Certbot write files in /var/letsencrypt-auto/.well-known/acme-challenge
to allow Let's Encrypt server to verify the certificate request comes
from an authorized source.
Fixes T2051.
Differential D3501
Allow nginx to read /.well-known/acme-challenge dereckson on Oct 9 2024, 17:48. Authored by Tags None Referenced Files
Subscribers
Details Certbot write files in /var/letsencrypt-auto/.well-known/acme-challenge Fixes T2051.
Diff Detail
Event TimelineComment Actions Complector $ salt docker-002 state.apply roles/core/certificates/letsencrypt […] ID: selinux_context_certbot_www Function: selinux.fcontext_policy_present Name: /var/letsencrypt-auto Result: True Comment: Started: 18:00:54.789434 Duration: 1865.606 ms Changes: ---------- new: ---------- /var/letsencrypt-auto: ---------- filetype: all files sel_type: httpd_sys_content_t old: ---------- ---------- ID: selinux_context_certbot_www_applied Function: selinux.fcontext_policy_applied Name: /var/letsencrypt-auto Result: True Comment: SElinux policies are already applied for filespec "/var/letsencrypt-auto" Started: 18:00:56.655250 Duration: 7.813 ms Changes: […] Summary for docker-002 ------------- Succeeded: 10 (changed=1) Failed: 0 ------------- Total states run: 10 Total run time: 2.193 s |