Update SSL certificate paths to /etc/xray/cert

Changed SSL certificate and key storage from ~/cert to /etc/xray/cert in both README.md and setup.sh for improved consistency and system-wide accessibility. Updated related script and config references to reflect the new directory.
This commit is contained in:
xixu-me committed 2025-07-12 14:22:27 +08:00
1 parent f2ad577f8a
commit b906bacb37
2 files changed
+14 -14

No files matched your search

+4 -4
View File
@@ -90,10 +90,10 @@ To customize the portfolio:
```text ```text
/var/www/html/ # Web root directory /var/www/html/ # Web root directory
├── index.html # Portfolio website ├── index.html # Portfolio website
~/cert/ # SSL certificates directory /etc/xray/cert/ # SSL certificates directory
├── x.crt # SSL certificate ├── x.crt # SSL certificate
├── x.key # Private key ├── x.key # Private key
└── cert-renew.sh # Certificate renewal script └── cert-renew.sh # Certificate renewal script
``` ```
## 🔒 Security Features ## 🔒 Security Features
+10 -10
View File
@@ -273,26 +273,26 @@ curl https://get.acme.sh | sh
sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install
# Setup certificates # Setup certificates
mkdir ~/cert sudo mkdir -p /etc/xray/cert
~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file ~/cert/x.crt --key-file ~/cert/x.key ~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key
chmod +r ~/cert/x.key chmod +r /etc/xray/cert/x.key
# Create certificate renewal script # Create certificate renewal script
cat >~/cert/cert-renew.sh <<EOF cat >/etc/xray/cert/cert-renew.sh <<EOF
#!/bin/bash #!/bin/bash
/home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /home/$USERNAME/cert/x.crt --key-file /home/$USERNAME/cert/x.key /home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key
echo "X Certificates Renewed" echo "X Certificates Renewed"
chmod +r /home/$USERNAME/cert/x.key chmod +r /etc/xray/cert/x.key
echo "Read Permission Granted for Private Key" echo "Read Permission Granted for Private Key"
sudo systemctl restart xray sudo systemctl restart xray
echo "X Restarted" echo "X Restarted"
EOF EOF
chmod +x ~/cert/cert-renew.sh chmod +x /etc/xray/cert/cert-renew.sh
# Setup cron job # Setup cron job
crontab -l >temp_cron crontab -l >temp_cron
echo "0 1 1 * * bash /home/$USERNAME/cert/cert-renew.sh" >>temp_cron echo "0 1 1 * * bash /etc/xray/cert/cert-renew.sh" >>temp_cron
crontab temp_cron crontab temp_cron
rm temp_cron rm temp_cron
@@ -340,8 +340,8 @@ sudo tee /usr/local/etc/xray/config.json >/dev/null <<EOF
"minVersion": "1.2", "minVersion": "1.2",
"certificates": [ "certificates": [
{ {
"certificateFile": "/home/$USERNAME/cert/x.crt", "certificateFile": "/etc/xray/cert/x.crt",
"keyFile": "/home/$USERNAME/cert/x.key" "keyFile": "/etc/xray/cert/x.key"
} }
] ]
} }