This article is for ubuntu admins only
Before you start - make sure you have acquired a .pfx certificate for the proper domain as well as the password for the .pfx certificate.
Make sure the domain points to the external domain of the DMCS. If the DMCS is not available on the internet - make sure that you have a local DNS service to validate the certificate
Upload the certificate to the server:
scp -i ~/.ssh/yourkey.pem Downloads/certificatename.pfx admin@dmcs-domain:/home/myfolder/Find the location of the certs volume:
docker volume inspect certsMove the pfx file to the certs directory:
mv /home/myfolder/certificatename.pfx /mnt/docker/volumes/certs/_data/Go to the certs directory:
cd /mnt/docker/volumes/certs/_data/Rename the pfx file:
mv certificatename.pfx cert.pfxExtract the private key:
openssl pkcs12 -in cert.pfx -nocerts -out key.pemExtract the full certificate chain (leaf + intermediates):
openssl pkcs12 -in cert.pfx -nokeys -out fullchain.pemRemove the passphrase from the key:
openssl pkey -in key.pem -out privkey.pemVerify the chain file contains more than one certificate and that the first one is your domain:
grep -c 'BEGIN CERT' fullchain.pem openssl x509 -in fullchain.pem -noout -subjectRestart nginx so the new certificate takes effect:
docker restart nginx