Task:
Switch the ISPConfig 3.2 or 3.3 administrative UI from another TLS/SSL provider or self-certified one to using the Certbot (LetsEncrypt) TLS certificate provision.
Note:
- These instructions assume LE/LetsEncrypt certbot has been installed and configured, and in use already for ISPConfig client sites.
- Confirm you have a valid VM backup before starting
Steps:
1. Run ISPConfig Update program:
a. Switch to root user:
$ sudo su -
<enter password if not using private cert>
b. Start update:
# ispconfig_update.sh
2. Answer the update prompts:
Notes:
- Unless otherwise prompted, the answer in [square brackets] is the default one and can be taken by simply clicking <enter>
- During reconfiguration of services, watch for any local config override templates for upstream changes checks
- The default update task is to keep the current certificate setup, instead of taking the default, we want to answer yes for this one.
a. Update source:
Select update source (stable,nightly,git-develop) [stable]: <enter>
b. Create backup:
Shall the script create a ISPConfig backup in /var/backup/ now? (yes,no) [yes]: <enter>
c. Enable or Disable Firewall:
Service 'firewall_server' has been detected (currently disabled) do you want to enable and configure it? (yes,no) [no]: <enter>
d. Reconfigure Services:
Reconfigure Services? (yes,no,selected) [yes]: <enter>
e. Replace the existing SSL certificate and let the update program create another with CertBot:
Create new ISPConfig SSL certificate (yes,no) [no]: yes
Symlink ISPConfig SSL certs to Postfix? (y,n) [y]: <enter>
Symlink ISPConfig SSL certs to Pure-FTPd? Creating dhparam file may take some time. (y,n) [y]: <enter>
f. Reconfigure Crontab:
Reconfigure Crontab? (yes,no) [yes]: <enter>
g. Confirm ended okay;
Restarting services ...
Update finished.
previous page
|