Solved

How to ensure a smooth transition to Let's Encrypt SSL Cert?

Posted on 2016-10-02
2
86 Views
Last Modified: 2016-10-03
Hello!

I've got LAMP running on Ubuntu 14.04 and almost a year ago I installed SSL (TLS 1.2) certificate for my web server, so my site would only run under HTTPS protocol. On October 8 the certificate expires. And from now on I want to install and use Let's Encrypt. They have pretty good tutorials on how to use Let's Encrypt, so (hopefully) I won't have any issues with it. But I don't know what to do now. Must I wait till after my old cert expires? Or should I go ahead and proceed with Let's Encrypt installation ASAP? If the latter, then another question arises. How to get rid of the old cert? I mean, it's probably NOT a good idea to use two of them side by side. In short, too many things I don't understand.
0
Comment
Question by:papa kota
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 7

Accepted Solution

by:
Jason earned 500 total points
ID: 41825711
I would start now. Familiarize your self with the whole process then try and make the switch. If something goes wrong you can put things back while you figure it out, because your current certificate is still good.

If you wait until your current certificate expires, then you run into problems setting up lets encrypt for the first time. You will have an extended period of people getting browser warnings while you try and figure out the problem.
0
 

Author Comment

by:papa kota
ID: 41825718
So what's the correct order of things? First, to delete the old files? I placed .crt and root_bundle.crt files in /etc/ssl/certs directory and a .key file in /etc/ssl/private directory. Other than physically deleting those files, do I have to run any specific command in the terminal or something? And then to install Let's Encrypt?
New cert from what I understood shouldn't be put like a file, it's somehow automatically works. Not the way it was with the old one...
Also in a file /etc/apache2/sites-available/000-default.conf there're 3 references to my old cert's files:

SSLCertificateFile /etc/ssl/certs/my_domain.com.crt
SSLCertificateKeyFile /etc/ssl/private/my_domain.com.key
SSLCertificateChainFile /etc/ssl/certs/root_bundle.crt

So what to do with those links? To comment out them? Or update with a new files that would be created by Let's Encrypt etc.?
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Introduction As you’re probably aware the HTTP protocol offers basic / weak authentication, which in combination with the relevant configuration on your web server, provides the ability to password protect all or part of your host.  If you were not…
Imagine a situation that you have installed SSL (http://en.wikipedia.org/wiki/Secure_Sockets_Layer) Certificate on your Cisco ASA (Cisco Adaptive Security Appliance) firewall. Installation of SSL certificate on ASA is an another topic for which you …
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question