Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Support
  3. delete *.domain.com certificate -- wildcard cert that got leftover after migration (manual dns)

delete *.domain.com certificate -- wildcard cert that got leftover after migration (manual dns)

Scheduled Pinned Locked Moved Solved Support
certificates
6 Posts 3 Posters 935 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • humptydumptyH Offline
      humptydumptyH Offline
      humptydumpty
      wrote on last edited by girish
      #1

      I finished migrating my server from DO to Contabo so I had to redo the DNS to get rid of *.domain.com and add a record for each app since I had to go with manual DNS again. All is well except for checking my email on iOS. It's spitting out an error about trust/certificate and when I inspect the details section, it's showing a cert pointing to *.domain.com instead of mail.domain.com.

      I assume I can find that cert via SFTP and delete it then click on RENEW ALL CERTS in my CR dashboard to recreate it. If I'm on the right track, does anyone know where those damn certs are located on the server?

      Arigato!

      girishG 1 Reply Last reply
      0
      • humptydumptyH humptydumpty

        I finished migrating my server from DO to Contabo so I had to redo the DNS to get rid of *.domain.com and add a record for each app since I had to go with manual DNS again. All is well except for checking my email on iOS. It's spitting out an error about trust/certificate and when I inspect the details section, it's showing a cert pointing to *.domain.com instead of mail.domain.com.

        I assume I can find that cert via SFTP and delete it then click on RENEW ALL CERTS in my CR dashboard to recreate it. If I'm on the right track, does anyone know where those damn certs are located on the server?

        Arigato!

        girishG Do not disturb
        girishG Do not disturb
        girish
        Staff
        wrote on last edited by
        #2

        @humptydumpty The cert is stored in the database and a "copy" of it is stored in /home/yellowtent/platformdata/nginx/cert . The wildcard certs will have the file name _.domain.com.cert . I think if you first renew all certs and then go the Services -> Mail -> Restart, it will copy over the appropriate certificate to the mail service as well.

        This all should be automatic, but I am not 100% clear why you have changing the server meant changing the DNS.

        humptydumptyH 1 Reply Last reply
        0
        • girishG girish

          @humptydumpty The cert is stored in the database and a "copy" of it is stored in /home/yellowtent/platformdata/nginx/cert . The wildcard certs will have the file name _.domain.com.cert . I think if you first renew all certs and then go the Services -> Mail -> Restart, it will copy over the appropriate certificate to the mail service as well.

          This all should be automatic, but I am not 100% clear why you have changing the server meant changing the DNS.

          humptydumptyH Offline
          humptydumptyH Offline
          humptydumpty
          wrote on last edited by
          #3

          @girish I had to go back to manual DNS because none of my providers are supported on Cloudron so I can't use Wildcard certs unless I have automated DNS (namesilo, contabo, dnsmadeeasy).

          I did click on Renew All Certs but I keep forgetting to restart the mail service! That did it. Thanks Girish!

          1 Reply Last reply
          0
          • robiR Offline
            robiR Offline
            robi
            wrote on last edited by
            #4

            Should those two things be tied together and restart the mail service with every renew all?

            Conscious tech

            girishG 1 Reply Last reply
            0
            • robiR robi

              Should those two things be tied together and restart the mail service with every renew all?

              girishG Do not disturb
              girishG Do not disturb
              girish
              Staff
              wrote on last edited by
              #5

              @robi they are already tied together. But clearly there is some bug and I haven't able to figure out the root cause. This is why we keep getting this issue of mail container cert expiring. For some reason, the renew logic is not copying over certs to the mail container. Even though the code is there.

              robiR 1 Reply Last reply
              0
              • girishG girish

                @robi they are already tied together. But clearly there is some bug and I haven't able to figure out the root cause. This is why we keep getting this issue of mail container cert expiring. For some reason, the renew logic is not copying over certs to the mail container. Even though the code is there.

                robiR Offline
                robiR Offline
                robi
                wrote on last edited by robi
                #6

                @girish Perhaps take a look at it from the pull perspective vs push.

                Maybe even originating the refresh from the mail container side, triggering the others.

                Conscious tech

                1 Reply Last reply
                0
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                  • Login

                  • Don't have an account? Register

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • Bookmarks
                  • Search