Comprehensive data protection for all workloads
Post Reply
Loosus456
Novice
Posts: 6
Liked: 1 time
Joined: Sep 29, 2021 12:22 pm
Full Name: Jason
Contact:

Automating certificate renewal for web UI (TCP 443) on Veeam Software Appliance?

Post by Loosus456 »

We use Let's Encrypt along with the DNS-01 challenge to renew our wildcard certificate (*[.]example[.]com) every 45 days. We have a virtual machine that takes care of the wildcard renewal, retrieves the new wildcard files and private keys, stores the new wildcard files, and runs an SFTP server that serves the certificate files to other servers that need them. For security purposes, servers that need the certificate files reach out to the certificates VM rather than the certificates VM reaching out to them.

We need to rotate the web UI certificate every 45 days (or more often). We need to automate rotation because manual replacement obviously isn't really a thing these days.
  1. Can I store a simple bash script on the Veeam Software Appliance to retrieve the wildcard certificate from our certificates VM? If so, is there a preferred directory path where I should store it?
  2. Can I run a cron job on VSA under the root account?
  3. Will VSA updates/upgrades eventually blow away our bash script and cron job? If so, is there a way to prevent that from happening?
  4. Assuming I can put a bash script and associated cron job on the VSA server, which certificate file and private key file do I need to have the bash script replace/rotate? What is the directory path to those files? After replacement, do any services/daemons need to be restarted for the replacement to take effect?
Post Reply

Who is online

Users browsing this forum: Semrush [Bot] and 193 guests