X-Git-Url: https://git.ralfj.de/lets-encrypt-tiny.git/blobdiff_plain/b2e264ae28b45fe07844a7d9d19f8e7f81cf40cf..26bdda3d0efd554a0abb5d590967323976a09817:/letsencrypt-tiny.conf.sample diff --git a/letsencrypt-tiny.conf.sample b/letsencrypt-tiny.conf.sample index d2535e5..4c28d17 100644 --- a/letsencrypt-tiny.conf.sample +++ b/letsencrypt-tiny.conf.sample @@ -5,16 +5,24 @@ domains = example.org example.com -# File containing the DH parameters, as generated by openssl (optional) -dh-params = /etc/ssl/dh2048.pem +# The length of secret RSA keys +key-length = 4096 + +[timing] +# After how many days should the private key be re-generated? +max-key-age-days = 180 +# How many hours should a new private key be left in staging? (0 for no staging) +staging-hours = 25 +# How many days before a certificate expires, should it be renewed? +renew-cert-before-expiry-days = 15 [hooks] # Called after a new certificate has been obtained. -# Example usage: Reloading services. -post-cert = /home/user/letsencrypt/cert-hook +# Example usage: Reloading services, generating combined "certificate + key chain" file. +post-certchange = /home/user/letsencrypt/cert-hook # Called after a new certificate has been obtained, *if* there also were changes in the private keys # Example usage: Updating TLSA records (with the selector being SubjectPublicKeyInfo) in the zone -post-key = /home/user/letsencrypt/key-hook +post-keychange = /home/user/letsencrypt/key-hook # Parameters for acme-tiny [acme]