trouble for it.
Title: Re: letsencrypt installer fails
Post by: Spacedust on 2016-05-19, 15:53:10
I have 403 forbbiden.
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-24, 04:02:31
saya pakai yang centos 6, apache
bisa menambah letsencrypt di domain gacatara.com tetapi sewaktu di test di ssllab muncul error
kemudian saya ketik "sh /script/cleanup"
muncul error sbb :


Stopping httpd:                                            [FAILED]
Starting httpd: AH00526: Syntax error on line 402 of /opt/configs/apache/conf/do                      mains/gacatara.com.conf:
SSLCertificateFile: file '/home/kloxo/ssl/gacatara.com.pem' does not exist or is                       empty
                                                           [FAILED]

kalau saya check di intodns memang ada eror :

ERROR: I could not get any A records for www.gacatara.com!

(I only do a cache request, if you recently added a WWW A record, it might not show up here.)

untuk memperbaiki error tersebut gimana ya master2.
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-24, 04:43:10
Hapus letsencrypt ssl dari panel dan kemudian buat baru. Tapi sebelumnya update dulu dengan 'yum clean all; yum update -y' dan kemudian 'sh /script/cleanup'.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-24, 10:04:24
tanya pak: jadi apakah sudah ada perpanjang otomatis letsencrypt kloxo-mr 7?
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-24, 12:12:06
Hapus letsencrypt ssl dari panel dan kemudian buat baru. Tapi sebelumnya update dulu dengan 'yum clean all; yum update -y' dan kemudian 'sh /script/cleanup'.

sudah saya coba master,  ada eror ketika "sh /script/cleanup" yaitu :

-------------------------------------------------------------------

Stopping nsd:                                              [  OK  ]
Starting nsd:                                              [  OK  ]
-------------------------------------------------------------------
error reading information on service phpm-fpm: No such file or directory

Stopping php-fpm:                                          [  OK  ]
Starting php-fpm:                                          [  OK  ]
-------------------------------------------------------------------

Stopping httpd:                                            [  OK  ]
Starting httpd: AH00558: httpd: Could not reliably determine the server's fully qualified domain name, using 77.81.226.79. Set the 'ServerName' directive globally to suppress this message
                                                           [  OK  ]
-------------------------------------------------------------------


kalau info :

A. Control Panel:
   - Kloxo-MR: 7.0.0.b-2016052404
   - Web: hiawatha-10.2.0-f.6.mr.el6.i686
   - PHP: php54s-5.4.45-1.ius.el6 (fpm mode)
B. Plateform:
   - OS: CentOS release 6.7 (Final) i686
   - Hostname: ita1
C. Services:
   1. MySQL: MariaDB-server-10.0.25-1.el6.i686
   2. PHP:
      - Branch: php54-cli-5.4.45-1.ius.el6.i686
      - Multiple:
        * php52m-5.2.17-102.mr.el6
        * php53m-5.3.29-1.ius.el6
        * php54m-5.4.45-1.ius.el6
        * php55m-5.5.33-1.ius.el6
        * php56m-5.6.19-1.ius.el6
        * php70m-7.0.4-1.w6
      - Used: --Use PHP Branch--
   3. Web Used: apache
     - Hiawatha: --unused--
     - Lighttpd: --uninstalled--
     - Nginx: --uninstalled--
     - Httpd: httpd24u-2.4.20-1.ius.el6.i686
       - PHP Type: php-fpm_event
   4. WebCache: none
     - ATS: --uninstalled--
     - Squid: --uninstalled--
     - Varnish: --uninstalled--
   5. Dns: nsd
     - Bind: --uninstalled--
     - DJBDns: --uninstalled--
     - NSD: nsd-4.1.9-1.mr.el6.i686
     - PowerDNS: --uninstalled--
     - Yadifa: --uninstalled--
   6. Mail: qmail-toaster-1.03-1.3.55.mr.el6.i386
      - pop3/imap4: courier-imap-toaster-4.1.2-1.3.18.mr.el6.i386
      - spam: bogofilter
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-24, 13:56:23
Kalau dijalankan 'sh /script/restart-all -y' apa hasilnya.
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-24, 14:39:10
Kalau dijalankan 'sh /script/restart-all -y' Hasil nya sbb :

# sh /script/restart-all -y

Shutting down system logger:                               [  OK  ]
Starting system logger:                                    [  OK  ]
-------------------------------------------------------------------

Shutting down MySQL. SUCCESS!
Starting MySQL. SUCCESS!
-------------------------------------------------------------------

Stopping nsd:                                              [  OK  ]
Starting nsd:                                              [  OK  ]
-------------------------------------------------------------------
error reading information on service phpm-fpm: No such file or directory

Stopping php-fpm:                                          [  OK  ]
Starting php-fpm:                                          [  OK  ]
-------------------------------------------------------------------

Stopping httpd:                                            [  OK  ]
Starting httpd: AH00558: httpd: Could not reliably determine the server's fully qualified domain name, using 77.81.226.79. Set the 'ServerName' directive globally to suppress this message
                                                           [  OK  ]
-------------------------------------------------------------------


*** Process for QMAIL service ***
Stopping qmail-toaster: svscan qmail logging.
qmail-send: no process killed
Starting qmail-toaster: svscan.
-------------------------------------------------------------------

- For help, type '/script/restart-mail [--help|-h]'
-------------------------------------------------------------------

Stopping pure-ftpd:                                        [  OK  ]
Starting pure-ftpd:                                        [  OK  ]
-------------------------------------------------------------------

Stopping kloxo-phpcgi:                                     [  OK  ]
Starting kloxo-phpcgi ('php54s' in 'fpm' mode):            [  OK  ]
Stopping kloxo-hiawatha:                                   [  OK  ]
Starting kloxo-hiawatha:                                   [  OK  ]
-------------------------------------------------------------------
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-24, 14:52:00
Did you execute 'sh /script/cleanup' after update?.
Title: Re: letsencrypt installer fails
Post by: hostrator on 2016-05-25, 09:04:42
yes sir, I have execute  'yum clean all; yum update -y' dan  'sh /script/cleanup'. dan 'sh /script/sysinfo -y'
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-25, 10:28:32
Wait 1 hours and then update your Kloxo-MR 7.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-25, 14:41:49
Wait 1 hours and then update your Kloxo-MR 7.

Pak, jadi apakah kloxo-mr 7 update terbaru sudah auto-renew letsencrypt-nya?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-25, 15:13:49
Wait 1 hours and then update your Kloxo-MR 7.

Pak, jadi apakah kloxo-mr 7 update terbaru sudah auto-renew letsencrypt-nya?
Sebenarnya saya lebih suka acme.sh daripada letsencrypt-auto untuk tangani ssl dari letsencrypt. Hanya saja acme.sh jadi bermasalah karena adanya perubahan dari letsencrypt API.

Alasannya lebih suka acme.sh karena (1) pakai ssh murni, (2) punya cron yang siap pakai, (3) jalan di CentOS 5. dan beberapa yang lain. Nanti jika acme.sh sudah stabil maka akan saya ganti pakai acme.sh.
Title: Re: letsencrypt installer fails
Post by: lanuma on 2016-05-25, 18:07:10
masih bingung nambah ssl lets encrypt yg baru, soalnya setelah di update menu add lets encrypt nya gak ada hehe
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-25, 19:10:09
Letsencrypt hanya ada dibagian domain. Sudah tidak ada dibagian admin/client.
Title: Re: letsencrypt installer fails
Post by: noob on 2016-05-26, 01:53:25
Sebenarnya saya lebih suka acme.sh daripada letsencrypt-auto untuk tangani ssl dari letsencrypt. Hanya saja acme.sh jadi bermasalah karena adanya perubahan dari letsencrypt API.

Alasannya lebih suka acme.sh karena (1) pakai ssh murni, (2) punya cron yang siap pakai, (3) jalan di CentOS 5. dan beberapa yang lain. Nanti jika acme.sh sudah stabil maka akan saya ganti pakai acme.sh.

jadi pak, dengan update kloxo-mr 7, maka sudah otomatis ada letsencrypt-auto? apakah ada seting (atau harus menjalankan cron) agar letsencrypt otomatis diperpanjang? atau tidak perlu diseting lagi?
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-26, 01:56:09
Sebenarnya saya lebih suka acme.sh daripada letsencrypt-auto untuk tangani ssl dari letsencrypt. Hanya saja acme.sh jadi bermasalah karena adanya perubahan dari letsencrypt API.

Alasannya lebih suka acme.sh karena (1) pakai ssh murni, (2) punya cron yang siap pakai, (3) jalan di CentOS 5. dan beberapa yang lain. Nanti jika acme.sh sudah stabil maka akan saya ganti pakai acme.sh.

jadi pak, dengan update kloxo-mr 7, maka sudah otomatis ada letsencrypt-auto? apakah ada seting (atau harus menjalankan cron) agar letsencrypt otomatis diperpanjang? atau tidak perlu diseting lagi?
Tidak perlu. Karena letsencrypt usia sslnya masih cukup lama (80 hari) maka masih ada waktu untuk saya nantinya menyempurnakan masalah auto-renew ssl ini.
Title: Re: letsencrypt installer fails
Post by: ar1246 on 2016-05-29, 01:37:18
Pak, ketika saya add letsencript dr panel ada alert:
Quote
Create Certificate failed [arif.awalud.in]
di log letsencrypt admin:
Quote
Create Certificate failed [arif.awalud.in]

sysinfo:
Code: [Select]
[root@mymail ~]# sh /script/sysinfo
A. Control Panel:
   - Kloxo-MR: 7.0.0.b-2016052507
   - Web: hiawatha-10.2.0-f.6.mr.el6.i686
   - PHP: php54s-5.4.44-1.ius.el6 (fpm mode)
B. Plateform:
   - OS: CentOS release 6.8 (Final) i686
   - Hostname: mymail.satriahost.com
C. Services:
   1. MySQL: MariaDB-server-10.0.25-1.el6.i686
   2. PHP:
      - Branch: php54-cli-5.4.45-1.ius.el6.i686
      - Multiple:
        * php52m-5.2.17-102.mr.el6
        * php53m-5.3.29-1.ius.el6
        * php54m-5.4.44-1.ius.el6
        * php55m-5.5.28-1.ius.el6
        * php56m-5.6.11-1.ius.el6
      - Used: --Use PHP Branch--
   3. Web Used: hiawathaproxy
     - Hiawatha: --used--
     - Lighttpd: --uninstalled--
     - Nginx: --uninstalled--
     - Httpd: httpd-2.2.31-1.mr.el6.i386
       - PHP Type: php-fpm_event
   4. WebCache: none
     - ATS: --uninstalled--
     - Squid: --uninstalled--
     - Varnish: --uninstalled--
   5. Dns: nsd
     - Bind: --uninstalled--
     - DJBDns: --uninstalled--
     - NSD: nsd-4.1.9-1.mr.el6.i686
     - PowerDNS: --uninstalled--
     - Yadifa: --uninstalled--
   6. Mail: qmail-toaster-1.03-1.3.55.mr.el6.i386
      - pop3/imap4: courier-imap-toaster-4.1.2-1.3.18.mr.el6.i386
      - spam: bogofilter
D. Memory:
                total       used       free     shared    buffers     cached
   Mem:          1893       1128        765         28        134        602
   -/+ buffers/cache:        390       1502
   Swap:          255          7        248
E. Disk Space:
   Filesystem      Size  Used Avail Use% Mounted on
   /dev/vda1        20G   16G  2.8G  86% /
*** Process Time: 00:00:00:03.3860 (dd:hh:mm:ss:xxxxxx) ***
* Note: run 'sh /script/sysinfo -y' if you want run 'fix-service-list' also
        (importance after Kloxo-MR update)
[root@mymail ~]#
makasih pak
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-29, 05:46:46
1. Jika pakai external mail (misalnya googleApp) pilihan pada 'SAN' tidak ikutkan 'webmail'
2. Jika ada redirect misalnya www ke non-www maka hentikan dulu redirect ini.
Title: Re: letsencrypt installer fails
Post by: ar1246 on 2016-05-30, 09:30:41
1. Jika pakai external mail (misalnya googleApp) pilihan pada 'SAN' tidak ikutkan 'webmail'
2. Jika ada redirect misalnya www ke non-www maka hentikan dulu redirect ini.
pak yang nmr 1 maksudnya gmn, blom ngerti SAN?

kebetulan yg mau di letsencript subdomain.
domain utama (awalud.in) emang pake google apps
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-05-30, 09:33:13
Subject Alternative Name (SAN)
Title: Re: letsencrypt installer fails
Post by: ar1246 on 2016-06-08, 07:04:14
Pak, kok sekarang jd fail yah kalo generate letsencrypt
hasil log manager yg acme:
Code: [Select]
mp-jurnalpendidikanislam.com_acme.sh: line 14: /root/.acme.sh/acme.sh: is a directory
*******lam.com_acme.sh: line 14: /root/.acme.sh/acme.sh: is a directory
*****ndaran.net_acme.sh: line 14: /root/.acme.sh/acme.sh: is a directory
***alud.in_acme.sh: line 14: /root/.acme.sh/acme.sh: is a directory

Code: [Select]
[root@mymail ~]# sh /script/sysinfo
A. Control Panel:
   - Kloxo-MR: 7.0.0.b-2016060703
   - Web: hiawatha-10.3.0-f.1.mr.el6.i686
   - PHP: php54s-5.4.44-1.ius.el6 (fpm mode)
B. Plateform:
   - OS: CentOS release 6.8 (Final) i686
   - Hostname: mymail.satriahost.com
C. Services:
   1. MySQL: MariaDB-server-10.0.25-1.el6.i686
   2. PHP:
      - 'Branch' installed: php54-cli-5.4.45-1.ius.el6.i686
      - 'Multiple' installed:
        * php52m-5.2.17-102.mr.el6
        * php53m-5.3.29-1.ius.el6
        * php54m-5.4.44-1.ius.el6
        * php55m-5.5.28-1.ius.el6
        * php56m-5.6.11-1.ius.el6
      - 'Used' selected: --PHP Branch--
      - 'Multiple' status: disable
   3. Web Used: hiawathaproxy
     - Hiawatha: --used--
     - Lighttpd: --uninstalled--
     - Nginx: --uninstalled--
     - Httpd: httpd-2.2.31-1.mr.el6.i386
       - PHP Type: php-fpm_event
   4. WebCache: none
     - ATS: --uninstalled--
     - Squid: --uninstalled--
     - Varnish: --uninstalled--
   5. Dns: nsd
     - Bind: --uninstalled--
     - DJBDns: djbdns-1.05-17.4.mr.el6.i386
     - NSD: nsd-4.1.9-1.mr.el6.i686
     - PowerDNS: --uninstalled--
     - Yadifa: --uninstalled--
   6. Mail: qmail-toaster-1.03-1.3.55.mr.el6.i386
      - pop3/imap4: courier-imap-toaster-4.1.2-1.3.19.mr.el6.i686
      - spam: bogofilter-1.2.4-1.el6.i686
D. Memory:
                total       used       free     shared    buffers     cached
   Mem:          1893       1553        339         28        254        662
   -/+ buffers/cache:        636       1256
   Swap:          255          3        252
E. Disk Space:
   Filesystem      Size  Used Avail Use% Mounted on
   /dev/vda1        20G   15G  3.6G  81% /
*** Process Time: 00:00:00:03.3819 (dd:hh:mm:ss:xxxxxx) ***
* Note: run 'sh /script/sysinfo -y' if you want run 'fix-service-list' also
        (importance after Kloxo-MR update)
[root@mymail ~]#
Title: Re: letsencrypt installer fails
Post by: MRatWork on 2016-06-08, 11:57:58
Coba install dulu dengan 'sh /script/acme.sh-installer'.