Hello
I setup ssl in MAIN and LB, when MAIN stream ssl working perfectly but not in LB
when LB stream anyone picks up users (Username and Password)
nginx.conf in MAIN and LB
server {
#listen 25461;
listen 25463 ssl;
ssl_certificate /etc/ssl/MYdomain/MYdomain.crt;ssl_certificate_key /etc/ssl/MYdomain/MYdomain.key;
ssl_protocols SSLv3 TLSv1.1 TLSv1.2;
can someone help please
# Generiši self-signed certifikat
Korak 1 - Generiši certifikat
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
-keyout /home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.key \
-out /home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.crt \
-subj "/C=BA/ST=FBiH/L=Sarajevo/O=IPTV/CN=$(curl -s
https://ifconfig.me)"
rm /home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.crt
rm /home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.key
openssl req -x509 -nodes -days 3650 -newkey rsa:2048 \
-keyout /home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.key \
-out /home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.crt \
-subj "/C=BA/ST=FBiH/L=xxxx/O=IPTV/CN=ip adress" && \
echo "Certifikat OK" && \
/home/xtreamcodes/iptv_xtream_codes/start_services.sh
# Pokreni nginx
/home/xtreamcodes/iptv_xtream_codes/nginx/sbin/nginx
# Instaliraj certbot
apt-get install -y certbot
# Zaustavi nginx privremeno
killall nginx 2>/dev/null
# Generiši certifikat za tvoju domenu
certbot certonly --standalone -d domena \
--agree-tos --no-eff-email -m here email
# Linkaj certifikate
ln -sf /etc/letsencrypt/live/domena/fullchain.pem \
/home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.crt
ln -sf /etc/letsencrypt/live/domena/privkey.pem \
/home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.key
# Pokreni nginx
/home/xtreamcodes/iptv_xtream_codes/nginx/sbin/nginx
iptables -I INPUT -p tcp --dport 80 -j ACCEPT
killall nginx 2>/dev/null
sleep 2
certbot certonly --standalone -d domena\
--agree-tos --email here email --non-interactive
ln -sf /etc/letsencrypt/live/domena/fullchain.pem \
/home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.crt
ln -sf /etc/letsencrypt/live/domena/privkey.pem \
/home/xtreamcodes/iptv_xtream_codes/nginx/conf/server.key
/home/xtreamcodes/iptv_xtream_codes/start_services.sh
dig domena +short
Ili da ne edituje ručno, pokreni ovu sed komandu:
sed -i 's/ listen 25500;/ listen 25500 ssl;\n ssl_certificate \/home\/xtreamcodes\/iptv_xtream_codes\/nginx\/conf\/server.crt;\n ssl_certificate_key \/home\/xtreamcodes\/iptv_xtream_codes\/nginx\/conf\/server.key;\n ssl_protocols TLSv1.2 TLSv1.3;\n ssl_session_cache shared:SSL:10m;\n ssl_session_timeout 1d;/' /home/xtreamcodes/iptv_xtream_codes/nginx/conf/nginx.conf
# Test i restart
/home/xtreamcodes/iptv_xtream_codes/nginx/sbin/nginx -t && \
killall nginx 2>/dev/null && sleep 1 && \
/home/xtreamcodes/iptv_xtream_codes/start_services.sh