Update certificate directory and renewal script paths

Changed SSL certificate storage from /etc/xray/cert to ~/cert and updated all related paths in README.md and setup.sh. Renamed the renewal script to cert-renew.sh and adjusted cron job and Xray config to use the new locations for improved user accessibility.
This commit is contained in:
xixu-me committed 2025-07-14 18:37:00 +08:00
1 parent 858c8a436a
commit e51c9e38fa
2 files changed
+13 -13

No files matched your search

+3 -3
View File
@@ -90,10 +90,10 @@ To customize the portfolio:
```text ```text
/var/www/html/ # Web root directory /var/www/html/ # Web root directory
├── index.html # Portfolio website ├── index.html # Portfolio website
/etc/xray/cert/ # SSL certificates directory ~/cert/ # SSL certificates directory
├── x.crt # SSL certificate ├── x.crt # SSL certificate
├── x.key # Private key ├── x.key # Private key
└── renew.sh # Certificate renewal script └── cert-renew.sh # Certificate renewal script
``` ```
## 🔒 Security Features ## 🔒 Security Features
@@ -110,7 +110,7 @@ To customize the portfolio:
Certificates are automatically renewed monthly via cron job. To manually renew: Certificates are automatically renewed monthly via cron job. To manually renew:
```bash ```bash
bash /cert/etc/xray/cert/renew.sh bash ~/cert/cert-renew.sh
``` ```
### Nginx Configuration ### Nginx Configuration
+10 -10
View File
@@ -273,26 +273,26 @@ curl https://get.acme.sh | sh
sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install sudo bash -c "$(curl -L https://github.com/XTLS/Xray-install/raw/main/install-release.sh)" @ install
# Setup certificates # Setup certificates
sudo mkdir -p /etc/xray/cert mkdir ~/cert
~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key ~/.acme.sh/acme.sh --install-cert -d "$DOMAIN" --ecc --fullchain-file ~/cert/x.crt --key-file ~/cert/x.key
chmod +r /etc/xray/cert/x.key chmod +r ~/cert/x.key
# Create certificate renewal script # Create certificate renewal script
cat >/etc/xray/cert/renew.sh <<EOF cat >~/cert/cert-renew.sh <<EOF
#!/bin/bash #!/bin/bash
/home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /etc/xray/cert/x.crt --key-file /etc/xray/cert/x.key /home/$USERNAME/.acme.sh/acme.sh --install-cert -d $DOMAIN --ecc --fullchain-file /home/$USERNAME/cert/x.crt --key-file /home/$USERNAME/cert/x.key
echo "X Certificates Renewed" echo "X Certificates Renewed"
chmod +r /etc/xray/cert/x.key chmod +r /home/$USERNAME/cert/x.key
echo "Read Permission Granted for Private Key" echo "Read Permission Granted for Private Key"
sudo systemctl restart xray sudo systemctl restart xray
echo "X Restarted" echo "X Restarted"
EOF EOF
chmod +x /etc/xray/cert/renew.sh chmod +x ~/cert/cert-renew.sh
# Setup cron job # Setup cron job
crontab -l >temp_cron crontab -l >temp_cron
echo "0 1 1 * * bash /etc/xray/cert/renew.sh" >>temp_cron echo "0 1 1 * * bash /home/$USERNAME/cert/cert-renew.sh" >>temp_cron
crontab temp_cron crontab temp_cron
rm temp_cron rm temp_cron
@@ -340,8 +340,8 @@ sudo tee /usr/local/etc/xray/config.json >/dev/null <<EOF
"minVersion": "1.2", "minVersion": "1.2",
"certificates": [ "certificates": [
{ {
"certificateFile": "/etc/xray/cert/x.crt", "certificateFile": "/home/$USERNAME/cert/x.crt",
"keyFile": "/etc/xray/cert/x.key" "keyFile": "/home/$USERNAME/cert/x.key"
} }
] ]
} }