FOOD FOR THOUGHT SSL Corrections

Port 80 and 443 are the most vulnerable, and those are the ports they need access to. So... adjusting iptables probably isn't worth the effort.
 
Seems we now have to install Python for auto-renew with certbot... anyone else having this problem.

Code:
Upgrading certbot-auto 0.20.0 to 0.22.2...
Replacing certbot-auto...
Bootstrapping dependencies for RedHat-based OSes that will use Python3... (you can skip this with --no-bootstrap)
yum is /usr/bin/yum
No supported Python package available to install. Aborting bootstrap!

Ran it again with "--no-bootstrap", and got:

Code:
WARNING: couldn't find Python 2.7+ to check for updates.
Creating virtual environment...
Cannot find any Pythons; please install one!
WARNING: Always run Incredible PBX behind a secure hardware-based firewall.

@wardmundy, installing Python isn't all that difficult. I'm just concerned about breaking something. Any risk to this on IncrediblePBX 13-12?
 
I've noticed that the original tutorial from September 25 has completely changed. Any instructions on how to update my configuration?
 
has anyone looked at using acme.sh and it's dns_nsupdate verification (I run my own nameserver, and can give it a T-SIG key to allow NSUPDATE to work) then you don't have to expose anything..
 

Members online

Forum statistics

Threads
26,687
Messages
174,410
Members
20,257
Latest member
Dempan
Get 3CX - Absolutely Free!

Link up your team and customers Phone System Live Chat Video Conferencing

Hosted or Self-managed. Up to 10 users free forever. No credit card. Try risk free.

3CX
A 3CX Account with that email already exists. You will be redirected to the Customer Portal to sign in or reset your password if you've forgotten it.
Back
Top