ื–ืืœ ืก ืขื ืงืจื™ืคึผื˜ ืจื™ื•ื•ืึธื•ืงืก 2 ืžื™ืœื™ืึธืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืจืขื›ื˜ ืฆื• ืคึผืจืึธื‘ืœืขืžืก ืžื™ื˜ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ TLS-ALPN-01

Let's Encrypt, ืึท ื ืึทืŸ-ื ื•ืฅ ืกืขืจื˜ื™ืคื™ืงืึทื˜ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜ ื•ื•ืึธืก ืื™ื– ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ื“ื™ ืงื”ืœ ืื•ืŸ ื’ื™ื˜ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืคืจื™ื™ ืฆื• ืึทืœืขืžืขืŸ, ืึทื ืึทื•ื ืกื˜ ื“ื™ ืคืจื™ ืจืขื•ื•ืึธืงืึทื˜ื™ืึธืŸ ืคื•ืŸ ื‘ืขืขืจืขืš ืฆื•ื•ื™ื™ ืžื™ืœื™ืึธืŸ TLS ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ื•ื•ืึธืก ืื™ื– ื•ื•ืขื’ืŸ 1% ืคื•ืŸ ืึทืœืข ืึทืงื˜ื™ื•ื• ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืคื•ืŸ ื“ืขื ืกืขืจื˜ืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ื™ื˜ืึธืจื™ื˜ืขื˜. ื“ื™ ืจืขื•ื•ืึธืงืึทื˜ื™ืึธืŸ ืคื•ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื™ื– ื™ื ื™ืฉื™ื™ื™ื˜ื™ื“ ืจืขื›ื˜ ืฆื• ื“ืขืจ ืœืขื’ื™ื˜ื™ืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื ื™ื˜-ื”ืขืกืงืขื ืจืขืงื•ื•ื™ืจืขืžืขื ืฅ ืื™ืŸ ื“ื™ ืงืึธื“ ื’ืขื ื™ืฆื˜ ืื™ืŸ Let's Encrypt ืžื™ื˜ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ TLS-ALPN-01 ืคืึทืจืœืขื ื’ืขืจื•ื ื’ (RFC 7301, ืึทืคึผืคึผืœื™ืงืึทื˜ื™ืึธืŸ-ืฉื™ื›ื˜ืข ืคึผืจืึธื˜ืึธืงืึธืœ ืคืึทืจื”ืึทื ื“ืœื•ื ื’). ื“ื™ ื“ื™ืกืงืจืขืคึผืึทื ืกื™ ืื™ื– ื’ืขื•ื•ืขืŸ ืจืขื›ื˜ ืฆื• ื“ืขืจ ืึทื•ื•ืขืง ืคื•ืŸ ืขื˜ืœืขื›ืข ื˜ืฉืขืงืก ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื‘ืขืฉืึทืก ื“ื™ ืคืึทืจื”ืึทื ื“ืœื•ื ื’ ืคึผืจืึธืฆืขืก ืคึฟืึทืจ ืงืฉืจ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ ALPN TLS ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ื’ืขื ื™ืฆื˜ ืื™ืŸ HTTP/2. ื“ื™ื˜ื™ื™ืœื“ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ืื™ื ืฆื™ื“ืขื ื˜ ื•ื•ืขื˜ ื–ื™ื™ืŸ ืคืืจืขืคื ื˜ืœืขื›ื˜ ื ืึธืš ื“ื™ ืจืขื•ื•ืึธืงืึทื˜ื™ืึธืŸ ืคื•ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืื™ื– ื’ืขืขื ื“ื™ืงื˜.

ืื•ื™ืฃ 26 ื™ืื ื•ืืจ 03:48 (MSK) ื“ื™ ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜, ืึธื‘ืขืจ ืึทืœืข ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื•ื•ืึธืก ื–ืขื ืขืŸ ืืจื•ื™ืก ืžื™ื˜ ื“ื™ TLS-ALPN-01 ืื•ืคึฟืŸ ืคึฟืึทืจ ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ื–ืขื ืขืŸ ื‘ืึทืฉืœืึธืกืŸ ืฆื• ื–ื™ื™ืŸ ื™ื ื•ื•ืึทืœืึทื“ื™ื™ื˜ืึทื“. ืจืขื•ื•ืึธืงืึทื˜ื™ืึธืŸ ืคื•ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื•ื•ืขื˜ ืึธื ื”ื™ื™ื‘ืŸ ืื•ื™ืฃ ื™ืื ื•ืืจ 28 ื‘ื™ื™ึท 19:00 (MSK). ื‘ื™ื– ื“ืขื ืžืึธืœ, ื ื™ืฆืขืจืก ื•ื•ืึธืก ื ื•ืฆืŸ ื“ื™ TLS-ALPN-01 ื•ื•ืขืจืึทืคืึทืงื™ื™ืฉืึทืŸ ืื•ืคึฟืŸ ื–ืขื ืขืŸ ืึทื“ื•ื•ื™ื™ื–ื“ ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ื–ื™ื™ืขืจ ืกืขืจื˜ื™ืคื™ืงืึทืฅ, ืึทื ื“ืขืจืฉ ื–ื™ื™ ื•ื•ืขืœืŸ ื–ื™ื™ืŸ ื™ื ื•ื•ืึทืœืึทื“ื™ื™ื˜ืึทื“ ืคืจื™.

ื‘ืึทื˜ื™ื™ึทื˜ื™ืง ื ืึธื•ื˜ืึทืคืึทืงื™ื™ืฉืึทื ื– ื•ื•ืขื’ืŸ ื“ืขื ื“ืึทืจืคึฟืŸ ืฆื• ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื–ืขื ืขืŸ ื’ืขืฉื™ืงื˜ ื“ื•ืจืš E- ื‘ืจื™ื•ื•. ื™ื•ื–ืขืจื– ื•ื•ืึธืก ื ื•ืฆืŸ ื“ื™ Certbot ืื•ืŸ ื“ื™ื›ื™ื™ื“ืจื™ื™ื˜ืึทื“ ืžื›ืฉื™ืจื™ื ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืึทืคืขืงื˜ืึทื“ ื“ื•ืจืš ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ื•ื•ืขืŸ ื–ื™ื™ ื ื•ืฆืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืกืขื˜ื˜ื™ื ื’ืก. ื“ื™ TLS-ALPN-01 ืื•ืคึฟืŸ ืื™ื– ื’ืขืฉื˜ื™ืฆื˜ ืื™ืŸ ื“ื™ ืงืึทื“ื™, ื˜ืจืึทืคื™ืง, ืึทืคึผืึทื˜ืฉื™ ืžืึธื“_ืžื“ ืื•ืŸ ืึทื•ื˜ืึธืกืขืจื˜ ืคึผืึทืงืึทื“ื–ืฉืึทื–. ืื™ืจ ืงืขื ืขืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืจื™ื›ื˜ื™ืง ืคื•ืŸ ื“ื™ื™ืŸ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื“ื•ืจืš ื–ื•ื›ืŸ ืคึฟืึทืจ ื™ื“ืขื ื˜ื™ืคื™ืขืจืก, ืกื™ืจื™ืึทืœ ื ื•ืžืขืจืŸ ืึธื“ืขืจ ื“ืึธื•ืžื™ื™ื ื– ืื™ืŸ ื“ืขืจ ืจืฉื™ืžื” ืคื•ืŸ ืคึผืจืึธื‘ืœืขืžืึทื˜ื™ืง ืกืขืจื˜ื™ืคื™ืงืึทืฅ.

ื–ื™ื ื˜ ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ื•ื•ื™ืจืงืŸ ื“ื™ ื ืึทื˜ื•ืจ ื•ื•ืขืŸ ื˜ืฉืขืง ืžื™ื˜ ื“ื™ TLS-ALPN-01 ืื•ืคึฟืŸ, ืึทืคึผื“ื™ื™ื˜ื™ื ื’ ื“ื™ ACME ืงืœื™ืขื ื˜ ืึธื“ืขืจ ื˜ืฉืึทื ื’ื™ื ื’ ืกืขื˜ื˜ื™ื ื’ืก (Caddy, bitnami/bn-cert, autocert, apache mod_md, Traefik) ืงืขืŸ ื–ื™ื™ืŸ ืคืืจืœืื ื’ื˜ ืฆื• ืคืึธืจื–ืขืฆืŸ ืืจื‘ืขื˜ืŸ. ื“ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ TLS ื•ื•ืขืจืกื™ืขืก ื ื™ื˜ ื ื™ื“ืขืจื™ืงืขืจ ื•ื•ื™ 1.2 (ืงืœื™ื™ืึทื ืฅ ื•ื•ืขื˜ ื ื™ื˜ ืžืขืจ ืงืขื ืขืŸ ืฆื• ื ื•ืฆืŸ TLS 1.1) ืื•ืŸ ื“ื™ ื“ื™ืคึผืจื™ืฉื™ื™ื™ืฉืึทืŸ ืคื•ืŸ OID 1.3.6.1.5.5.7.1.30.1, ื•ื•ืึธืก ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื“ื™ ืคืึทืจืขืœื˜ืขืจื˜ ืึทืงืžืขื™ื“ืขื ื˜ื™ืคื™ืขืจ ืคืึทืจืœืขื ื’ืขืจื•ื ื’, ื’ืขืฉื˜ื™ืฆื˜ ื‘ืœื•ื™ื– ืื™ืŸ ืคืจื™ืขืจ ื“ืจืึทืคืฅ ืคื•ืŸ ื“ื™ RFC 8737 ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ (ื•ื•ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ, ืื™ืฆื˜ ื‘ืœื•ื™ื– OID 1.3.6.1.5.5.7.1.31 ืื™ื– ืขืจืœื•ื™ื‘ื˜, ืื•ืŸ ืงืœื™ื™ืึทื ืฅ ื•ื•ืึธืก ื ื•ืฆืŸ OID 1.3.6.1.5.5.7.1.30.1 ืงืขื ืขืŸ ื ื™ืฉื˜ ื‘ืึทืงื•ืžืขืŸ ืึท ื‘ืึทื•ื•ื™ื™ึทื–ืŸ).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’