Jump to content

SSL certificate question


Recommended Posts

sonusfaber
Posted

Hello

I have Emby setup on Ubuntu Linux running at my home and exposed over the Internet and protected by the firewall. Everything is working very well and I am in the process to renew the .pfx certificate provided by my DNS provider.

I installed the certificate long time ago and at that time I did not noticed...

I have to specify the location on the Ubuntu filesystem of the .pfx file and provide the password. It is OK.

Question: Having to renew the certificate, I copy the new .pfx file, I fill in the path of the .pfx in the Emby server config, I provide the password and then i save the config.
Once the config has been saved, what should I do with the -pfx file? May I delete it from the filesystem? Or do I need t keep it in the server filesystem?

Other products using the certificate have a way to "import" the certificate and, once imported, you can delete the cert file from the filesystem

Regards

Q-Droid
Posted

If you use the same password when you renew certs and create the new pfx file then copy the new pfx on top of the old pfx (same path and name) then restart the Emby server. That's it. You only need to redo the settings if you change the file name, location and/or password.

You have to keep the pfx file at the location specified in the settings. Products that "import" the certs are also saving them somewhere even if you can delete the source.

There are other options like reverse proxies and tools which can automate cert renewal and deployment so you don't have to mess with it after setup.

 

sonusfaber
Posted

Ok. Got it.

Then the certificate must be hosted on the Emby filesystem.

 

Thanks.

Q-Droid
Posted

If we want to get specific the pfx file needs to be in a path the Emby server can read on startup. It doesn't matter which filesystem. 😉

What are your concerns over having the pfx on a filesystem? It's already password protected. 

sonusfaber
Posted

No concerns... just used to manage other applications that, once the certificate has been imported, I can remove it from the filesystem.

I Am ok.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...