Solved

How to ensure a smooth transition to Let's Encrypt SSL Cert?

Posted on 2016-10-02
2
52 Views
Last Modified: 2016-10-03
Hello!

I've got LAMP running on Ubuntu 14.04 and almost a year ago I installed SSL (TLS 1.2) certificate for my web server, so my site would only run under HTTPS protocol. On October 8 the certificate expires. And from now on I want to install and use Let's Encrypt. They have pretty good tutorials on how to use Let's Encrypt, so (hopefully) I won't have any issues with it. But I don't know what to do now. Must I wait till after my old cert expires? Or should I go ahead and proceed with Let's Encrypt installation ASAP? If the latter, then another question arises. How to get rid of the old cert? I mean, it's probably NOT a good idea to use two of them side by side. In short, too many things I don't understand.
0
Comment
Question by:papa kota
2 Comments
 
LVL 7

Accepted Solution

by:
Jason earned 500 total points
ID: 41825711
I would start now. Familiarize your self with the whole process then try and make the switch. If something goes wrong you can put things back while you figure it out, because your current certificate is still good.

If you wait until your current certificate expires, then you run into problems setting up lets encrypt for the first time. You will have an extended period of people getting browser warnings while you try and figure out the problem.
0
 

Author Comment

by:papa kota
ID: 41825718
So what's the correct order of things? First, to delete the old files? I placed .crt and root_bundle.crt files in /etc/ssl/certs directory and a .key file in /etc/ssl/private directory. Other than physically deleting those files, do I have to run any specific command in the terminal or something? And then to install Let's Encrypt?
New cert from what I understood shouldn't be put like a file, it's somehow automatically works. Not the way it was with the old one...
Also in a file /etc/apache2/sites-available/000-default.conf there're 3 references to my old cert's files:

SSLCertificateFile /etc/ssl/certs/my_domain.com.crt
SSLCertificateKeyFile /etc/ssl/private/my_domain.com.key
SSLCertificateChainFile /etc/ssl/certs/root_bundle.crt

So what to do with those links? To comment out them? Or update with a new files that would be created by Let's Encrypt etc.?
0

Featured Post

Control application downtime with dependency maps

Visualize the interdependencies between application components better with Applications Manager's automated application discovery and dependency mapping feature. Resolve performance issues faster by quickly isolating problematic components.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you need a certificate so you can offer SSL encryption.  But which one should you get?  There are so many choices out there! Here is a generic overview of the main types of SSL certificates sold by the majority of commercial Certification Auth…
Over the last year I have answered a couple of basic URL rewriting questions several times so I thought I might as well have a stab at: explaining the basics, providing a few useful links and consolidating some of the most common queries into a sing…
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now