add wildcard ACME certificate

This commit is contained in:
Alexander Tomokhov
2023-12-19 01:07:05 +04:00
parent 312077240a
commit b37cadff68
9 changed files with 45 additions and 40 deletions

View File

@@ -72,8 +72,8 @@ in
'';
};
services.nginx.virtualHosts."password.${sp.domain}" = {
sslCertificate = "/var/lib/acme/${sp.domain}/fullchain.pem";
sslCertificateKey = "/var/lib/acme/${sp.domain}/key.pem";
sslCertificate = "/var/lib/acme/wildcard-${sp.domain}/fullchain.pem";
sslCertificateKey = "/var/lib/acme/wildcard-${sp.domain}/key.pem";
forceSSL = true;
extraConfig = ''
add_header Strict-Transport-Security $hsts_header;