Get a certificate for your Pi-Gateway with Let's Encrypt

Started by Scram, February 10, 2018, 05:57:54 AM

Scram

It was always bothering me to see this nasty notification from the web browser telling me that my own Pi gateway is a unsafe place to be. If this is bothering you as well...just get rid of it and buy a proper certificate  ::)

Or simply follow these instructions and get a proper certificate 4 free using LETSENRYPT ;D

Before you begin please check and answer with yes:
- you're running Raspian Jessie
- you have a dynamic domain pointing to the public IP of your raspberry (or ports 80 & 443 are forwarded to it)

1. Begin editing the sources.list file by using the following command in the terminal:

sudo nano /etc/apt/sources.list


2. Add the following line:

deb http://ftp.debian.org/debian jessie-backports main


save & exit by pressing CTRL + X, then pressing Y

3. Grab both public keys we need by typing in the following four commands:

gpg --keyserver pgpkeys.mit.edu --recv-key  8B48AD6246925553
gpg -a --export 8B48AD6246925553 | sudo apt-key add -
gpg --keyserver pgpkeys.mit.edu --recv-key  7638D0442B90D010
gpg -a --export 7638D0442B90D010 | sudo apt-key add -


4. Update to grab the latest package list:

sudo apt-get update


5.  Install the let's encrypt software:

sudo apt-get install certbot -t jessie-backports


6. Stop your Nginx Server which is currently blocking port 80 & 443 (we temporarily need those for a moment)

sudo service nginx stop


7. Go and grab your certificate (replace the domain name "example.com" with your Domain for the Raspberry)

You will be prompted to enter some details, such as your email address. This is required for Let's Encrypt to keep track of the certificates it provides and also allow them to contact you if any issues arrive with the certificate. Then get them:

sudo certbot certonly --standalone -d example.com


The certificates that are grabbed by the certbot client will be stored in the following folder:
/etc/letsencrypt/live/example.com/

8. Open the Nginx config file as root

sudo nano /etc/nginx/sites-available/default


Find the two lines pointing to your self generated certificates. Probably they're looking like the following:

  ssl_certificate /home/pi/gateway/data/secure/server.crt;
  ssl_certificate_key /home/pi/gateway/data/secure/server.key;


Put a # in front of each to comment them out and insert the newly created ones in here:

  ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
  ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;


9. Restart your Nginx server again and voila

sudo service nginx start



If everything went well you should now have a green closed lock icon in your firefox address line when browsing your gateway and no more warnings about the site being unsafe.

The certificate will only be valid for a 3 month period. To obtain a new or tweaked version of this certificate in the future, simply run certbot again.

1. Stop Nginx server:

sudo service nginx stop


2. To non-interactively renew *all* of your certificates, run:

sudo certbot renew


3. Restart Nginx server:

sudo service nginx start


This is how it worked out for me, let me know if you found an issue with this.

LukaQ

Great, this will have to be tried! Also it would good to make script while at it, to auto update cert. Since 3 months is pretty short time


LukaQ

This will no longer work since
deb http://ftp.debian.org/debian jessie-backports main

does not exists anymore

Also certbot-auto should be used. But I can't get it to work... can't generate certs because
rejected request from rfc1918 ip to public server address


Some sites don't see the site, I can access it from outside with no problem

HeneryH

I'm not up on the latest raspbian versions but wouldn't these instructions work?

https://certbot.eff.org/lets-encrypt/debianbuster-nginx  <-- select the version at the top to get the instructions.

LukaQ

i'm on 8. I didn't try for the 9/10. It might be incompatible.

But on other PI, also running 8 (jessie), works just fine