add wildcard ACME certificate

This commit is contained in:
Alexander Tomokhov
2023-12-19 01:07:05 +04:00
parent 312077240a
commit b37cadff68
9 changed files with 45 additions and 40 deletions

View File

@@ -28,8 +28,8 @@ in
tcp-port = 8443
udp-port = 8443
server-cert = /var/lib/acme/${domain}/fullchain.pem
server-key = /var/lib/acme/${domain}/key.pem
server-cert = /var/lib/acme/wildcard-${domain}/fullchain.pem
server-key = /var/lib/acme/wildcard-${domain}/key.pem
compression = true
@@ -56,8 +56,8 @@ in
'';
};
services.nginx.virtualHosts."vpn.${domain}" = {
sslCertificate = "/var/lib/acme/${domain}/fullchain.pem";
sslCertificateKey = "/var/lib/acme/${domain}/key.pem";
sslCertificate = "/var/lib/acme/wildcard-${domain}/fullchain.pem";
sslCertificateKey = "/var/lib/acme/wildcard-${domain}/key.pem";
forceSSL = true;
extraConfig = ''
add_header Strict-Transport-Security $hsts_header;