From 4239dc22d433b31e30144fcbf9d5f9dd233c1a36 Mon Sep 17 00:00:00 2001 From: aptalca <541623+aptalca@users.noreply.github.com> Date: Sat, 23 Mar 2024 11:10:04 -0400 Subject: [PATCH] fix perms on generated priv-fullchain-bundle.pem --- README.md | 1 + readme-vars.yml | 1 + root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default | 1 + 3 files changed, 3 insertions(+) diff --git a/README.md b/README.md index 8dd657c..9e9f8fb 100644 --- a/README.md +++ b/README.md @@ -400,6 +400,7 @@ Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64 ## Versions +* **23.03.24:** - Fix perms on the generated `priv-fullchain-bundle.pem`. * **14.03.24:** - [Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-location.conf, authelia-server.conf - Update Authelia conf samples with support for 4.38. * **11.03.24:** - Restore support for DynuDNS using `certbot-dns-dynudns`. * **06.03.24:** - [Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) site-confs/default.conf - Cleanup default site conf. diff --git a/readme-vars.yml b/readme-vars.yml index cb17508..64f8b71 100644 --- a/readme-vars.yml +++ b/readme-vars.yml @@ -168,6 +168,7 @@ app_setup_block: | # changelog changelogs: + - { date: "23.03.24:", desc: "Fix perms on the generated `priv-fullchain-bundle.pem`." } - { date: "14.03.24:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-location.conf, authelia-server.conf - Update Authelia conf samples with support for 4.38." } - { date: "11.03.24:", desc: "Restore support for DynuDNS using `certbot-dns-dynudns`." } - { date: "06.03.24:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) site-confs/default.conf - Cleanup default site conf." } diff --git a/root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default b/root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default index e87f85c..2f39981 100644 --- a/root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default +++ b/root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default @@ -5,4 +5,5 @@ cd /config/keys/letsencrypt || exit 1 openssl pkcs12 -export -out privkey.pfx -inkey privkey.pem -in cert.pem -certfile chain.pem -passout pass: sleep 1 cat {privkey,fullchain}.pem >priv-fullchain-bundle.pem +chmod 600 priv-fullchain-bundle.pem chown -R abc:abc /config/etc/letsencrypt