CentOS 7 安裝Let’s Encrypt憑證與啓用Https

Let's Encrypt簡(jiǎn)介

Let's Encrypt作為一個(gè)公共且免費(fèi)SSL的項(xiàng)目逐漸被廣大用戶(hù)傳播和使用,是由Mozilla仍秤、Cisco蛋褥、Akamai、IdenTrust浴捆、EFF等組織人員發(fā)起蒜田,主要的目的也是為了推進(jìn)網(wǎng)站從HTTP向HTTPS過(guò)度的進(jìn)程,目前已經(jīng)有越來(lái)越多的商家加入和贊助支持选泻。

參考資料:
Let’s Encrypt官網(wǎng)
EFF's Certbot

1.安裝certbot

yum -y install yum-utils
yum-config-manager --enable rhui-REGION-rhel-server-extras rhui-REGION-rhel-server-optional
sudo yum install python2-certbot-apache

2.生成的證書(shū)與配置Apache

sudo certbot --apache

執(zhí)行過(guò)程:

    Saving debug log to /var/log/letsencrypt/letsencrypt.log                                   
    Plugins selected: Authenticator apache, Installer apache                                   
    Enter email address (used for urgent renewal and security notices) (Enter 'c' to           
    cancel): **輸入郵箱地址**                                                              
    Starting new HTTPS connection (1): acme-v01.api.letsencrypt.org                            
                                                                                            
    -------------------------------------------------------------------------------            
    Please read the Terms of Service at                                                        
    https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must                
    agree in order to register with the ACME server at                                         
    https://acme-v01.api.letsencrypt.org/directory                                             
    -------------------------------------------------------------------------------            
    (A)gree/(C)ancel: **輸入A同意服務(wù)條款**
                                                                                            
    -------------------------------------------------------------------------------            
    Would you be willing to share your email address with the Electronic Frontier              
    Foundation, a founding partner of the Let's Encrypt project and the non-profit             
    organization that develops Certbot? We'd like to send you email about EFF and              
    our work to encrypt the web, protect its users and defend digital rights.                  
    -------------------------------------------------------------------------------            
    (Y)es/(N)o: **是否接收相關(guān)郵件**                                                                              
    Starting new HTTPS connection (1): supporters.eff.org                                      
                                                                                            
    Which names would you like to activate HTTPS for?                                          
    -------------------------------------------------------------------------------            
    **這裡將列出網(wǎng)站相關(guān)網(wǎng)址**
    -------------------------------------------------------------------------------            
    Select the appropriate numbers separated by commas and/or spaces, or leave input           
    blank to select all options shown (Enter 'c' to cancel): ** 選擇網(wǎng)站 **
    Obtaining a new certificate                                                                
    Performing the following challenges:                                                       
    http-01 challenge for **網(wǎng)站網(wǎng)址**                                                       
    Waiting for verification...                                                                
    Cleaning up challenges                                                                     
    Created an SSL vhost at /etc/httpd/conf.d/httpd-vhosts-le-ssl.conf                         
    Deploying Certificate to VirtualHost /etc/httpd/conf.d/httpd-vhosts-le-ssl.conf            
    Created an SSL vhost at /etc/httpd/conf.d/httpd-vhosts-le-ssl.conf                         
    Deploying Certificate to VirtualHost /etc/httpd/conf.d/httpd-vhosts-le-ssl.conf            
    Deploying Certificate to VirtualHost /etc/httpd/conf.d/httpd-vhosts-le-ssl.conf            
                                                                                            
    Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.      
    -------------------------------------------------------------------------------            
    1: No redirect - Make no further changes to the webserver configuration.                   
    2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for           
    new sites, or if you're confident your site works on HTTPS. You can undo this              
    change by editing your web server's configuration.                                         
    -------------------------------------------------------------------------------            
    Select the appropriate number [1-2] then [enter] (press 'c' to cancel): **是否全部導(dǎo)向https**
    
    -------------------------------------------------------------------------------            
    Congratulations! You have successfully enabled **網(wǎng)站網(wǎng)址**                                                         
    You should test your configuration at:                                                     
    https://www.ssllabs.com/ssltest/analyze.html?d=**網(wǎng)站網(wǎng)址**
    -------------------------------------------------------------------------------            
                                                                                            
    IMPORTANT NOTES:                                                                           
    - Congratulations! Your certificate and chain have been saved at:                         
    /etc/letsencrypt/live/**網(wǎng)站網(wǎng)址**/fullchain.pem                                      
    Your key file has been saved at:                                                        
    /etc/letsencrypt/live/**網(wǎng)站網(wǎng)址**/privkey.pem                                        
    Your cert will expire on 2018-09-23. To obtain a new or tweaked                         
    version of this certificate in the future, simply run certbot again                     
    with the "certonly" option. To non-interactively renew *all* of                         
    your certificates, run "certbot renew"                                                  
    - Your account credentials have been saved in your Certbot                                
    configuration directory at /etc/letsencrypt. You should make a                          
    secure backup of this folder now. This configuration directory will                     
    also contain certificates and private keys obtained by Certbot so                       
    making regular backups of this folder is ideal.                                         
    - If you like Certbot, please consider supporting our work by:                            

3.防火牆打開(kāi)https

firewall-cmd --add-service=https --permanent  
systemctl restart firewalld #重啟防火牆設(shè)定

4.測(cè)試

除了自己用瀏覽器打開(kāi)https://網(wǎng)址以外冲粤,還可以用外部服務(wù)檢查,例如:
SSL Labs測(cè)試

5.排程自動(dòng)更新

Let’s Encrypt有90天的有效期页眯,必須定時(shí)更新梯捕,certbot也有這功能,只要在系統(tǒng)排程裡加入下面設(shè)定:

0 0,12 * * * python -c 'import random; import time; time.sleep(random.random() * 3600)' && certbot renew
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末窝撵,一起剝皮案震驚了整個(gè)濱河市傀顾,隨后出現(xiàn)的幾起案子,更是在濱河造成了極大的恐慌碌奉,老刑警劉巖短曾,帶你破解...
    沈念sama閱讀 219,188評(píng)論 6 508
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件,死亡現(xiàn)場(chǎng)離奇詭異赐劣,居然都是意外死亡嫉拐,警方通過(guò)查閱死者的電腦和手機(jī),發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 93,464評(píng)論 3 395
  • 文/潘曉璐 我一進(jìn)店門(mén)魁兼,熙熙樓的掌柜王于貴愁眉苦臉地迎上來(lái)婉徘,“玉大人,你說(shuō)我怎么就攤上這事咐汞∨懈纾” “怎么了?”我有些...
    開(kāi)封第一講書(shū)人閱讀 165,562評(píng)論 0 356
  • 文/不壞的土叔 我叫張陵碉考,是天一觀(guān)的道長(zhǎng)塌计。 經(jīng)常有香客問(wèn)我,道長(zhǎng)侯谁,這世上最難降的妖魔是什么锌仅? 我笑而不...
    開(kāi)封第一講書(shū)人閱讀 58,893評(píng)論 1 295
  • 正文 為了忘掉前任蓝撇,我火速辦了婚禮碑幅,結(jié)果婚禮上,老公的妹妹穿的比我還像新娘桐臊。我一直安慰自己惨撇,他們只是感情好伊脓,可當(dāng)我...
    茶點(diǎn)故事閱讀 67,917評(píng)論 6 392
  • 文/花漫 我一把揭開(kāi)白布。 她就那樣靜靜地躺著魁衙,像睡著了一般报腔。 火紅的嫁衣襯著肌膚如雪株搔。 梳的紋絲不亂的頭發(fā)上,一...
    開(kāi)封第一講書(shū)人閱讀 51,708評(píng)論 1 305
  • 那天纯蛾,我揣著相機(jī)與錄音纤房,去河邊找鬼。 笑死翻诉,一個(gè)胖子當(dāng)著我的面吹牛炮姨,可吹牛的內(nèi)容都是我干的。 我是一名探鬼主播碰煌,決...
    沈念sama閱讀 40,430評(píng)論 3 420
  • 文/蒼蘭香墨 我猛地睜開(kāi)眼舒岸,長(zhǎng)吁一口氣:“原來(lái)是場(chǎng)噩夢(mèng)啊……” “哼!你這毒婦竟也來(lái)了芦圾?” 一聲冷哼從身側(cè)響起蛾派,我...
    開(kāi)封第一講書(shū)人閱讀 39,342評(píng)論 0 276
  • 序言:老撾萬(wàn)榮一對(duì)情侶失蹤,失蹤者是張志新(化名)和其女友劉穎堕扶,沒(méi)想到半個(gè)月后碍脏,有當(dāng)?shù)厝嗽跇?shù)林里發(fā)現(xiàn)了一具尸體,經(jīng)...
    沈念sama閱讀 45,801評(píng)論 1 317
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡稍算,尸身上長(zhǎng)有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 37,976評(píng)論 3 337
  • 正文 我和宋清朗相戀三年典尾,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片糊探。...
    茶點(diǎn)故事閱讀 40,115評(píng)論 1 351
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡钾埂,死狀恐怖,靈堂內(nèi)的尸體忽然破棺而出科平,到底是詐尸還是另有隱情褥紫,我是刑警寧澤,帶...
    沈念sama閱讀 35,804評(píng)論 5 346
  • 正文 年R本政府宣布瞪慧,位于F島的核電站髓考,受9級(jí)特大地震影響,放射性物質(zhì)發(fā)生泄漏弃酌。R本人自食惡果不足惜氨菇,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 41,458評(píng)論 3 331
  • 文/蒙蒙 一、第九天 我趴在偏房一處隱蔽的房頂上張望妓湘。 院中可真熱鬧查蓉,春花似錦、人聲如沸榜贴。這莊子的主人今日做“春日...
    開(kāi)封第一講書(shū)人閱讀 32,008評(píng)論 0 22
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽(yáng)。三九已至鹃共,卻和暖如春鬼佣,著一層夾襖步出監(jiān)牢的瞬間,已是汗流浹背及汉。 一陣腳步聲響...
    開(kāi)封第一講書(shū)人閱讀 33,135評(píng)論 1 272
  • 我被黑心中介騙來(lái)泰國(guó)打工沮趣, 沒(méi)想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留屯烦,地道東北人坷随。 一個(gè)月前我還...
    沈念sama閱讀 48,365評(píng)論 3 373
  • 正文 我出身青樓,卻偏偏與公主長(zhǎng)得像驻龟,于是被迫代替她去往敵國(guó)和親温眉。 傳聞我的和親對(duì)象是個(gè)殘疾皇子,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 45,055評(píng)論 2 355

推薦閱讀更多精彩內(nèi)容