diff --git a/Containers/apache/Caddyfile b/Containers/apache/Caddyfile index a9169a89..0fafb46f 100644 --- a/Containers/apache/Caddyfile +++ b/Containers/apache/Caddyfile @@ -89,7 +89,7 @@ http://{$APACHE_HOST}.nextcloud-aio:23973, # For Collabora callback and WOPI req # TLS options tls { issuer acme { - profile tlsserver + profile shortlived # Disable HTTP challenge because that would require port 80, which we don't get (it's exposed to the mastercontainer). # This container by default only exposes port 443 if not configured otherwise via APACHE_PORT. disable_http_challenge diff --git a/Containers/nextcloud/entrypoint.sh b/Containers/nextcloud/entrypoint.sh index c3fddad5..b95fa29f 100644 --- a/Containers/nextcloud/entrypoint.sh +++ b/Containers/nextcloud/entrypoint.sh @@ -947,6 +947,8 @@ if [ "$TALK_ENABLED" = 'yes' ]; then elif [ "$SKIP_UPDATE" != 1 ]; then php /var/www/html/occ app:update spreed fi + # We auto-renew the certs via caddy so the outdated cert warning should not be displayed + php /var/www/html/occ config:app:set spreed certificate_expiration_days --type=integer --value="2" # Add turn server # shellcheck disable=SC2153 if ! php /var/www/html/occ talk:turn:list --output="plain" | grep server | grep -q " $TURN_DOMAIN:$TALK_PORT"; then