<!DOCTYPE HTML>
<html>
<head>
<title>plan9 - lets encrypt</title>
<style media="screen, handheld">
body { display: flex; flex-wrap: wrap; font-family: sans;}
header { flex-basis: 100%; flex-shrink: 0; }
article { flex-basis: 60%; padding-left: 1em; }
footer { flex-basis: 100%; flex-shrink: 0; }
header nav { display: flex; justify-content: space-between; }
nav a, header a { text-decoration: none ; color: inherit; }
header h1 span { margin-left: 1em; font-size: 50%; font-style: italic; }
.mainContent > nav { flex-basis: content; padding-right: 1vw; min-width: 16em; }
nav ul { display: flex; flex-direction: column; list-style-type: none; list-style-position: outside; padding-left: 0; }
nav li ul { padding-left: 0.6em }
footer { display: flex; justify-content: space-between; }
/* cut here to leave vanity behind */
body { margin:0; padding: 0; font-size: 84%; font-family: Helvetica, Verdana, Arial, 'Liberation Sans', FreeSans, sans-serif; }
a { text-decoration: none; color: }
a:hover { text-decoration: underline; }
.thisPage { color: black; }
/* header and top bar */
header nav { background-color: rgb(100,135,220); color: white; padding: 0.3em; border-bottom: 2px solid black; font-size: 91%; }
header h1 { background-color: #ff6d06; color: black; margin: 0; border-bottom: 2px solid black; font-weight: normal; padding: 0.25ex; font-size: 233%; }
header a:hover { text-decoration: none; }
/* sidebar */
.mainContent > nav { border-right: 1px solid #ddd; padding: 0; }
.mainContent > nav > div { border-bottom: 1px solid #ddd; }
.mainContent > nav > div a { color: rgb(0, 102, 204); display: block; text-transform: capitalize; font-weight: bold; padding: 0.25em 1ex 0.25em 2mm; font-size: 102%}
.mainContent > nav > div a:hover { color: white; background-color: rgb(100,135,220); border-left: black solid 0.2em; text-decoration: none; }
.mainContent > nav > div p { font-weight: bold; margin: 0 0 0.5em 2mm; padding: 1em 0 0 0; }
/* main copy */
article { padding: 0.5ex 0 5vh 1vw; }
article h1, article h2 { color: rgb(0,102,204); font-weight: bold; margin: 2em 0 0 0; border-bottom: 2px solid rgb(0,102,204); }
article h3, article h4, article h5 { color: rgb(0,102,204); font-weight: bold; margin: 2em 0 0 0; }
article h6, article h7, article h8 { color: rgb(0,102,204); font-weight: bold; margin: 2em 0 0 0; }
article a { color: rgb(0,102,204); }
article a:hover { color: rgb(100,135,220); }
article pre { font-size: 1.2em; }
/* footer */
footer { color: white; background-color: rgb(100,135,220); }
footer a { color: inherit; }
footer div { padding: 1em; }
/* tables */
table { border: 1px solid rgba(128,128,128,0.5); padding: 0; }
th { color: white; background-color: rgb(100,135,220); }
tr:nth-child(odd) { background-color: rgba(128,128,128,0.1) }
/* modifications */
img {
max-width: 100%;
border: 1px solid black;
}
body {
}
header h1 {
background-color: #c2d2c6;
}
html {
font-size: 1.2em;
}
header nav, footer {
background-color: #442a13;
}
code > pre {
border: 2px solid #442a13;
background-color: #c2d2c6;
width: max-content;
padding: 0 0.5em;
}
.mainContent > nav > div a, article a:hover {
color: #442a13;
}
.mainContent > nav > div a:hover {
color: #442a13;
background-color: #c2d2c6;
}
article h1, article h2 {
color: #c48f3b;
border-bottom: 2px solid #442a13;
}
article a, .thisPage, footer, header nav {
color: #c48f3b;
}
footer {
padding: 0.5em;
flex-shrink: 1;
flex-basis: unset;
}
header {
flex-basis: unset;
}
html {
display: flex;
min-height: 100%;
}
body {
flex-direction: column;
flex: 1;
background-color: #e3dfd7;
}
.mainContent {
display: flex;
flex-grow: 1;
} </style>
<link rel="shortcut icon" href="https://images.pmikkelsen.com/favicon.ico" type="image/vnd.microsoft.icon">
<meta charset="UTF-8">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<header>
<nav>
<div class="left">
<a href="https://pmikkelsen.com">notes</a> |
<a href="https://git.pmikkelsen.com">git</a> |
<a href="https://images.pmikkelsen.com">images</a> |
<a href="https://files.pmikkelsen.com">files</a> |
<a href="https://prolog.pmikkelsen.com">PProlog</a> |
<a href="https://apl.pmikkelsen.com">APL9</a> |
<a href="https://aplwc.org">aplwc</a>
</div>
<div class="right">
<a href="https://git.sr.ht/~pmikkelsen">sourcehut</a> |
<a href="https://9front.org">9front</a> |
<a href="https://openbsd.org">OpenBSD</a> |
<a href="https://dyalog.com">Dyalog</a>
</div>
</nav>
<h1><a href="../index.html">Peter's website <span id="headerSubTitle">- random notes</span></a></h1>
</header>
<div class=mainContent>
<nav id="side-bar">
<div>
<ul>
<li><a href="../APL-and-J/index.html">› APL and J/</a></li>
<li><a href="../OpenBSD/index.html">› OpenBSD/</a></li>
<li><a href="../contact.html">› contact</a></li>
<li><a href="../facts/index.html">› facts/</a></li>
<li><a href="../haskell/index.html">› haskell/</a></li>
<li><a href="../linux/index.html">› linux/</a></li>
<li><a href="../mainframe/index.html">› mainframe/</a></li>
<li><a href="../me/index.html">› me/</a></li>
<li><a href="../opinions/index.html">› opinions/</a></li>
<li><a href="index.html" class="thisPage">»<i> plan9/</i></a></li>
<li><ul>
<li><a href="basic_9p_server.html">› basic 9p server</a></li>
<li><a href="discord.html">› discord</a></li>
<li><a href="dns.html">› dns</a></li>
<li><a href="fonts.html">› fonts</a></li>
<li><a href="lets_encrypt.html" class="thisPage">»<i> lets encrypt</i></a></li>
<li><a href="mounting-9p-over-drawterm.html">› mounting 9p over drawterm</a></li>
<li><a href="network_booting.html">› network booting</a></li>
<li><a href="trellofs.html">› trellofs</a></li>
<li><a href="using_irc.html">› using irc</a></li>
<li><a href="webfs-websocket.html">› webfs websocket</a></li>
</ul></li>
<li><a href="../prolog/index.html">› prolog/</a></li>
<li><a href="../web/index.html">› web/</a></li>
</ul>
</div>
</nav>
<article>
<h2>How I get tls certificates for 9front</h2>
<p>First of all, I use linux and drawterm for this for now, but I would like to be able to do it all from 9front at some point.</p>
<h2>Generate the certificate</h2>
<p>Install certbot on linux and run the following command</p>
<code><pre>
certbot certonly --manual -d pmikkelsen.com -d vps1.pmikkelsen.com
</pre></code>
<p>and do the challenges, they should be easy. I use the diff <a href="https://files.pmikkelsen.com/ndb.diff">here</a> to make 9fronts dns server understand the needed records.</p>
<p><strong>EDIT</strong>: As of Sun Feb 14 2021, this patch is no longer needed since cinap pushed a <a href="http://code.9front.org/hg/plan9front/rev/73935ff27172">proper fix</a>.</p>
<h2>Importing the cert and private key</h2>
<p>Start drawterm and login as the hostowner. After this, the filesystem of the linux system is available at <code>/mnt/term</code>. Run the following:</p>
<code><pre>
cd /sys/lib/tls/
cp /mnt/term/etc/letsencrypt/live/pmikkelsen.com/privkey.pem ./
cp /mnt/term/etc/letsencrypt/live/pmikkelsen.com/fullchain.pem ./cert
</pre></code>
<p>Now the private key must be converted to one that can be loaded into factotum</p>
<code><pre>
auth/pemdecode 'PRIVATE KEY' privkey.pem | auth/asn12rsa -t 'service=tls role=client' > key
rm privkey.pem
chmod 400 key
</pre></code>
<p>Add the following to <code>/cfg/$sysname/cpurc</code> to load the private key on boot.</p>
<code><pre>
cat /sys/lib/tls/key >> /mnt/factotum/ctl
</pre></code>
<p>Done. The key can also be stored in secstore if that is setup, so it doesn't lay unencryped on the disk.</p>
<h2>SMTP over TLS</h2>
<p>I have the following in <code>/bin/service.auth/tcp25</code></p>
<code><pre>
#!/bin/rc
user=`{cat /dev/user}
exec upas/smtpd -c /sys/lib/tls/cert -n $3
</pre></code>
<p>Notice I had to put it in the <code>/bin/service.auth</code> folder so that it could find the private key.</p>
<h2>Https with rc-httpd</h2>
<p>I have the following in <code>/bin/service.auth/tcp443</code></p>
<code><pre>
#!/bin/rc
exec tlssrv -c /sys/lib/tls/cert -l /sys/log/https /bin/service/tcp80 $*
</pre></code>
<p>Again, in the <code>/bin/service.auth</code> folder. It simply wraps the plain http service in a tls wrapper. The plain tcp80 service looks like this for me</p>
<code><pre>
#!/bin/rc
PLAN9=/
auth/none /rc/bin/rc-httpd/rc-httpd >>[2]/sys/log/www
</pre></code>
</article>
</div>
<footer>
<a href="http://werc.cat-v.org">Powered by werc</a> © Peter Mikkelsen 2019-2025
</footer>
</body></html>