Update certificate directory and renewal script paths
Changed SSL certificate storage from /etc/xray/cert to ~/cert and updated all related paths in README.md and setup.sh. Renamed the renewal script to cert-renew.sh and adjusted cron job and Xray config to use the new locations for improved user accessibility.
This commit is contained in:
1 parent
858c8a436a
commit
e51c9e38fa
2 files changed
+13
-13
No files matched your search
@@ -90,10 +90,10 @@ To customize the portfolio:
|
|||||||
```text
|
```text
|
||||||
/var/www/html/ # Web root directory
|
/var/www/html/ # Web root directory
|
||||||
├── index.html # Portfolio website
|
├── index.html # Portfolio website
|
||||||
/etc/xray/cert/ # SSL certificates directory
|
~/cert/ # SSL certificates directory
|
||||||
├── x.crt # SSL certificate
|
├── x.crt # SSL certificate
|
||||||
├── x.key # Private key
|
├── x.key # Private key
|
||||||
└── renew.sh # Certificate renewal script
|
└── cert-renew.sh # Certificate renewal script
|
||||||
```
|
```
|
||||||
|
|
||||||
## 🔒 Security Features
|
## 🔒 Security Features
|
||||||
@@ -110,7 +110,7 @@ To customize the portfolio:
|
|||||||
Certificates are automatically renewed monthly via cron job. To manually renew:
|
Certificates are automatically renewed monthly via cron job. To manually renew:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
bash /cert/etc/xray/cert/renew.sh
|
bash ~/cert/cert-renew.sh
|
||||||
```
|
```
|
||||||
|
|
||||||
### Nginx Configuration
|
### Nginx Configuration
|
||||||
|
|||||||
@@ -273,26 +273,26 @@ curl https://get.acme.sh | sh
|
|||||||
sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install
|
sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install
|
||||||
|
|
||||||
# Setup certificates
|
# Setup certificates
|
||||||
sudo mkdir -p /etc/xray/cert
|
mkdir ~/cert
|
||||||
~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key
|
~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file ~/cert/x.crt --key-file ~/cert/x.key
|
||||||
chmod +r /etc/xray/cert/x.key
|
chmod +r ~/cert/x.key
|
||||||
|
|
||||||
# Create certificate renewal script
|
# Create certificate renewal script
|
||||||
cat >/etc/xray/cert/renew.sh <<EOF
|
cat >~/cert/cert-renew.sh <<EOF
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
/home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key
|
/home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /home/$USERNAME/cert/x.crt --key-file /home/$USERNAME/cert/x.key
|
||||||
echo "X Certificates Renewed"
|
echo "X Certificates Renewed"
|
||||||
chmod +r /etc/xray/cert/x.key
|
chmod +r /home/$USERNAME/cert/x.key
|
||||||
echo "Read Permission Granted for Private Key"
|
echo "Read Permission Granted for Private Key"
|
||||||
sudo systemctl restart xray
|
sudo systemctl restart xray
|
||||||
echo "X Restarted"
|
echo "X Restarted"
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
chmod +x /etc/xray/cert/renew.sh
|
chmod +x ~/cert/cert-renew.sh
|
||||||
|
|
||||||
# Setup cron job
|
# Setup cron job
|
||||||
crontab -l >temp_cron
|
crontab -l >temp_cron
|
||||||
echo "0 1 1 * * bash /etc/xray/cert/renew.sh" >>temp_cron
|
echo "0 1 1 * * bash /home/$USERNAME/cert/cert-renew.sh" >>temp_cron
|
||||||
crontab temp_cron
|
crontab temp_cron
|
||||||
rm temp_cron
|
rm temp_cron
|
||||||
|
|
||||||
@@ -340,8 +340,8 @@ sudo tee /usr/local/etc/xray/config.json >/dev/null <<EOF
|
|||||||
"minVersion": "1.2",
|
"minVersion": "1.2",
|
||||||
"certificates": [
|
"certificates": [
|
||||||
{
|
{
|
||||||
"certificateFile": "/etc/xray/cert/x.crt",
|
"certificateFile": "/home/$USERNAME/cert/x.crt",
|
||||||
"keyFile": "/etc/xray/cert/x.key"
|
"keyFile": "/home/$USERNAME/cert/x.key"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in new issue
Block a user