Hi all,
I am trying to install a lets encrypt certificate generated via certbot
that comes with debian/ubuntu.
It gives me the following files
cert.pem
chain.pem
fullchain.pem (a combination of the previous two it looks like)
privkey.pam
I disabled the generate self-signed key in scfg. But I left both cryptlib.key and ssl.cert in place.
Things that i have tried.
1.
jsexec certtool --import ./fullchain.pem
result: "!JavaScript /home/synchronet/sbbs/exec/certtool.js line 70:
Error: CryptLib error -43"
The fullchain.pem looks the same as the example here https://wiki.synchro.net/module:certtool
2.
I tried adding the folloing to the bottom of the [Mail] section in
sbbs.ini:
Secure = true
CertificateFile = ./ssl_certs/fullchain.pem
KeyFile = ./cryptlib.key
result: cannot connenct to port 995
Re: How do I install an Lets Encrypt Certificate.
By: Mojo to DOVE-Net.Synchronet_Sysops on Thu Nov 06 2025 11:50 am
Hi all,
I am trying to install a lets encrypt certificate generated via
certbot that comes with debian/ubuntu.
It gives me the following files
cert.pem
chain.pem
fullchain.pem (a combination of the previous two it looks like) privkey.pam
I disabled the generate self-signed key in scfg. But I left both cryptlib.key and ssl.cert in place.
Things that i have tried.
1.
jsexec certtool --import ./fullchain.pem
result: "!JavaScript /home/synchronet/sbbs/exec/certtool.js line
70: Error: CryptLib error -43"
cryptlib.h:#define CRYPT_ERROR_NOTFOUND ( -43 ) /* Requested item not
found in object */
I'd try that again with a different/bogus path to the pem file to see
if the error changes (i.e. it's complaining about an object *within*
the file instead of the file itself).
The fullchain.pem looks the same as the example here https://wiki.synchro.net/module:certtool
That's promising.
2.
I tried adding the folloing to the bottom of the [Mail] section in sbbs.ini:
Secure = true
CertificateFile = ./ssl_certs/fullchain.pem
KeyFile = ./cryptlib.key
Those keys don't seem to be supported or documented anywhere. How'd
you come up with that?
Its failing due to the keys I added to the [Mail] section.result: cannot connenct to port 995
That just suggests that your TCP port 995 isn't open or sbbs isn't
listening on it. The [mail] Options TLS_POP3 option must be included
(which is by default) and the TLSPOP3Port option must be set to 995
(also the default) and your sbbs log output (e.g. syslog) would tell
if if it's in fact listening on that port or not. This is completely unrelated to any certificate or key file.
2.
I tried adding the folloing to the bottom of the [Mail] section in sbbs.ini:
Secure = true
CertificateFile = ./ssl_certs/fullchain.pem
KeyFile = ./cryptlib.key
Those keys don't seem to be supported or documented anywhere. How'd
you come up with that?
I saw them here so just tried them. https://nettwerked.synchronetbbs.org/?page= 001-forum.ssjs&sub=dove-syncdisc&thread=1575
Its failing due to the keys I added to the [Mail] section.
*** SSL/TLShandshake failed ***
Re: Re: How do I install an Lets Encrypt Certificate.
By: Mojo to All on Thu Nov 06 2025 10:59 pm
2.
I tried adding the folloing to the bottom of the [Mail]
section in sbbs.ini:
Secure = true
CertificateFile = ./ssl_certs/fullchain.pem
KeyFile = ./cryptlib.key
Those keys don't seem to be supported or documented anywhere.
How'd you come up with that?
I saw them here so just tried them. https://nettwerked.synchronetbbs.org/?page= 001-forum.ssjs&sub=dove-syncdisc&thread=1575
I'm guessing that's just some AI slop. Those keys in sbbs.ini "CertificateFile" and "KeyFile" and "Secure" will do absolutely
nothing.
Its failing due to the keys I added to the [Mail] section.
*** SSL/TLShandshake failed ***
No, those keys you added will be ignored and have no effect on the
mail server.
So there is no way of using already existing key/cert pair from LE
other than thru the module or go with the self-generated cert that sbbs does? That is getting them into ctrl/ssl.cert.
| Sysop: | Fercho |
|---|---|
| Lugar: | La Plata, Buenos Aires |
| Usuarios: | 27 |
| Nodos: | 10 (0 / 10) |
| Uptime: | 14:21:53 |
| Llamadas: | 131 |
| Archivoss: | 15,607 |
| Mensajes: | 38,833 |
Novedades:
Servidor de Quake 3 Arena Online! - Conectate a ferchobbs.ddns.net, puerto 27960 y vence con tu equipo!