Thomas Buck
37dd16fb67
add sslletsencrypt and sslselfsigned roles for internal servers
3 gadus atpakaļ
Dosenpfand
f2c14dd911
Remove unneeded/deprecated apache configuration
8 gadus atpakaļ
Mike Ashley
8e1d473027
Use Let's Encrypt for generating site certificates
This method uses Subjective Alternative Names (SANs) to get one
certificate for all the subdomains that Sovereign employs, whether or
not the user configured their site with the roles.
9 gadus atpakaļ
Mike Ashley
7f46129a4c
Remove use of wildcard certificate
9 gadus atpakaļ
Mike Ashley
195d8811fc
Remove references to Trusty and Wheezy
Make a clean distinction between Debian 7 and Debian 8. Anticipate the
next Ubuntu LTS release (Xenial) that is planned for support.
8 gadus atpakaļ
Mike Ashley
d3abc02f84
Clean up Apache SSL configuration
Avoid using the Include directive. Move most of the SSL configuration
to the global configuration and leave enabling the SSL engine to each
virtual host that wants to use it.
8 gadus atpakaļ
Dan Milon
829c8491c7
restart apache on SSL changes
9 gadus atpakaļ
Dan Milon
a5c6f663ce
properly install changed SSL certificate
9 gadus atpakaļ
Sven Neuhaus
d59c5eff05
Generate 2048 DH group and add it to Postfix
9 gadus atpakaļ
Dan Milon
2fb7cfa7c9
Add SSL stapling cache for apache
Fixes #406
9 gadus atpakaļ
Sven Neuhaus
20bd80c599
Generate 2048 DH group and add it to Postfix
9 gadus atpakaļ
Dan Milon
34f3a483aa
Add SSL stapling cache for apache
Fixes #406
9 gadus atpakaļ
Dan Milon
a419d9403b
restart apache on SSL changes
9 gadus atpakaļ
Dan Milon
e063abaa51
properly install changed SSL certificate
9 gadus atpakaļ
Will McCutchen
16b66cc849
Define apache SSL config in one place
9 gadus atpakaļ
Luke Cyca
4bc4cebf41
Explicit permissions for all cert files
11 gadus atpakaļ
Luke Cyca
76d52b63f3
XMPP cert handling improvements, ufw rules, and tests
11 gadus atpakaļ
Luke Cyca
c697e135e9
Move NameVirtualHost directives to ports.conf
11 gadus atpakaļ
Luke Cyca
ca8a371320
Use combined cert for postfix, dovecot, and znc
Fix CAcert usage in postfix and dovecot
11 gadus atpakaļ
Luke Cyca
09c8fcb295
Named all tasks and made them idempotent where possible
11 gadus atpakaļ
Alex Payne
080d38986c
first commit
11 gadus atpakaļ