Skip to content

Commit b9476ca

Browse files
authored
don't use a keyfile for ssl cert (#265)
1 parent 4141c17 commit b9476ca

File tree

2 files changed

+1
-3
lines changed

2 files changed

+1
-3
lines changed

docker-assets/docker-entrypoint.sh

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -38,8 +38,7 @@ if [ $SSL_ENABLED = true ] ; then
3838
## generate cert if not present
3939
if [ ! -f /certs/cert.pem ] ; then
4040
mkdir -p /certs
41-
openssl req -x509 -newkey rsa:4096 -keyout /certs/key.pem -out /certs/cert.pem -days 365 -passout pass:'sigmaprime' -subj "/C=AU/CN=siren/emailAddress=noreply@sigmaprime.io"
42-
echo 'sigmaprime' > /certs/key.pass
41+
openssl req -nodes -x509 -newkey rsa:4096 -keyout /certs/key.pem -out /certs/cert.pem -days 365 -subj "/C=AU/CN=siren/emailAddress=noreply@sigmaprime.io"
4342
fi
4443
ln -s /app/docker-assets/siren-https.conf /etc/nginx/conf.d/siren-https.conf
4544
fi

docker-assets/siren-https.conf

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@ server {
33
listen 443 ssl;
44
ssl_certificate /certs/cert.pem;
55
ssl_certificate_key /certs/key.pem;
6-
ssl_password_file /certs/key.pass;
76
ssl_protocols TLSv1.3;
87
ssl_ciphers HIGH:!aNULL:!MD5;
98

0 commit comments

Comments
 (0)