Compare commits

..

No commits in common. "8cd801bd642abe2b2cbf33debfad8766325a1015" and "a858a1973f8fc4e8f856ecaa0cb4ef01dad22149" have entirely different histories.

2 changed files with 13 additions and 6 deletions

View file

@ -9,13 +9,20 @@ set -eu
le_dir="/etc/letsencrypt/live/$(hostname -f)"
mosquitto_dir="/etc/mosquitto"
le_fullchain="$le_dir/fullchain.pem"
mosquitto_fullchain="$mosquitto_dir/certs/fullchain.pem"
install -m 644 -o mosquitto -g root "$le_fullchain" "$mosquitto_fullchain"
le_chain="$le_dir/chain.pem"
mosquitto_chain="$mosquitto_dir/ca_certificates/chain.pem"
cp "$le_chain" "$mosquitto_chain"
chown mosquitto:root "$mosquitto_chain"
le_cert="$le_dir/cert.pem"
mosquitto_cert="$mosquitto_dir/certs/cert.pem"
cp "$le_cert" "$mosquitto_cert"
chown mosquitto:root "$mosquitto_cert"
le_key="$le_dir/privkey.pem"
mosquitto_key="$mosquitto_dir/certs/privkey.pem"
install -m 600 -o mosquitto -g root "$le_key" "$mosquitto_key"
cp "$le_key" "$mosquitto_key"
chown mosquitto:root "$mosquitto_key"
# Tell mosquitto to reload certs
pkill -x -HUP mosquitto

View file

@ -1,6 +1,6 @@
listener 8883
cafile /usr/local/share/ca-certificates/step_ca_root.crt
certfile /etc/mosquitto/certs/fullchain.pem
cafile /etc/mosquitto/ca_certificates/chain.pem
certfile /etc/mosquitto/certs/cert.pem
keyfile /etc/mosquitto/certs/privkey.pem
require_certificate true
use_identity_as_username true