# Use Let's encrypt certificate for ejabberd

**URL:** https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577
**Category:** Uncategorized
**Created:** [May 25, 2021, 6:51pm UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577 "2021-05-25T18:51:41Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![eboelens](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/e/bb73d2/32.png) [@eboelens](https://discuss.freedombox.org/u/eboelens)
#### Post date: [May 25, 2021, 6:51pm UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/1 "2021-05-25T18:51:41Z")

</div>

Hello I’m trying setup ejabberd server , use a client  
Can someone help me with stupid questions ?  
I have allready a domainname for my freedombox (raspi4 via Debian), and a cerificate

Ports are open in the router for ejabberd  
First:  
is the domainname of the freedombox automatically linked to ejabberd and let’s Encrypted?  
(the manual says something about this but I don’t find that anywhere)

I don’t understand how to use a client.

**JSXC for example:**  
asked for domain , login and pasword  
when I put my domainname there is an error BOSH server NOT reachable or misconfigured.  
(I don’t read anything from a BOSCH server anywhere)

**Conversation mobile for example** : is asking for xmpp addres and a password  
I don’t now what which address they mean. It is in the email-form I read . username@hostname  
But that doesnt work.  
When put username@domainname.freedombox.rocks it won’t work  
username is my username in my freedombox

Can someone put me in the right direction please ?

---

<div class="post-metadata">

### Author: ![hanstux](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/h/45deac/32.png) [@hanstux](https://discuss.freedombox.org/u/hanstux)
#### Post date: [May 31, 2021, 5:48pm UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/2 "2021-05-31T17:48:39Z")

</div>

Since the last update conversations doesn’t accept self signed certificates, if I understand that right. I struggle myself to get a let’s encrypt certificate for ejabberd. I created a new topic.  
Please tell, if you found a viable solution.

---

<div class="post-metadata">

### Author: ![Avron](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/a/a9adbd/32.png) [@Avron](https://discuss.freedombox.org/u/Avron)
#### Post date: [June 2, 2021, 9:45am UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/3 "2021-06-02T09:45:43Z")

</div>

I have a Let’s encrypt certificate that I obtained by the “Let’s encrypt” option in the system menu. I know it is used by the web interface but I am not sure how to see whether it is used by ejabberd or not.

I am using the latest version of conversations from F-Droid (2.9.13+fcr) and Gajim 1.3.2 and both work, but I don’t know how to check the TLS certificate of the server.

---

<div class="post-metadata">

### Author: ![hanstux](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/h/45deac/32.png) [@hanstux](https://discuss.freedombox.org/u/hanstux)
#### Post date: [June 3, 2021, 10:03pm UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/4 "2021-06-03T22:03:41Z")

</div>

Hi Avron,  
there is a test at [xmpp.net](http://xmpp.net). It returns an  
Error. self signed certificate.

---

<div class="post-metadata">

### Author: ![Avron](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/a/a9adbd/32.png) [@Avron](https://discuss.freedombox.org/u/Avron)
#### Post date: [June 4, 2021, 7:33am UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/5 "2021-06-04T07:33:27Z")

</div>

Thanks.

I don’t have that error. The hashes are the same like the ones visible in my web browser for the web interface. I tried to look at configuration files, ejabberd.yml refers to a .pem file in a letsencrypt subdir of ejabberd, I guess apache uses another file but I am unable to find that now.

I only used the plinth interface to configure things, except perhaps an apt update/upgrade once at the very beginning (I have the Pioneer edition and have used the default sdcard image).

I can check files on my Feedombox to compare with your setup if you know what to look for.

---

<div class="post-metadata">

### Author: ![hanstux](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/h/45deac/32.png) [@hanstux](https://discuss.freedombox.org/u/hanstux)
#### Post date: [June 8, 2021, 8:23am UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/6 "2021-06-08T08:23:39Z")

</div>

oh, turned out, ejabberd refers to a .pem file, which does not exist!  
it says

> /etc/letsencrypt/live/localhost/fullchain.pem

but under /etc/letsencrypt/live/ there is no localhost in my case. Only /etc/letsencrypt/live/“mydnsname”/fullchain.pem…

Can I just adjust that in the yaml file?

---

<div class="post-metadata">

### Author: ![hanstux](https://discuss.freedombox.org/letter_avatar_proxy/v4/letter/h/45deac/32.png) [@hanstux](https://discuss.freedombox.org/u/hanstux)
#### Post date: [August 22, 2021, 11:49pm UTC](https://discuss.freedombox.org/t/use-lets-encrypt-certificate-for-ejabberd/1577/7 "2021-08-22T23:49:51Z")

</div>

# Yeah!

Since the last update to 21.4.4 it miraculously works again!
