LetsEncrypt ืคึผืœืึทื ื– ืฆื• ืึธืคึผืจื•ืคืŸ ื–ื™ื™ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืจืขื›ื˜ ืฆื• ืึท ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื–ืฉื•ืง

LetsEncrypt ืคึผืœืึทื ื– ืฆื• ืึธืคึผืจื•ืคืŸ ื–ื™ื™ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืจืขื›ื˜ ืฆื• ืึท ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื–ืฉื•ืง
LetsEncrypt, ื•ื•ืึธืก ืึธืคืคืขืจืก ืคืจื™ื™ ืกืกืœ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืคึฟืึทืจ ืขื ืงืจื™ืคึผืฉืึทืŸ, ืื™ื– ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืฆื• ืึธืคึผืจื•ืคืŸ ืขื˜ืœืขื›ืข ืกืขืจื˜ื™ืคื™ืงืึทืฅ.

ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืฉื™ื™ืš ืฆื• ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื˜ืขื•ืช ืื™ืŸ ื“ื™ ื‘ืึธื•ืœื“ืขืจ ืงืึธื ื˜ืจืึธืœ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื’ืขื ื™ืฆื˜ ืฆื• ื‘ื•ื™ืขืŸ ื“ื™ CA. ื˜ื™ืคึผื™ืงืึทืœืœื™, ื“ื™ DNS ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ CAA ืจืขืงืึธืจื“ ืึทืงืขืจื– ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืกืœื™ ืžื™ื˜ ื“ื™ ื‘ืึทืฉื˜ืขื˜ื™ืงื•ื ื’ ืคื•ืŸ ืคืขืœื“ ืึธื•ื ืขืจืฉื™ืคึผ, ืื•ืŸ ืจื•ื‘ึฟ ืื‘ืื ืขื ื˜ืŸ ื‘ืึทืงื•ืžืขืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื’ืœื™ื™ืš ื ืึธืš ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ, ืึธื‘ืขืจ ื“ื™ ื•ื•ื™ื™ื›ื•ื•ืืจื’ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ื”ืึธื‘ืŸ ื’ืขืžืื›ื˜ ืขืก ืึทื–ื•ื™ ืึทื– ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ื™ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืื™ื– ื’ืขื”ืืœื˜ืŸ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืื™ืŸ ื“ื™ ื•ื•ื™ื™ึทื˜ืขืจ 30 ื˜ืขื’ . ืื™ืŸ ืขื˜ืœืขื›ืข ืคืืœืŸ, ืขืก ืื™ื– ืžืขื’ืœืขืš ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืจืขืงืึธืจื“ืก ืึท ืฆื•ื•ื™ื™ื˜ ืžืึธืœ ื ืึธืจ ืื™ื™ื“ืขืจ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืื™ื– ืืจื•ื™ืก, ืกืคึผืขืฆื™ืขืœ ื“ื™ CAA ื“ืึทืจืฃ ื–ื™ื™ืŸ ืฉื™ื™ึทืขืš-ื•ื•ืขืจืึทืคื™ื™ื“ ื™ืŸ 8 ืฉืขื” ืื™ื™ื“ืขืจ ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ, ืึทื–ื•ื™ ืงื™ื™ืŸ ืคืขืœื“ ื•ื•ืขืจืึทืคื™ื™ื“ ืื™ื™ื“ืขืจ ื“ืขื ืคึผืขืจื™ืึธื“ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืฉื™ื™ึทืขืš-ื•ื•ืขืจืึทืคื™ื™ื“.

ื•ื•ืืก ืื™ื– ื“ืขืจ ื˜ืขื•ืช? ืื•ื™ื‘ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื‘ืขื˜ืŸ ื›ึผื•ืœืœ N ื“ืึธื•ืžื™ื™ื ื– ื•ื•ืึธืก ื“ืึทืจืคืŸ ืจื™ืคึผื™ื˜ื™ื“ CAA ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ, ื‘ืึธื•ืœื“ืขืจ ืกืึทืœืขืงืฅ ืื™ื™ื ืขืจ ืคื•ืŸ ื–ื™ื™ ืื•ืŸ ื•ื•ืขืจืึทืคื™ื™ื– ืขืก N ืžืืœ. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜, ืขืก ืื™ื– ื’ืขื•ื•ืขืŸ ืžืขื’ืœืขืš ืฆื• ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ืืคื™ืœื• ืื•ื™ื‘ ืื™ืจ ืฉืคึผืขื˜ืขืจ (ืึทืจื•ื™ืฃ ืฆื• X + 30 ื˜ืขื’) ืฉื˜ืขืœืŸ ืึท CAA ืจืขืงืึธืจื“ ื•ื•ืึธืก ืคึผืจืึธื•ื›ื™ื‘ืึทืฅ ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืคื•ืŸ ืึท LetsEncrypt ื‘ืึทื•ื•ื™ื™ึทื–ืŸ.

ืฆื• ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ื“ื™ ืคื™ืจืžืข ื”ืื˜ ืฆื•ื’ืขื’ืจื™ื™ื˜ ืึธื ืœื™ื™ืŸ ื’ืขืฆื™ื™ึทื’ื•ื•ืึธืก ื•ื•ืขื˜ ื•ื•ื™ื™ึทื–ืŸ ืึท ื“ื™ื˜ื™ื™ืœื“ ื‘ืึทืจื™ื›ื˜.

ืึทื•ื•ืึทื ืกื™ืจื˜ืข ื ื™ืฆืขืจืก ืงืขื ืขืŸ ื˜ืึธืŸ ืึทืœืฅ ื–ื™ืš ืžื™ื˜ ื“ื™ ืคืืœื’ืขื ื“ืข ืงืึทืžืึทื ื“ื–:

# ะฟั€ะพะฒะตั€ะบะฐ https
openssl s_client -connect example.com:443 -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฒะฐั€ะธะฐะฝั‚ ะฟั€ะพะฒะตั€ะบะธ ะพั‚ @simpleadmin 
echo | openssl s_client -connect example.com:443 |& openssl x509 -noout -serial
# ะฟั€ะพะฒะตั€ะบะฐ ะฟะพั‡ั‚ะพะฒะพะณะพ ัะตั€ะฒะตั€ะฐ, ะฟั€ะพั‚ะพะบะพะป SMTP
openssl s_client -connect example.com:25 -starttls smtp -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฟั€ะพะฒะตั€ะบะฐ ะฟะพั‡ั‚ะพะฒะพะณะพ ัะตั€ะฒะตั€ะฐ, ะฟั€ะพั‚ะพะบะพะป SMTP
openssl s_client -connect example.com:587 -starttls smtp -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฟั€ะพะฒะตั€ะบะฐ ะฟะพั‡ั‚ะพะฒะพะณะพ ัะตั€ะฒะตั€ะฐ, ะฟั€ะพั‚ะพะบะพะป IMAP
openssl s_client -connect example.com:143 -starttls imap -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฟั€ะพะฒะตั€ะบะฐ ะฟะพั‡ั‚ะพะฒะพะณะพ ัะตั€ะฒะตั€ะฐ, ะฟั€ะพั‚ะพะบะพะป IMAP
openssl s_client -connect example.com:993 -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฒ ะฟั€ะธะฝั†ะธะฟะต ะฐะฝะฐะปะพะณะธั‡ะฝะพ ะฟั€ะพะฒะตั€ััŽั‚ัั ะธ ะดั€ัƒะณะธะต ัะตั€ะฒะธัั‹

ื•ื•ื™ื™ึทื˜ืขืจ ืื™ืจ ื“ืึทืจืคึฟืŸ ืฆื• ืงื•ืงืŸ ื“ืึธ ื“ื™ื™ืŸ ืกื™ืจื™ืึทืœ ื ื•ืžืขืจ, ืื•ืŸ ืื•ื™ื‘ ืขืก ืื™ื– ืื•ื™ืฃ ื“ืขืจ ืจืฉื™ืžื”, ืขืก ืื™ื– ืจืขืงืึทืžืขื ื“ื™ื“ ืฆื• ื‘ืึทื ื™ื™ึทืขืŸ ื“ื™ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ (s).

ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ืื™ืจ ืงืขื ืขืŸ ื ื•ืฆืŸ certbot:

certbot renew --force-renewal

ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ื’ืขืคึฟื•ื ืขืŸ ื’ืขื•ื•ืึธืจืŸ ืื•ื™ืฃ 29 ืคืขื‘ืจื•ืืจ 2020; ืฆื• ืกืึธืœื•ื•ืข ื“ืขื ืคึผืจืึธื‘ืœืขื, ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืคื•ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื™ื– ืกื•ืกืคึผืขื ื“ืขื“ ืคื•ืŸ 3:10 UTC ืฆื• 5:22 UTC. ืœื•ื™ื˜ ื“ื™ ืื™ื ืขืจืœืขื›ืข ื•ื™ืกืคืึธืจืฉื•ื ื’, ื“ืขืจ ื˜ืขื•ืช ืื™ื– ื’ืขืžืื›ื˜ ืื•ื™ืฃ ื™ื•ืœื™ 25, 2019; ื“ื™ ืคื™ืจืžืข ื•ื•ืขื˜ ืฆื•ืฉื˜ืขืœืŸ ืึท ืžืขืจ ื“ื™ื˜ื™ื™ืœื“ ื‘ืึทืจื™ื›ื˜ ืฉืคึผืขื˜ืขืจ.

UPD: ื“ื™ ืึธื ืœื™ื™ืŸ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ื“ื™ื ืกื˜ ืงืขืŸ ื ื™ืฉื˜ ืึทืจื‘ืขื˜ืŸ ืคึฟื•ืŸ ืจื•ืกื™ืฉ IP ืึทื“ืจืขืกืขืก.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’