Let's Encrypt ืžื‘ื˜ืœ 2 ืžื™ืœื™ื•ืŸ ืื™ืฉื•ืจื™ื ืขืงื‘ ื‘ืขื™ื•ืช ื‘ื™ื™ืฉื•ื TLS-ALPN-01

Let's Encrypt, ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— ืฉื ืฉืœื˜ืช ืขืœ ื™ื“ื™ ื”ืงื”ื™ืœื” ื•ืžืกืคืงืช ืชืขื•ื“ื•ืช ื‘ื—ื™ื ื ืœื›ื•ืœื, ื”ื•ื“ื™ืขื” ืขืœ ื‘ื™ื˜ื•ืœ ืžื•ืงื“ื ืฉืœ ื›ืฉื ื™ ืžื™ืœื™ื•ืŸ ืชืขื•ื“ื•ืช TLS, ืฉื”ื ื›-1% ืžื›ืœืœ ื”ืชืขื•ื“ื•ืช ื”ืคืขื™ืœื•ืช ืฉืœ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ื–ื•. ื‘ื™ื˜ื•ืœ ื”ืื™ืฉื•ืจื™ื ื”ื—ืœ ืขืงื‘ ื–ื™ื”ื•ื™ ืฉืœ ืื™ ืขืžื™ื“ื” ื‘ื“ืจื™ืฉื•ืช ื”ืžืคืจื˜ ื‘ืงื•ื“ ื”ืžืฉืžืฉ ื‘-Let's Encrypt ืขื ื™ื™ืฉื•ื ื”ื”ืจื—ื‘ื” TLS-ALPN-01 (RFC 7301, Application-Layer Protocol Negotiation). ืื™ ื”ื”ืชืืžื” ื ื‘ืขื” ืžื”ื™ืขื“ืจ ื‘ื“ื™ืงื•ืช ืžืกื•ื™ืžื•ืช ืฉื‘ื•ืฆืขื• ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ืžืฉื ื•ืžืชืŸ ืขืœ ื”ื—ื™ื‘ื•ืจ ื”ืžื‘ื•ืกืก ืขืœ ืชื•ืกืฃ ALPN TLS ื”ืžืฉืžืฉ ื‘-HTTP/2. ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื”ืื™ืจื•ืข ื™ืคื•ืจืกื ืœืื—ืจ ื”ืฉืœืžืช ื‘ื™ื˜ื•ืœ ื”ืื™ืฉื•ืจื™ื ื”ื‘ืขื™ื™ืชื™ื™ื.

ื‘-26 ื‘ื™ื ื•ืืจ ื‘ืฉืขื” 03:48 (MSK) ื”ืชืงืœื” ืชื•ืงื ื”, ืืš ื›ืœ ื”ืื™ืฉื•ืจื™ื ืฉื”ื•ื ืคืงื• ื‘ืฉื™ื˜ืช TLS-ALPN-01 ืœืื™ืžื•ืช ื”ื•ื—ืœื˜ ืœื‘ื˜ืœ. ืฉืœื™ืœืช ืชืขื•ื“ื•ืช ืชื—ืœ ื‘-28 ื‘ื™ื ื•ืืจ ื‘ืฉืขื” 19:00 (MSK). ืขื“ ืœืžื•ืขื“ ื–ื”, ืžื•ืžืœืฅ ืœืžืฉืชืžืฉื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืฉื™ื˜ืช ื”ืื™ืžื•ืช TLS-ALPN-01 ืœืขื“ื›ืŸ ืืช ื”ืื™ืฉื•ืจื™ื ืฉืœื”ื, ืื—ืจืช ื”ื ื™ื‘ื•ื˜ืœื• ืžื•ืงื“ื.

ื”ื•ื“ืขื•ืช ืจืœื•ื•ื ื˜ื™ื•ืช ืœื’ื‘ื™ ื”ืฆื•ืจืš ื‘ืขื“ื›ื•ืŸ ืชืขื•ื“ื•ืช ื ืฉืœื—ื•ืช ื‘ื“ื•ื"ืœ. ืžืฉืชืžืฉื™ื ื”ืžืฉืชืžืฉื™ื ื‘-Certbot ื•ื‘ื›ืœื™ื ืžื™ื•ื‘ืฉื™ื ื›ื“ื™ ืœืงื‘ืœ ืื™ืฉื•ืจ ืœื ื”ื•ืฉืคืขื• ืžื”ื‘ืขื™ื” ื‘ืขืช ื”ืฉื™ืžื•ืฉ ื‘ื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ. ืฉื™ื˜ืช TLS-ALPN-01 ื ืชืžื›ืช ื‘ื—ื‘ื™ืœื•ืช Caddy, Traefik, apache mod_md ื•-autocert. ืืชื” ื™ื›ื•ืœ ืœื‘ื“ื•ืง ืืช ื ื›ื•ื ื•ืช ื”ืชืขื•ื“ื•ืช ืฉืœืš ืขืœ ื™ื“ื™ ื—ื™ืคื•ืฉ ืžื–ื”ื™ื, ืžืกืคืจื™ื ืกื™ื“ื•ืจื™ื™ื ืื• ื“ื•ืžื™ื™ื ื™ื ื‘ืจืฉื™ืžืช ื”ืชืขื•ื“ื•ืช ื”ื‘ืขื™ื™ืชื™ื•ืช.

ืžื›ื™ื•ื•ืŸ ืฉื”ืฉื™ื ื•ื™ื™ื ืžืฉืคื™ืขื™ื ืขืœ ื”ื”ืชื ื”ื’ื•ืช ื‘ืขืช ื‘ื“ื™ืงื” ื‘ืืžืฆืขื•ืช ืฉื™ื˜ืช TLS-ALPN-01, ื™ื™ืชื›ืŸ ืฉื™ื™ื“ืจืฉ ืขื“ื›ื•ืŸ ืœืงื•ื— ACME ืื• ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช (Caddy, bitnami/bn-cert, autocert, apache mod_md, Traefik) ื›ื“ื™ ืœื”ืžืฉื™ืš ืœืขื‘ื•ื“. ื”ืฉื™ื ื•ื™ื™ื ื›ื•ืœืœื™ื ืฉื™ืžื•ืฉ ื‘ื’ืจืกืื•ืช TLS ืฉืื™ื ืŸ ื ืžื•ื›ื•ืช ืž-1.2 (ืœืงื•ื—ื•ืช ืœื ื™ื•ื›ืœื• ื™ื•ืชืจ ืœื”ืฉืชืžืฉ ื‘-TLS 1.1) ื•ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ืฉืœ OID 1.3.6.1.5.5.7.1.30.1, ื”ืžื–ื”ื” ืืช ื”ืจื—ื‘ื” ื”ืžื™ื•ืฉื ืช acmeIdentifier, ืฉื ืชืžื›ื” ืจืง ื‘ืงื•ื“ืžื™ื ืงื•ื“ืžื™ื. ื˜ื™ื•ื˜ื•ืช ืฉืœ ืžืคืจื˜ RFC 8737 (ื‘ืขืช ื”ืคืงืช ืื™ืฉื•ืจ, ื›ืขืช ืจืง OID 1.3.6.1.5.5.7.1.31 ืžื•ืชืจ, ื•ืœืงื•ื—ื•ืช ื”ืžืฉืชืžืฉื™ื ื‘-OID 1.3.6.1.5.5.7.1.30.1 ืœื ื™ื•ื›ืœื• ืœืงื‘ืœ ืื™ืฉื•ืจ).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”