{"id":601,"date":"2019-06-21T13:01:44","date_gmt":"2019-06-21T12:01:44","guid":{"rendered":"https:\/\/notiz.comanet.xyz\/?p=601"},"modified":"2019-11-11T00:35:18","modified_gmt":"2019-11-10T23:35:18","slug":"linux-ubuntu-18-4-yacy-ssl","status":"publish","type":"post","link":"https:\/\/notiz.comanet.xyz\/?p=601","title":{"rendered":"Linux &#8211; Ubuntu 18.4 &#8211; Docker &#8211; YaCy \u00fcber HTTPS"},"content":{"rendered":"<h1>SSL Certifikat za yacy<\/h1>\n<p>https:\/\/github.com\/yacy\/yacy_search_server\/issues\/194<\/p>\n<p><strong>Letsencript<\/strong><br \/>\n&#8211; install certboot<\/p>\n<p>&#8211; open port 80 &#8211; certboot ima http server &#8211; opcija &#8211;standalone<br \/>\n&#8211; generirat certifikat:<\/p>\n<pre>sudo certbot certonly --standalone -d example.com\r\n\r\n<\/pre>\n<pre>sudo certbot certonly --standalone -d comanet.ddns.net\r\n\r\n<\/pre>\n<p>&#8211; Certifkat je sada u \/etc\/letsencrypt\/live\/comanet.ddns.net\/<\/p>\n<h3><strong>&#8211; Konvertirat Certifikat<\/strong><\/h3>\n<p>&#8211; use openssl to convert them into yacy-readable format:<br \/>\n&#8211; <strong>generira keystore.pkcs12 u ordneru gdje se nalazis pa je zato najbolje biti u \/DATA\/SETTINGS kad knvertiras<\/strong><\/p>\n<pre>openssl pkcs12 -export -out keystore.pkcs12 -passout pass:pass -in \/etc\/letsencrypt\/live\/example.com\/cert.pem -inkey \/etc\/letsencrypt\/live\/example.com\/privkey.pem -certfile \/etc\/letsencrypt\/live\/example.com\/fullchain.pem<\/pre>\n<pre>sudo openssl pkcs12 -export -out letsencrypt.pkcs12 -in \/etc\/letsencrypt\/live\/comanet.ddns.net\/cert.pem -inkey \/etc\/letsencrypt\/live\/comanet.ddns.net\/privkey.pem -certfile \/etc\/letsencrypt\/live\/comanet.ddns.net\/fullchain.pem<\/pre>\n<p>&#8211; Ako se ne nalazis u \/DATA\/SETTINGS kopiraj:<br \/>\n&#8211; yacy_search_server\/DATA\/SETTINGS\/keystore.pkcs12<\/p>\n<p>&#8211; update the yacy conf in &lt;YaCy-Dir&gt;\/DATA\/SETTINGS\/yacy.conf:<\/p>\n<pre>keyStore=\r\nkeyStoePassword=\r\npkcs12ImportFile = DATA\/SETTINGS\/keystore.pkcs12\r\npkcs12ImportPwd = pass<\/pre>\n<hr \/>\n<p>Next starts<\/p>\n<p>As attached process<\/p>\n<pre>docker start -a yacy<\/pre>\n<p>As background process<\/p>\n<pre>docker start yacy<\/pre>\n<p>Shutdown<\/p>\n<p>Use &#8220;Shutdown&#8221; button in administration web interface<\/p>\n<p>OR run :<\/p>\n<pre>docker exec [your_container_name] \/opt\/yacy_search_server\/stopYACY.sh<\/pre>\n<p>OR run :<\/p>\n<pre>docker stop [your_container_name]<\/pre>\n<p>Upgrade<\/p>\n<p>You can upgrade your YaCy container the Docker way with the following commands sequence.<\/p>\n<p>Get latest Docker image :<\/p>\n<pre>docker pull luccioman\/yacy:latest<\/pre>\n<p>OR<\/p>\n<pre>docker pull luccioman\/yacy:latest-alpine<\/pre>\n<p>Create new container based on pulled image, using volume data from old container :<\/p>\n<pre>docker create --name [tmp-container_name] -p 8090:8090 -p 8443:8443 --volumes-from=[container_name] --log-opt max-size=100m --log-opt max-file=2 luccioman\/yacy:latest<\/pre>\n<p>Stop old container :<\/p>\n<pre>docker exec [container_name] \/opt\/yacy_search_server\/stopYACY.sh<\/pre>\n<p>Start new container :<\/p>\n<pre>docker start [tmp-container_name]<\/pre>\n<p>Check everything works fine, then you can delete old container :<\/p>\n<pre>docker rm [container_name]<\/pre>\n<p>Rename new container to reuse same container name :<\/p>\n<pre>docker rename [tmp-container_name] [container_name]\r\n\r\n<\/pre>\n<p>https:\/\/notiz.comanet.xyz\/?p=593<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SSL Certifikat za yacy https:\/\/github.com\/yacy\/yacy_search_server\/issues\/194 Letsencript &#8211; install certboot &#8211; open port 80 &#8211; certboot ima http server &#8211; opcija &#8211;standalone &#8211; generirat certifikat: sudo certbot certonly &#8211;standalone -d example.com sudo certbot certonly &#8211;standalone -d comanet.ddns.net &#8211; Certifkat je sada u \/etc\/letsencrypt\/live\/comanet.ddns.net\/ &#8211; Konvertirat Certifikat &#8211; use openssl to convert them into yacy-readable format: &#8211;&#8230;<\/p>\n","protected":false},"author":1,"featured_media":610,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,6],"tags":[],"class_list":["post-601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-how-to-s","category-linux"],"_links":{"self":[{"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/posts\/601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=601"}],"version-history":[{"count":6,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/posts\/601\/revisions"}],"predecessor-version":[{"id":650,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/posts\/601\/revisions\/650"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=\/wp\/v2\/media\/610"}],"wp:attachment":[{"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=601"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/notiz.comanet.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}