Installation SSL Certificates For OpenMeetings 7.1.0 On Ubuntu 22.04 Lts
Installation SSL Certificates For OpenMeetings 7.1.0 On Ubuntu 22.04 Lts
04 lts
for OpenMeetings 7.1.0
These SSL certificates are for can run OpenMeetings 7.1.0 as “https”.
If you didn't have it installed you can directly download the installation tutorial from here:
I thank Maxim Solodovnik and Carlos Heras, without whose collaboration in the trials practices
could not have confirmed the proper functioning and thus be able to publish the present tutorial.
I also thank all those who have contributed such as Marcus Schulz and Daniel Baker.
Thanks to all them.
Starting…
1)
------ Creating SSL Let´s Encrypt certificates ------
It is important that your pc-server does not have port 80 in use with some web server or some
other. If so, stop it and continue with this step. When the certificates are completed, you can
throw it again.
We'll run it with the --standalone parameter, so you can add each domain at the end requires a
certificate, for exemple: -d newexemple.com
Change "exemple.com" to the true domain of your server:
# You will be asked for an admin email address. Put a real one to get you keep you informed about
certificates:
Installation succeeded.
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator standalone, Installer None
Enter email address (used for urgent renewal and security notices) (Enter 'c' to
cancel): ...here your mail address and press Enter
----------------------------------------
Please read the Terms of Service at
https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must
agree in order to register with the ACME server at
https://acme-v02.api.letsencrypt.org/directory
----------------------------------------
(A)gree/(C)ancel: ...type... a ...and press Enter
----------------------------------------
Would you be willing to share your email address with the Electronic Frontier
Foundation, a founding partner of the Let's Encrypt project and the non-profit
organization that develops Certbot? We'd like to send you email about our work
encrypting the web, EFF news, campaigns, and ways to support digital freedom.
----------------------------------------
(Y)es/(N)o: ...type... n ...and press Enter
when you finish making the certificates successfully, it will show the following:
Pag 2
IMPORTANT NOTES:
- Congratulations! Your certificate and chain have been saved at:
/etc/letsencrypt/live/your_domain/fullchain.pem
Your key file has been saved at:
/etc/letsencrypt/live/your_domain/privkey.pem
Your cert will expire on 2020-06-24. To obtain a new or tweaked
version of this certificate in the future, simply run
letsencrypt-auto again. To non-interactively renew *all* of your
certificates, run "letsencrypt-auto renew"
- If you like Certbot, please consider supporting our work by:
2)
------ Checking domain certificates ------
We´ll see where are stored the certificates we just create, that in our case will be at
/etc/letsencrypt/live:
sudo ls /etc/letsencrypt/live
All domains that you specified in the previous step will be located in the same
certificate.
3)
------ Renewing the SSL certificate ------
The Let's Encrypt certificate has an drawback, and is that it is valid only 90 days, so we're going to
have to renew it. Remember to open port 80.
...or we can do it automatically by adding the bottom line to the cron so that every Sunday check if
the certificate needs to be renewed and do so if necessary:
sudo crontab -e
...exit the nano editor by pressing the Ctrl+x keys, ask if you save and press Y and then Enter to
exit.
4)
------ Configuring Tomcat-OpenMeetings with SSL certificates ------
These steps 3 and 4, must be repeated every 80 days, as it is 90 Let´s Encrypt's valid days.
I followed the OM installation path that show the OpenMeetings tutorials that are
found on their official wiki site. I mean /opt/open710.
If you had done the installation on a different path, modify what you indicate below.
We already made the letsencrypt certificates for our domain in step 1.
Now let's create a PKCS12 that contains the full chain and the private one. It is necessary to have
installed openssl. We install it if not:
…replace example.com with your true domain (the same as when we made letsencrypt certificates)
...will ask for a password. Type one that you likes and paste in a text file (will need now)
And now convert that PKCS12 to JKS file using java keytool:
…replace example.com with your true domain (twice), and samplePassword (three times) with
the password you just choosed (it you pasted in a text file).
...replace example.com with your true domain, and samplePassword with the password that
you've just chosen (the one you just saved to a text file)
...exit the nano editor by pressing the Ctrl+x keys, ask if you save and press Y and then Enter to
exit.
Restart OpenMeetings:
---------------------
If you have some doubt or question, please raise it in the Apache OpenMeetings forums:
https://openmeetings.apache.org/mailing-lists.html
Thank you.