LetsEncrypt, ืืืึธืก ืึธืคืคืขืจืก ืคืจืื ืกืกื ืกืขืจืืืคืืงืึทืฅ ืคึฟืึทืจ ืขื ืงืจืืคึผืฉืึทื, ืืื ืืขืฆืืืื ืืขื ืฆื ืึธืคึผืจืืคื ืขืืืขืืข ืกืขืจืืืคืืงืึทืฅ.
ืื ืคึผืจืึธืืืขื ืืื ืฉืืื ืฆื
ืืืืก ืืื ืืขืจ ืืขืืช? ืืืื ืึท ืืึทืืืืึทืื ืืขืื ืึผืืื N ืืึธืืืืื ื ืืืึธืก ืืึทืจืคื ืจืืคึผืืืื CAA ืืืขืจืึทืคืึทืงืืืฉืึทื, ืืึธืืืืขืจ ืกืึทืืขืงืฅ ืืืื ืขืจ ืคืื ืืื ืืื ืืืขืจืึทืคืืื ืขืก N ืืื. ืืื ืึท ืจืขืืืืืึทื, ืขืก ืืื ืืขืืืขื ืืขืืืขื ืฆื ืึทืจืืืกืืขืื ืึท ืืึทืืืืึทืื ืืคืืื ืืืื ืืืจ ืฉืคึผืขืืขืจ (ืึทืจืืืฃ ืฆื X + 30 ืืขื) ืฉืืขืื ืึท CAA ืจืขืงืึธืจื ืืืึธืก ืคึผืจืึธืืืืืึทืฅ ืื ืึทืจืืืกืืขืื ืคืื ืึท LetsEncrypt ืืึทืืืืึทืื.
ืฆื ืืึทืฉืืขืืืงื ืกืขืจืืืคืืงืึทืฅ, ืื ืคืืจืืข ืืื ืฆืืืขืืจืืื
ืึทืืืึทื ืกืืจืืข ื ืืฆืขืจืก ืงืขื ืขื ืืึธื ืึทืืฅ ืืื ืืื ืื ืคืืืืขื ืืข ืงืึทืืึทื ืื:
# ะฟัะพะฒะตัะบะฐ https
openssl s_client -connect example.com:443 -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฒะฐัะธะฐะฝั ะฟัะพะฒะตัะบะธ ะพั @simpleadmin
echo | openssl s_client -connect example.com:443 |& openssl x509 -noout -serial
# ะฟัะพะฒะตัะบะฐ ะฟะพััะพะฒะพะณะพ ัะตัะฒะตัะฐ, ะฟัะพัะพะบะพะป SMTP
openssl s_client -connect example.com:25 -starttls smtp -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฟัะพะฒะตัะบะฐ ะฟะพััะพะฒะพะณะพ ัะตัะฒะตัะฐ, ะฟัะพัะพะบะพะป SMTP
openssl s_client -connect example.com:587 -starttls smtp -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฟัะพะฒะตัะบะฐ ะฟะพััะพะฒะพะณะพ ัะตัะฒะตัะฐ, ะฟัะพัะพะบะพะป IMAP
openssl s_client -connect example.com:143 -starttls imap -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฟัะพะฒะตัะบะฐ ะฟะพััะพะฒะพะณะพ ัะตัะฒะตัะฐ, ะฟัะพัะพะบะพะป IMAP
openssl s_client -connect example.com:993 -showcerts </dev/null 2>/dev/null | openssl x509 -text -noout | grep -A 1 Serial Number | tr -d :
# ะฒ ะฟัะธะฝัะธะฟะต ะฐะฝะฐะปะพะณะธัะฝะพ ะฟัะพะฒะตัััััั ะธ ะดััะณะธะต ัะตัะฒะธัั
ืืืืึทืืขืจ ืืืจ ืืึทืจืคึฟื ืฆื ืงืืงื
ืฆื ืืขืจืืืึทื ืืืงื ืกืขืจืืืคืืงืึทืฅ, ืืืจ ืงืขื ืขื ื ืืฆื certbot:
certbot renew --force-renewal
ืืขืจ ืคึผืจืึธืืืขื ืืื ืืขืคึฟืื ืขื ืืขืืืึธืจื ืืืืฃ 29 ืคืขืืจืืืจ 2020; ืฆื ืกืึธืืืืข ืืขื ืคึผืจืึธืืืขื, ืื ืึทืจืืืกืืขืื ืคืื ืกืขืจืืืคืืงืึทืฅ ืืื ืกืืกืคึผืขื ืืขื ืคืื 3:10 UTC ืฆื 5:22 UTC. ืืืื ืื ืืื ืขืจืืขืืข ืืืกืคืึธืจืฉืื ื, ืืขืจ ืืขืืช ืืื ืืขืืืื ืืืืฃ ืืืื 25, 2019; ืื ืคืืจืืข ืืืขื ืฆืืฉืืขืื ืึท ืืขืจ ืืืืืืื ืืึทืจืืื ืฉืคึผืขืืขืจ.
UPD: ืื ืึธื ืืืื ืืึทืืืืึทืื ืืืขืจืึทืคืึทืงืืืฉืึทื ืืื ืกื ืงืขื ื ืืฉื ืึทืจืืขืื ืคึฟืื ืจืืกืืฉ IP ืึทืืจืขืกืขืก.
ืืงืืจ: www.habr.com