{"id":31714797,"url":"https://github.com/gensecaihq/letsencrypt-ip-ssl-manager","last_synced_at":"2025-10-09T01:49:04.829Z","repository":{"id":306804141,"uuid":"1025605084","full_name":"gensecaihq/LetsEncrypt-IP-SSL-Manager","owner":"gensecaihq","description":"This tool simplifies the process of obtaining and managing Lets' Encrypt IP certificates with automatic renewal, comprehensive validation, and user ready features.","archived":false,"fork":false,"pushed_at":"2025-07-27T17:09:39.000Z","size":84,"stargazers_count":2,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2025-07-27T19:23:31.404Z","etag":null,"topics":["lets-encrypt","letsencrypt","letsencrypt-certificates","linux","open-source","ssl","ssl-certificates"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/gensecaihq.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"docs/SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2025-07-24T14:05:55.000Z","updated_at":"2025-07-27T17:09:43.000Z","dependencies_parsed_at":"2025-07-27T19:34:40.161Z","dependency_job_id":null,"html_url":"https://github.com/gensecaihq/LetsEncrypt-IP-SSL-Manager","commit_stats":null,"previous_names":["gensecaihq/letsencrypt-ip-ssl-manager"],"tags_count":null,"template":false,"template_full_name":null,"purl":"pkg:github/gensecaihq/LetsEncrypt-IP-SSL-Manager","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FLetsEncrypt-IP-SSL-Manager","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FLetsEncrypt-IP-SSL-Manager/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FLetsEncrypt-IP-SSL-Manager/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FLetsEncrypt-IP-SSL-Manager/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/gensecaihq","download_url":"https://codeload.github.com/gensecaihq/LetsEncrypt-IP-SSL-Manager/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/gensecaihq%2FLetsEncrypt-IP-SSL-Manager/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":279000707,"owners_count":26082895,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-10-08T02:00:06.501Z","response_time":56,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["lets-encrypt","letsencrypt","letsencrypt-certificates","linux","open-source","ssl","ssl-certificates"],"created_at":"2025-10-09T01:49:03.029Z","updated_at":"2025-10-09T01:49:04.822Z","avatar_url":"https://github.com/gensecaihq.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# Let's Encrypt IP Certificate Manager\n\n\u003cdiv align=\"center\"\u003e\n\n![License](https://img.shields.io/badge/license-MIT-blue.svg)\n![Version](https://img.shields.io/badge/version-3.0.0-green.svg)\n![Bash](https://img.shields.io/badge/bash-3.2%2B-orange.svg)\n![Certbot](https://img.shields.io/badge/certbot-2.0.0%2B-red.svg)\n![Production Ready](https://img.shields.io/badge/production-ready-brightgreen.svg)\n![Cross Platform](https://img.shields.io/badge/cross--platform-linux%20|%20bsd%20|%20macos-blue.svg)\n\n**Enterprise-grade Swiss Army Knife for managing Let's Encrypt SSL certificates for IP addresses**\n\n[Features](#features) • [Quick Start](#quick-start) • [Documentation](#documentation) • [Installation](#installation) • [Usage](#usage) • [FAQ](#faq) • [Contributing](#contributing)\n\n\u003c/div\u003e\n\n---\n\n## 🎉 Announcement\n\nAs of July 2025, [Let's Encrypt now supports SSL certificates for IP addresses](https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate/)! This is a significant milestone that enables HTTPS for services accessed directly via IP address.\n\nThis tool simplifies the process of obtaining and managing these IP certificates with automatic renewal, comprehensive validation, and production-ready features.\n\n## 🙏 Acknowledgments\n\nThis project is made possible by [Let's Encrypt](https://letsencrypt.org/), a free, automated, and open Certificate Authority. We extend our gratitude to:\n\n- **[Let's Encrypt](https://letsencrypt.org/)** - For providing free SSL certificates and pioneering IP address certificate support\n- **[Internet Security Research Group (ISRG)](https://www.abetterinternet.org/)** - For operating Let's Encrypt\n- **[Electronic Frontier Foundation (EFF)](https://www.eff.org/)** - For their contributions to Certbot and web security\n\n## ⚠️ Important Notes\n\n- **Staging Environment Only**: IP certificates are currently available only in Let's Encrypt's staging environment\n- **Short-lived Certificates**: IP certificates are valid for only 6 days (requires aggressive renewal)\n- **ACME Profile Support**: Requires Certbot 2.0.0+ with [ACME profile support](https://letsencrypt.org/2025/01/09/acme-profiles/)\n- **Public IPs Only**: Private or local IP addresses are not supported\n\n## 🚀 Quick Start\n\n```bash\n# Clone and setup\ngit clone https://github.com/yourusername/letsencrypt-ip-manager.git\ncd letsencrypt-ip-manager\nchmod +x letsencrypt-ip-ssl-manager.sh\n\n# Interactive setup (recommended for new users)\nsudo ./letsencrypt-ip-ssl-manager.sh --setup\n\n# Or quick certificate generation\nsudo ./letsencrypt-ip-ssl-manager.sh -i YOUR_PUBLIC_IP -e your@email.com\n```\n\n## 📚 Documentation\n\n- **[📖 User Manual](docs/USER_MANUAL.md)** - Complete usage guide\n- **[🔧 Installation Guide](docs/INSTALLATION.md)** - Step-by-step setup\n- **[🛠️ API Reference](docs/API_REFERENCE.md)** - All commands and options\n- **[🔍 Troubleshooting](docs/TROUBLESHOOTING.md)** - Common issues and solutions\n- **[🛡️ Security Guide](docs/SECURITY.md)** - Security best practices\n- **[🚀 Deployment Examples](docs/DEPLOYMENT.md)** - Production deployment scenarios\n\n## ✨ Features\n\n### 🌟 Core Capabilities\n- 🌐 **Universal IP Support**: IPv4 and IPv6 addresses with comprehensive validation\n- 🔒 **Smart Validation**: Ensures public IP addresses only, rejects private/reserved ranges\n- ⚡ **Aggressive Renewal**: Every 4 hours for 6-day certificates with multiple fallback mechanisms\n- 🎯 **Interactive Setup**: User-friendly configuration wizard with persistent settings\n\n### 🛡️ Enterprise Security\n- 🔐 **Input Sanitization**: Comprehensive validation preventing injection attacks\n- 🔒 **Secure Permissions**: Proper file permissions and access controls\n- 📋 **Audit Logging**: Complete audit trail for compliance and monitoring\n- 🚨 **Emergency Recovery**: Automatic backup and restore capabilities\n\n### 🌍 Cross-Platform Excellence  \n- 🐧 **Linux Distributions**: Debian, Ubuntu, RHEL, CentOS, Fedora, SUSE, Arch, Alpine, Gentoo\n- 🔺 **BSD Systems**: FreeBSD, OpenBSD, NetBSD, DragonFlyBSD  \n- 🍎 **macOS Support**: Limited support with Homebrew\n- ⚙️ **Multi-Init Systems**: SystemD, OpenRC, SysV, BSD RC, launchd\n\n### 🔧 Swiss Army Knife Tools\n- 📊 **System Monitoring**: Comprehensive status reports and health checks\n- 🗃️ **Backup Management**: Automated backup rotation with configurable retention\n- 🔄 **Auto-Recovery**: Intelligent error recovery with rollback capabilities\n- 🎨 **User Experience**: Colored output, progress indicators, helpful messages\n- 📈 **Dependency Management**: Automatic dependency detection and installation\n- 🔍 **Integrity Checking**: System integrity verification and validation\n\n## 📋 Requirements\n\n### System Requirements\n- **Operating System**: Linux (Debian/Ubuntu/RHEL/CentOS/Fedora/SUSE/Arch/Alpine/Gentoo), BSD (FreeBSD/OpenBSD/NetBSD), or macOS\n- **Privileges**: Root or sudo access for certificate operations\n- **Network**: Public IP address (IPv4 or IPv6) accessible from the internet\n- **Firewall**: Port 80 accessible for HTTP-01 challenge validation\n\n### Software Requirements\n- **Shell**: Bash 3.2+ (compatible with older systems)\n- **Certbot**: 2.0.0+ with ACME profile support (auto-installed if missing)\n- **Python**: 3.6+ (usually pre-installed)\n- **Utilities**: curl, openssl, DNS tools (auto-detected and installed)\n\n## 🚀 Installation\n\n### 🎯 Automated Installation (Recommended)\n\n```bash\n# Clone the repository\ngit clone https://github.com/yourusername/letsencrypt-ip-manager.git\ncd letsencrypt-ip-manager\n\n# Make the script executable\nchmod +x letsencrypt-ip-ssl-manager.sh\n\n# Interactive setup (handles everything automatically)\nsudo ./letsencrypt-ip-ssl-manager.sh --setup\n```\n\n### ⚡ Quick Installation\n\n```bash\n# Clone and install dependencies\ngit clone https://github.com/yourusername/letsencrypt-ip-manager.git\ncd letsencrypt-ip-manager\nchmod +x letsencrypt-ip-ssl-manager.sh\n\n# Install certbot and dependencies automatically\nsudo ./letsencrypt-ip-ssl-manager.sh --install\n\n# Configure settings interactively\nsudo ./letsencrypt-ip-ssl-manager.sh --configure\n```\n\n### Manual Installation\n\n1. **Install Dependencies** (if not using the script's auto-installer):\n\n   **Debian/Ubuntu:**\n   ```bash\n   sudo apt update\n   sudo apt install -y snapd python3 curl openssl dnsutils\n   sudo snap install --classic certbot\n   sudo ln -s /snap/bin/certbot /usr/bin/certbot\n   ```\n\n   **RHEL/CentOS/Fedora:**\n   ```bash\n   sudo yum install -y snapd python3 curl openssl bind-utils\n   sudo systemctl enable --now snapd.socket\n   sudo snap install --classic certbot\n   sudo ln -s /snap/bin/certbot /usr/bin/certbot\n   ```\n\n2. **Verify Certbot Version**:\n   ```bash\n   certbot --version  # Should be 2.0.0 or higher\n   ```\n\n## 📖 Usage\n\n### 🎯 Essential Commands\n\n```bash\n# Interactive setup for new users\nsudo ./letsencrypt-ip-ssl-manager.sh --setup\n\n# Get certificate for IPv4 address  \nsudo ./letsencrypt-ip-ssl-manager.sh -i 203.0.113.10 -e admin@example.com\n\n# Get certificate for IPv6 address\nsudo ./letsencrypt-ip-ssl-manager.sh -i 2001:db8::1 -e admin@example.com\n\n# Setup automatic renewal (CRITICAL for 6-day certs!)\nsudo ./letsencrypt-ip-ssl-manager.sh --setup-renewal\n\n# Check system status and health\nsudo ./letsencrypt-ip-ssl-manager.sh --status\n\n# View current configuration\n./letsencrypt-ip-ssl-manager.sh --show-config\n```\n\n### 🔧 Management Commands\n\n```bash\n# List all certificates and expiration status\nsudo ./letsencrypt-ip-ssl-manager.sh --list\n\n# Force renewal of all certificates\nsudo ./letsencrypt-ip-ssl-manager.sh --force-renew\n\n# Check available ACME profiles\nsudo ./letsencrypt-ip-ssl-manager.sh --check-profiles\n\n# Create manual backup\nsudo ./letsencrypt-ip-ssl-manager.sh --backup\n\n# Emergency recovery mode\nsudo ./letsencrypt-ip-ssl-manager.sh --emergency\n\n# System integrity check\n./letsencrypt-ip-ssl-manager.sh --integrity-check\n```\n\n### 📚 Complete Command Reference\n\n| Command | Description | Root Required |\n|---------|-------------|---------------|\n| **Certificate Operations** |\n| `-i, --ip IP_ADDRESS` | Public IP address (IPv4 or IPv6) for certificate | ✅ |\n| `-e, --email EMAIL` | Email address for certificate notifications | ✅ |\n| `-w, --webroot PATH` | Webroot path for HTTP-01 challenge (default: /var/www/html) | ✅ |\n| **Interactive Setup** |\n| `--setup` | Quick interactive setup for new users | ✅ |\n| `--configure` | Interactive configuration wizard | ✅ |\n| `--show-config` | Display current configuration | ❌ |\n| **Management Operations** |\n| `--install` | Install certbot with profile support | ✅ |\n| `--renew` | Renew existing IP certificates | ✅ |\n| `--force-renew` | Force renewal of all certificates | ✅ |\n| `--setup-renewal` | Configure automatic renewal (every 4 hours) | ✅ |\n| `--list` | List all certificates and expiration status | ✅ |\n| `--check-profiles` | Show available ACME profiles | ✅ |\n| **Information \u0026 Diagnostics** |\n| `-h, --help` | Show comprehensive help message | ❌ |\n| `-v, --version` | Show version information | ❌ |\n| `--status` | Generate comprehensive system status report | ❌ |\n| `--integrity-check` | Perform system integrity verification | ❌ |\n| `--debug` | Enable debug logging for troubleshooting | ❌ |\n| **Maintenance \u0026 Recovery** |\n| `--backup` | Create manual backup of configuration and certificates | ✅ |\n| `--restore` | Interactive restore from backup | ✅ |\n| `--emergency` | Emergency recovery mode with guided restoration | ✅ |\n\n### Complete Workflow Example\n\n```bash\n# 1. Clone and setup (recommended)\ngit clone https://github.com/yourusername/letsencrypt-ip-manager.git\ncd letsencrypt-ip-manager\nchmod +x letsencrypt-ip-ssl-manager.sh\nsudo ./letsencrypt-ip-ssl-manager.sh --setup\n\n# 2. Or manual steps\nsudo ./letsencrypt-ip-ssl-manager.sh --install\ncurl -4 icanhazip.com  # Check your public IPv4\nsudo ufw allow 80/tcp  # Open port 80 if using ufw\nsudo ./letsencrypt-ip-ssl-manager.sh -i YOUR_PUBLIC_IP -e your-email@example.com\nsudo ./letsencrypt-ip-ssl-manager.sh --setup-renewal\n\n# 3. Verify everything is working\nsudo ./letsencrypt-ip-ssl-manager.sh --status\nsudo ./letsencrypt-ip-ssl-manager.sh --list\n```\n\n## 📁 File Locations\n\n### Certificates\n- **Live certificates**: `/etc/letsencrypt/live/YOUR_IP/`\n  - `cert.pem` - Certificate\n  - `privkey.pem` - Private key\n  - `chain.pem` - Intermediate certificates\n  - `fullchain.pem` - Certificate + intermediates\n\n### Logs\n- **Main log**: `/var/log/letsencrypt-ip-manager/ip-certificate.log`\n- **Error log**: `/var/log/letsencrypt-ip-manager/error.log`\n- **Audit log**: `/var/log/letsencrypt-ip-manager/audit.log`\n- **Renewal log**: `/var/log/letsencrypt-ip-manager/renewal.log`\n\n### Configuration\n- **Systemd timer**: `/etc/systemd/system/certbot-ip-renew.timer`\n- **Systemd service**: `/etc/systemd/system/certbot-ip-renew.service`\n- **Cron job**: `/etc/cron.d/certbot-ip-renew`\n\n## 🔧 Web Server Configuration\n\n### Nginx Example\n\n```nginx\nserver {\n    listen YOUR_IP:443 ssl http2;\n    \n    ssl_certificate /etc/letsencrypt/live/YOUR_IP/fullchain.pem;\n    ssl_certificate_key /etc/letsencrypt/live/YOUR_IP/privkey.pem;\n    \n    # Modern SSL configuration\n    ssl_protocols TLSv1.2 TLSv1.3;\n    ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384;\n    ssl_prefer_server_ciphers off;\n    \n    location / {\n        root /var/www/html;\n        index index.html;\n    }\n}\n\n# HTTP to HTTPS redirect\nserver {\n    listen YOUR_IP:80;\n    return 301 https://$host$request_uri;\n}\n```\n\n### Apache Example\n\n```apache\n\u003cVirtualHost YOUR_IP:443\u003e\n    SSLEngine on\n    SSLCertificateFile /etc/letsencrypt/live/YOUR_IP/cert.pem\n    SSLCertificateKeyFile /etc/letsencrypt/live/YOUR_IP/privkey.pem\n    SSLCertificateChainFile /etc/letsencrypt/live/YOUR_IP/chain.pem\n    \n    # Modern SSL configuration\n    SSLProtocol -all +TLSv1.2 +TLSv1.3\n    SSLCipherSuite ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384\n    \n    DocumentRoot /var/www/html\n\u003c/VirtualHost\u003e\n\n# HTTP to HTTPS redirect\n\u003cVirtualHost YOUR_IP:80\u003e\n    Redirect permanent / https://YOUR_IP/\n\u003c/VirtualHost\u003e\n```\n\n## ❓ FAQ\n\n### Why are IP certificates only available in staging?\nLet's Encrypt is gradually rolling out IP certificate support. Production availability is expected later in 2025.\n\n### Why do IP certificates only last 6 days?\nShort-lived certificates enhance security by limiting the window of exposure if a private key is compromised. They also align with Let's Encrypt's automation philosophy.\n\n### Can I use this for private IP addresses?\nNo, Let's Encrypt only issues certificates for publicly routable IP addresses. Private IPs (192.168.x.x, 10.x.x.x, etc.) are not supported.\n\n### What happens if renewal fails?\nThe script sets up multiple renewal mechanisms (systemd timer + cron) running every 4 hours. It also logs all renewal attempts for troubleshooting.\n\n### Can I use DNS-01 challenge instead of HTTP-01?\nNo, DNS-01 challenge is not supported for IP address certificates.\n\n## 🐛 Troubleshooting\n\n### Common Issues\n\n1. **\"Port 80 is not accessible\"**\n   - Ensure firewall allows port 80: `sudo ufw allow 80/tcp`\n   - Check if another service is using port 80: `sudo netstat -tlnp | grep :80`\n\n2. **\"IP address appears to be private\"**\n   - Verify you're using your public IP: `curl -4 icanhazip.com`\n   - Check if you're behind NAT/proxy\n\n3. **\"Certbot version too old\"**\n   - Update certbot: `sudo snap refresh certbot`\n   - Or reinstall: `sudo ./letsencrypt-ip-manager.sh --install`\n\n4. **\"Certificate expired\"**\n   - Check renewal timer: `sudo systemctl status certbot-ip-renew.timer`\n   - Force renewal: `sudo ./letsencrypt-ip-manager.sh --force-renew`\n\n### Debug Mode\n\nEnable detailed logging:\n```bash\nsudo DEBUG=true ./letsencrypt-ip-manager.sh -i YOUR_IP -e your@email.com\n```\n\n## 🤝 Contributing\n\nContributions are welcome! Please feel free to submit a Pull Request. For major changes, please open an issue first to discuss what you would like to change.\n\n1. Fork the repository\n2. Create your feature branch (`git checkout -b feature/AmazingFeature`)\n3. Commit your changes (`git commit -m 'Add some AmazingFeature'`)\n4. Push to the branch (`git push origin feature/AmazingFeature`)\n5. Open a Pull Request\n\n## 📄 License\n\nThis project is licensed under the MIT License - see the [LICENSE](LICENSE) file for details.\n\n## 🔗 Resources\n\n- [Let's Encrypt - IP Address Certificates Announcement](https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate/)\n- [Let's Encrypt - ACME Profiles](https://letsencrypt.org/2025/01/09/acme-profiles/)\n- [Let's Encrypt - Staging Environment](https://letsencrypt.org/docs/staging-environment/)\n- [Certbot Documentation](https://certbot.eff.org/)\n- [ACME Protocol Specification](https://datatracker.ietf.org/doc/html/rfc8555)\n\n## ⭐ Star History\n\nIf you find this tool useful, please consider giving it a star on GitHub!\n\n---\n\n\u003cdiv align=\"center\"\u003e\n\nMade with ❤️ for the community by developers who believe in a secure and open internet.\n\nSpecial thanks to [Let's Encrypt](https://letsencrypt.org/) for making HTTPS accessible to everyone.\n\n\u003c/div\u003e","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgensecaihq%2Fletsencrypt-ip-ssl-manager","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fgensecaihq%2Fletsencrypt-ip-ssl-manager","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fgensecaihq%2Fletsencrypt-ip-ssl-manager/lists"}