Update SSL certificate paths to /etc/xray/cert

Changed SSL certificate and key storage from ~/cert to /etc/xray/cert in both README.md and setup.sh for improved consistency and system-wide accessibility. Updated related script and config references to reflect the new directory.
This commit is contained in:
xixu-me committed 2025-07-12 14:22:27 +08:00
1 parent f2ad577f8a
commit b906bacb37
2 files changed
+14 -14

No files matched your search

+4 -4
View File
@@ -90,10 +90,10 @@ To customize the portfolio:
```text
/var/www/html/ # Web root directory
├── index.html # Portfolio website
~/cert/ # SSL certificates directory
├── x.crt # SSL certificate
├── x.key # Private key
└── cert-renew.sh # Certificate renewal script
/etc/xray/cert/ # SSL certificates directory
├── x.crt # SSL certificate
├── x.key # Private key
└── cert-renew.sh # Certificate renewal script
```
## 🔒 Security Features
+10 -10
View File
@@ -273,26 +273,26 @@ curl https://get.acme.sh | sh
sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install
# Setup certificates
mkdir ~/cert
~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file ~/cert/x.crt --key-file ~/cert/x.key
chmod +r ~/cert/x.key
sudo mkdir -p /etc/xray/cert
~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key
chmod +r /etc/xray/cert/x.key
# Create certificate renewal script
cat >~/cert/cert-renew.sh <<EOF
cat >/etc/xray/cert/cert-renew.sh <<EOF
#!/bin/bash
/home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /home/$USERNAME/cert/x.crt --key-file /home/$USERNAME/cert/x.key
/home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key
echo "X Certificates Renewed"
chmod +r /home/$USERNAME/cert/x.key
chmod +r /etc/xray/cert/x.key
echo "Read Permission Granted for Private Key"
sudo systemctl restart xray
echo "X Restarted"
EOF
chmod +x ~/cert/cert-renew.sh
chmod +x /etc/xray/cert/cert-renew.sh
# Setup cron job
crontab -l >temp_cron
echo "0 1 1 * * bash /home/$USERNAME/cert/cert-renew.sh" >>temp_cron
echo "0 1 1 * * bash /etc/xray/cert/cert-renew.sh" >>temp_cron
crontab temp_cron
rm temp_cron
@@ -340,8 +340,8 @@ sudo tee /usr/local/etc/xray/config.json >/dev/null <<EOF
"minVersion": "1.2",
"certificates": [
{
"certificateFile": "/home/$USERNAME/cert/x.crt",
"keyFile": "/home/$USERNAME/cert/x.key"
"certificateFile": "/etc/xray/cert/x.crt",
"keyFile": "/etc/xray/cert/x.key"
}
]
}