update to letsencrypt v2.x

This commit is contained in:
AJ ONeal 2016-08-16 14:49:12 -06:00 committed by GitHub
parent d18bf7f3c5
commit 838eb46b78
1 changed files with 21 additions and 19 deletions

View File

@ -4,7 +4,6 @@
// //
// Configure LetsEncrypt // Configure LetsEncrypt
// //
var LEX = require('letsencrypt-express').testing();
var leConfDir = require('os').homedir() + '/letsencrypt/etc'; var leConfDir = require('os').homedir() + '/letsencrypt/etc';
throw new Error( throw new Error(
@ -12,18 +11,20 @@ throw new Error(
+ " Also, you'll need to remove .testing() and rm -rf '" + leConfDir + "'" + " Also, you'll need to remove .testing() and rm -rf '" + leConfDir + "'"
+ " to get actual, trusted production certificates."); + " to get actual, trusted production certificates.");
var lex = LEX.create({ var le = require('letsencrypt-express').create({
configDir: leConfDir server: 'staging' // in production use https://acme-v01.api.letsencrypt.org/directory
// leave `null` to disable automatic registration
, approveRegistration: function (hostname, cb) { , configDir: require('os').homedir() + '/letsencrypt/etc'
// Note: this is the place to check your database
// to get the user associated with this domain , approveDomains: function (opts, certs, cb) {
cb(null, { opts.domains = certs && certs.altnames || opts.domains;
domains: [hostname] opts.email = 'john.doe@example.com' // CHANGE ME
, email: 'CHANGE_ME' // user@example.com opts.agreeTos = true;
, agreeTos: true
}); cb(null, { options: opts, certs: certs });
} }
, debug: true
}); });
@ -33,10 +34,11 @@ var lex = LEX.create({
var hapi = require('hapi'); var hapi = require('hapi');
var https = require('spdy'); var https = require('spdy');
var server = new hapi.Server(); var server = new hapi.Server();
var acmeResponder = LEX.createAcmeResponder(lex); var acmeResponder = le.middleware();
var httpsServer = https.createServer(lex.httpsOptions).listen(443); var httpsServer = https.createServer(le.httpsOptions).listen(443);
server.connection({ listener: httpsServer, autoListen: false, tls: true }); server.connection({ listener: httpsServer, autoListen: false, tls: true });
server.route({ server.route({
method: 'GET' method: 'GET'
, path: '/.well-known/acme-challenge' , path: '/.well-known/acme-challenge'
@ -62,8 +64,8 @@ server.route({
// Redirect HTTP to HTTPS // Redirect HTTP to HTTPS
// //
var http = require('http'); var http = require('http');
http.createServer(LEX.createAcmeResponder(lex, function redirectHttps(req, res) { var redirectHttps = require('redirect-https')();
res.setHeader('Location', 'https://' + req.headers.host + req.url);
res.statusCode = 302; http.createServer(le.middleware(redirectHttps)).listen(80, function () {
res.end('<!-- Hello Developer Person! Please use HTTPS instead -->'); console.log('handle ACME http-01 challenge and redirect to https');
})).listen(80); });