一勺像、申請(qǐng)條件:
1.Linux服務(wù)器或VM一臺(tái)
2.安裝了Nginx Web Server
3.域名CAA DNS解析
二、域名CAA DNS解析
國(guó)內(nèi)推薦https://www.cloudxns.net/
三豹储、下載Certbot-auto
wget https://dl.eff.org/certbot-auto
chmod a+x certbot-auto
四少辣、申請(qǐng)ssl證書
./certbot-auto certonly --email xxx@sina.com --agree-tos --no-eff-email --webroot -w /data/wwwroot/gitlab -d xxx.xxx.cn
五颠黎、Nginx配置ssl證書
listen 443;
ssl on;
ssl_certificate /etc/letsencrypt/live/gitlab.vizn.cn/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/gitlab.vizn.cn/privkey.pem;
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_prefer_server_ciphers on;
ssl_ciphers 'EECDH+AESGCM:EDH+AESGCM:AES256+EECDH:AES256+EDH';
六、ssl有效期3個(gè)月嘹狞,續(xù)約命令
./certbot-auto renew