@@ -6,8 +6,6 @@ o Furthermore, that there is a ~/acme-challenge and that is aliased in apache:
| Alias "/.well-known/acme-challenge" "/srv/letsencrypt/acme-challenge"
o Also, we want an account key in ~:
(umask 277 && ! [ -e account.key ] && openssl genrsa 4096 > account.key)
-o And you want the letsencrypt chain file lets-encrypt-x1-cross-signed.pem
- in ~/certs/extra
o Optionally, a dh file in ~/certs/extra/dh-4096.pem
openssl dhparam -out ~/certs/extra/dh-4096.pem 4096
o And you want this bin directory in PATH for your letsencrypt role user.