2019-07-06

certbot官網(wǎng)(構(gòu)建https)

1.獲取certbot-auto

####? 下載

wget https://dl.eff.org/certbot-auto

####? 給予權(quán)限

chmod a+x ./certbot-auto

2.使用

#### 請(qǐng)改為自己的域名

./certbot-auto --server https://acme-v02.api.letsencrypt.org/directory -d "*.xxx.com" -d "xxx.com" --manual --preferred-challenges dns-01 certonly

####? 出現(xiàn)如下 輸入郵箱

Enter email address (used for urgent renewal and security notices) (Enter 'c' to

cancel):

####? 輸入A同意

Please read the Terms of Service at

https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must

agree in order to register with the ACME server at

https://acme-v02.api.letsencrypt.org/directory

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

(A)gree/(C)ancel:

####? 輸入Y同意

Would you be willing to share your email address with the Electronic Frontier

Foundation, a founding partner of the Let's Encrypt project and the non-profit

organization that develops Certbot? We'd like to send you email about our work

encrypting the web, EFF news, campaigns, and ways to support digital freedom.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

(Y)es/(N)o:

####? 輸入Y確認(rèn)

NOTE: The IP of this machine will be publicly logged as having requested this

certificate. If you're running certbot in manual mode on a machine that is not

your server, please ensure you're okay with that.

Are you OK with your IP being logged?

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

(Y)es/(N)o:

####? 域名添加TXT解析? 添加對(duì)應(yīng)的域名和值 添加好后回車(chē)?yán)^續(xù)

Please deploy a DNS TXT record under the name

xxxx.xxxx.com with the following value:

xxxxxxxx

Before continuing, verify the record is deployed.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Press Enter to Continue

####? 出現(xiàn)如下即成功

IMPORTANT NOTES:

- Congratulations! Your certificate and chain have been saved at:

? /etc/letsencrypt/live/xxxxx.com/fullchain.pem

? Your key file has been saved at:

? /etc/letsencrypt/live/xxxxx.com/privkey.pem

? Your cert will expire on 2018-12-28. To obtain a new or tweaked

? version of this certificate in the future, simply run certbot-auto

? again. To non-interactively renew *all* of your certificates, run

? "certbot-auto renew"

- Your account credentials have been saved in your Certbot

? configuration directory at /etc/letsencrypt. You should make a

? secure backup of this folder now. This configuration directory will

? also contain certificates and private keys obtained by Certbot so

? making regular backups of this folder is ideal.

- If you like Certbot, please consider supporting our work by:

? Donating to ISRG / Let's Encrypt:? https://letsencrypt.org/donate

? Donating to EFF:? ? ? ? ? ? ? ? ? ? https://eff.org/donate-le

3.nginx配置

server{

? listen? 80;

? listen [::]:80;

? server_name? xxx.xxx.com;

? return? ? ? ? 301 https://$server_name$request_uri;

}

server {

? ? ? ? listen 443 ssl;

? ? ? ? server_name xxx.xxx.com;

? ? ? ? ssl on;

? ? ? ? ssl_certificate /etc/letsencrypt/live/xxx.xxx.com/fullchain.pem;

? ? ? ? ssl_certificate_key /etc/letsencrypt/live/xxx.xxx.com/privkey.pem;

? ? ? ? ssl_session_cache shared:SSL:20m;

? ? ? ? ssl_session_timeout? 10m;

? ? ? ? ssl_protocols TLSv1 TLSv1.1 TLSv1.2;

? ? ? ? ssl_ciphers ECDHE-RSA-AES128-GCM-SHA256:HIGH:!aNULL:!MD5:!RC4:!DHE:!kEDH;

? ? ? ? ssl_prefer_server_ciphers on;

? ? ? ? ssl_stapling on;

? ? ? ? ssl_stapling_verify on;

? ? ? ? ssl_trusted_certificate /etc/letsencrypt/live/xxx.xxx.com/chain.pem;

? ? ? ? #啟用 HSTS 用于通知瀏覽器強(qiáng)制使用 https 通信

? ? ? ? add_header Strict-Transport-Security "max-age=31536000";

? ? ? ? resolver 8.8.8.8 8.8.4.4;



? ? ? ? ........

? }

---------------------

作者:濫情丶

來(lái)源:CSDN

原文:https://blog.csdn.net/q85795362/article/details/82903507

版權(quán)聲明:本文為博主原創(chuàng)文章,轉(zhuǎn)載請(qǐng)附上博文鏈接!

最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末暇屋,一起剝皮案震驚了整個(gè)濱河市畅厢,隨后出現(xiàn)的幾起案子,更是在濱河造成了極大的恐慌拙毫,老刑警劉巖颗祝,帶你破解...
    沈念sama閱讀 206,723評(píng)論 6 481
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件,死亡現(xiàn)場(chǎng)離奇詭異删铃,居然都是意外死亡,警方通過(guò)查閱死者的電腦和手機(jī)踏堡,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 88,485評(píng)論 2 382
  • 文/潘曉璐 我一進(jìn)店門(mén)猎唁,熙熙樓的掌柜王于貴愁眉苦臉地迎上來(lái),“玉大人顷蟆,你說(shuō)我怎么就攤上這事诫隅。” “怎么了帐偎?”我有些...
    開(kāi)封第一講書(shū)人閱讀 152,998評(píng)論 0 344
  • 文/不壞的土叔 我叫張陵逐纬,是天一觀的道長(zhǎng)。 經(jīng)常有香客問(wèn)我削樊,道長(zhǎng)豁生,這世上最難降的妖魔是什么? 我笑而不...
    開(kāi)封第一講書(shū)人閱讀 55,323評(píng)論 1 279
  • 正文 為了忘掉前任漫贞,我火速辦了婚禮甸箱,結(jié)果婚禮上,老公的妹妹穿的比我還像新娘迅脐。我一直安慰自己摇肌,他們只是感情好,可當(dāng)我...
    茶點(diǎn)故事閱讀 64,355評(píng)論 5 374
  • 文/花漫 我一把揭開(kāi)白布仪际。 她就那樣靜靜地躺著围小,像睡著了一般。 火紅的嫁衣襯著肌膚如雪树碱。 梳的紋絲不亂的頭發(fā)上肯适,一...
    開(kāi)封第一講書(shū)人閱讀 49,079評(píng)論 1 285
  • 那天,我揣著相機(jī)與錄音成榜,去河邊找鬼框舔。 笑死,一個(gè)胖子當(dāng)著我的面吹牛,可吹牛的內(nèi)容都是我干的刘绣。 我是一名探鬼主播樱溉,決...
    沈念sama閱讀 38,389評(píng)論 3 400
  • 文/蒼蘭香墨 我猛地睜開(kāi)眼,長(zhǎng)吁一口氣:“原來(lái)是場(chǎng)噩夢(mèng)啊……” “哼纬凤!你這毒婦竟也來(lái)了福贞?” 一聲冷哼從身側(cè)響起,我...
    開(kāi)封第一講書(shū)人閱讀 37,019評(píng)論 0 259
  • 序言:老撾萬(wàn)榮一對(duì)情侶失蹤停士,失蹤者是張志新(化名)和其女友劉穎挖帘,沒(méi)想到半個(gè)月后,有當(dāng)?shù)厝嗽跇?shù)林里發(fā)現(xiàn)了一具尸體恋技,經(jīng)...
    沈念sama閱讀 43,519評(píng)論 1 300
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡拇舀,尸身上長(zhǎng)有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 35,971評(píng)論 2 325
  • 正文 我和宋清朗相戀三年,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了蜻底。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片骄崩。...
    茶點(diǎn)故事閱讀 38,100評(píng)論 1 333
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡,死狀恐怖薄辅,靈堂內(nèi)的尸體忽然破棺而出刁赖,到底是詐尸還是另有隱情,我是刑警寧澤长搀,帶...
    沈念sama閱讀 33,738評(píng)論 4 324
  • 正文 年R本政府宣布,位于F島的核電站鸡典,受9級(jí)特大地震影響源请,放射性物質(zhì)發(fā)生泄漏。R本人自食惡果不足惜彻况,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 39,293評(píng)論 3 307
  • 文/蒙蒙 一谁尸、第九天 我趴在偏房一處隱蔽的房頂上張望。 院中可真熱鬧纽甘,春花似錦良蛮、人聲如沸。這莊子的主人今日做“春日...
    開(kāi)封第一講書(shū)人閱讀 30,289評(píng)論 0 19
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽(yáng)。三九已至左权,卻和暖如春皮胡,著一層夾襖步出監(jiān)牢的瞬間,已是汗流浹背赏迟。 一陣腳步聲響...
    開(kāi)封第一講書(shū)人閱讀 31,517評(píng)論 1 262
  • 我被黑心中介騙來(lái)泰國(guó)打工屡贺, 沒(méi)想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留,地道東北人。 一個(gè)月前我還...
    沈念sama閱讀 45,547評(píng)論 2 354
  • 正文 我出身青樓甩栈,卻偏偏與公主長(zhǎng)得像泻仙,于是被迫代替她去往敵國(guó)和親。 傳聞我的和親對(duì)象是個(gè)殘疾皇子量没,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 42,834評(píng)論 2 345