Let's Encrypt ืžื‘ื˜ืœ 2 ืžื™ืœื™ื•ืŸ ืื™ืฉื•ืจื™ื ืขืงื‘ ื‘ืขื™ื•ืช ื‘ื™ื™ืฉื•ื TLS-ALPN-01

Let's Encrypt, ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืœืœื ืžื˜ืจื•ืช ืจื•ื•ื— ื”ื ืฉืœื˜ืช ืขืœ ื™ื“ื™ ื”ืงื”ื™ืœื”, ื”ืžืกืคืงืช ืื™ืฉื•ืจื™ื ื‘ื—ื™ื ื ืœื›ืœ ืžื™ ืฉืžืขื•ื ื™ื™ืŸ ื‘ื”ื, ื”ื•ื“ื™ืขื” ืขืœ ื‘ื™ื˜ื•ืœ ืžื•ืงื“ื ืฉืœ ื›ืฉื ื™ ืžื™ืœื™ื•ืŸ ืื™ืฉื•ืจื™ื TLS, ื”ืžื”ื•ื•ื™ื ื›-1% ืžื›ืœืœ ื”ืื™ืฉื•ืจื™ื ื”ืคืขื™ืœื™ื ืฉืœ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ื–ื•. ื‘ื™ื˜ื•ืœ ื”ืื™ืฉื•ืจื™ื ื”ื—ืœ ืขืงื‘ ื’ื™ืœื•ื™ ืื™-ืฆื™ื•ืช ืœื“ืจื™ืฉื•ืช ื”ืžืคืจื˜ ื‘ืงื•ื“ ื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘-Let's Encrypt ืขื ื™ื™ืฉื•ื ื”ื”ืจื—ื‘ื” TLS-ALPN-01 (RFC 7301, Application-Layer Protocol Negotiation). ืื™-ื”ืฆื™ื•ืช ื ื‘ืข ืžื”ื™ืขื“ืจ ื‘ื“ื™ืงื•ืช ืžืกื•ื™ืžื•ืช ืฉื‘ื•ืฆืขื• ื‘ืžื”ืœืš ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจื™ื ื”ืžื‘ื•ืกืกื™ื ืขืœ ื”ื”ืจื—ื‘ื” ALPN TLS ื”ืžืฉืžืฉืช ื‘-HTTP/2. ืžื™ื“ืข ืžืคื•ืจื˜ ืขืœ ื”ืชืงืจื™ืช ื™ืคื•ืจืกื ืœืื—ืจ ื”ืฉืœืžืช ื‘ื™ื˜ื•ืœ ื”ืื™ืฉื•ืจื™ื ื”ื‘ืขื™ื™ืชื™ื™ื.

ื‘-26 ื‘ื™ื ื•ืืจ ื‘ืฉืขื” 03:48 (MSK) ื”ื‘ืขื™ื” ืชื•ืงื ื”, ืืš ื›ืœ ื”ืื™ืฉื•ืจื™ื ืฉื”ื•ื ืคืงื• ื‘ืืžืฆืขื•ืช ืฉื™ื˜ืช ื”ืื™ืžื•ืช TLS-ALPN-01 ื”ื•ื—ืœื˜ ื›ื™ ื”ื ืื™ื ื ืชืงืคื™ื. ื‘ื™ื˜ื•ืœ ื”ืื™ืฉื•ืจื™ื ื™ื—ืœ ื‘-28 ื‘ื™ื ื•ืืจ ื‘ืฉืขื” 19:00 (MSK). ืœืคื ื™ ื›ืŸ, ืžื•ืžืœืฅ ืœืžืฉืชืžืฉื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืฉื™ื˜ืช ื”ืื™ืžื•ืช TLS-ALPN-01 ืœืขื“ื›ืŸ ืืช ื”ืื™ืฉื•ืจื™ื ืฉืœื”ื, ืื—ืจืช ื”ื ื™ื‘ื•ื˜ืœื• ืžื•ืงื“ื ืžื”ืฆืคื•ื™.

ื”ื•ื“ืขื•ืช ืขืœ ื”ืฆื•ืจืš ืœื—ื“ืฉ ืื™ืฉื•ืจื™ื ื ืฉืœื—ื• ื‘ื“ื•ื"ืœ. ืžืฉืชืžืฉื™ื ื”ืžืฉืชืžืฉื™ื ื‘-Certbot ื•ื‘ื›ืœื™ dehydrated ื›ื“ื™ ืœื”ืฉื™ื’ ืื™ืฉื•ืจื™ื ืขื ื”ื’ื“ืจื•ืช ื‘ืจื™ืจืช ืžื—ื“ืœ ืื™ื ื ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”. ืฉื™ื˜ืช TLS-ALPN-01 ื ืชืžื›ืช ื‘ื—ื‘ื™ืœื•ืช Caddy, Traefik, Apache mod_md ื•-autocert. ื ื™ืชืŸ ืœืืžืช ืืช ืชื•ืงืฃ ื”ืื™ืฉื•ืจื™ื ืฉืœืš ืขืœ ื™ื“ื™ ื—ื™ืคื•ืฉ ืžื–ื”ื™ื, ืžืกืคืจื™ื ืกื™ื“ื•ืจื™ื™ื ืื•... ื“ื•ืžื™ื™ื ื™ื ื‘ืจืฉื™ืžืช ื”ืชืขื•ื“ื•ืช ื”ื‘ืขื™ื™ืชื™ื•ืช.

ืžืื—ืจ ืฉื”ืฉื™ื ื•ื™ื™ื ืžืฉืคื™ืขื™ื ืขืœ ื”ื”ืชื ื”ื’ื•ืช ื‘ืขืช ืื™ืžื•ืช ื‘ืืžืฆืขื•ืช ืฉื™ื˜ืช TLS-ALPN-01, ื™ื™ืชื›ืŸ ืฉื™ื™ื“ืจืฉ ืขื“ื›ื•ืŸ ืœืงื•ื— ACME ืื• ืฉื™ื ื•ื™ื™ ืชืฆื•ืจื” (Caddy, bitnami/bn-cert, autocert, apache mod_md, Traefik) ื›ื“ื™ ืœื”ืžืฉื™ืš ืœืคืขื•ืœ. ื”ืฉื™ื ื•ื™ื™ื ืžืกืชื›ืžื™ื ื‘ืฉื™ืžื•ืฉ ื‘ื’ืจืกืื•ืช TLS ืฉืื™ื ืŸ ื ืžื•ื›ื•ืช ืžื’ืจืกื” 1.2 (ืœืงื•ื—ื•ืช ืœื ื™ื•ื›ืœื• ืขื•ื“ ืœื”ืฉืชืžืฉ ื‘-TLS 1.1) ื•ื”ืคืกืงืช ื”ืชืžื™ื›ื” ื‘-OID 1.3.6.1.5.5.7.1.30.1, ื”ืžื–ื”ื” ืืช ืกื™ื•ืžืช acmeIdentifier ื”ืžื™ื•ืฉื ืช ื”ื ืชืžื›ืช ืจืง ื‘ื˜ื™ื•ื˜ื•ืช ืžื•ืงื“ืžื•ืช ืฉืœ ืžืคืจื˜ RFC 8737 (ื‘ืขืช ื™ืฆื™ืจืช ืื™ืฉื•ืจ, ืจืง OID 1.3.6.1.5.5.7.1.31 ืžื•ืชืจ ื›ืขืช, ื•ืœืงื•ื—ื•ืช ื”ืžืฉืชืžืฉื™ื ื‘-OID 1.3.6.1.5.5.7.1.30.1 ืœื ื™ื•ื›ืœื• ืœืงื‘ืœ ืื™ืฉื•ืจ).

ืžืงื•ืจ: OpenNet.ru

ืงื ื” ืื™ืจื•ื— ืืžื™ืŸ ืœืืชืจื™ื ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS ๐Ÿ”ฅ ืงื ื” ืื—ืกื•ืŸ ืืชืจื™ื ืืžื™ืŸ ืขื ื”ื’ื ืช DDoS, ืฉืจืชื™ VPS VDS | ProHoster