FOOD FOR THOUGHT SSL Corrections

wardmundy

Nerd Uno
Joined
Oct 12, 2007
Messages
19,206
Reaction score
5,228
Port 80 and 443 are the most vulnerable, and those are the ports they need access to. So... adjusting iptables probably isn't worth the effort.
 

DoctorJ

Member
Joined
Jul 14, 2015
Messages
80
Reaction score
18
Seems we now have to install Python for auto-renew with certbot... anyone else having this problem.

Code:
Upgrading certbot-auto 0.20.0 to 0.22.2...
Replacing certbot-auto...
Bootstrapping dependencies for RedHat-based OSes that will use Python3... (you can skip this with --no-bootstrap)
yum is /usr/bin/yum
No supported Python package available to install. Aborting bootstrap!

Ran it again with "--no-bootstrap", and got:

Code:
WARNING: couldn't find Python 2.7+ to check for updates.
Creating virtual environment...
Cannot find any Pythons; please install one!
WARNING: Always run Incredible PBX behind a secure hardware-based firewall.

@wardmundy, installing Python isn't all that difficult. I'm just concerned about breaking something. Any risk to this on IncrediblePBX 13-12?
 

DoctorJ

Member
Joined
Jul 14, 2015
Messages
80
Reaction score
18
I've noticed that the original tutorial from September 25 has completely changed. Any instructions on how to update my configuration?
 

lrosenman

Guru
Joined
Oct 17, 2014
Messages
221
Reaction score
30
has anyone looked at using acme.sh and it's dns_nsupdate verification (I run my own nameserver, and can give it a T-SIG key to allow NSUPDATE to work) then you don't have to expose anything..
 

Members online

Forum statistics

Threads
25,825
Messages
167,849
Members
19,250
Latest member
mark-curtis
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Top