From: Stefan Huber Date: Mon, 13 Sep 2021 08:05:24 +0000 (+0200) Subject: letsencrypt: Add path for iptables X-Git-Url: https://git.sthu.org/?p=shutils.git;a=commitdiff_plain;h=dfe38bbeeb301bd49ac99a2ca26042cb60290f7f letsencrypt: Add path for iptables --- diff --git a/letsencrypt/renewal.sh b/letsencrypt/renewal.sh index e6a4658..83f3f44 100644 --- a/letsencrypt/renewal.sh +++ b/letsencrypt/renewal.sh @@ -13,8 +13,8 @@ PORT80=$(lsof -ti :80 | wc -l) if [ $PORT80 = 0 ]; then cd /var/www/challenges nohup python3 -m http.server 80 > /dev/null 2>&1 & - iptables -A INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT - ip6tables -A INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/iptables -A INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/ip6tables -A INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT fi @@ -55,7 +55,7 @@ done # Stop temp web server and close port 80 if needed. if [ $PORT80 = 0 ]; then - iptables -D INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT - ip6tables -D INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/iptables -D INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT + /usr/sbin/ip6tables -D INPUT -i venet0 -p tcp --dport 80 -m conntrack --ctstate NEW -j ACCEPT pkill -f http.server fi