[root@UCT-PRD ~]# cd acme.sh [root@UCT-PRD acme.sh]# ls acme.sh deploy dnsapi README.md [root@UCT-PRD acme.sh]# ./acme.sh --install [Mon Dec 12 14:01:44 CST 2016] It is recommended to install nc first, try to install 'nc' or 'netcat'. [Mon Dec 12 14:01:44 CST 2016] We use nc for standalone server if you use standalone mode. [Mon Dec 12 14:01:44 CST 2016] If you don't use standalone mode, just ignore this warning. [Mon Dec 12 14:01:44 CST 2016] Installing to /root/.acme.sh [Mon Dec 12 14:01:44 CST 2016] Installed to /root/.acme.sh/acme.sh [Mon Dec 12 14:01:44 CST 2016] Installing alias to '/root/.bashrc' [Mon Dec 12 14:01:44 CST 2016] OK, Close and reopen your terminal to start using acme.sh [Mon Dec 12 14:01:44 CST 2016] Installing alias to '/root/.cshrc' [Mon Dec 12 14:01:44 CST 2016] Installing alias to '/root/.tcshrc' [Mon Dec 12 14:01:44 CST 2016] Installing cron job [Mon Dec 12 14:01:44 CST 2016] Good, bash is found, so change the shebang to use bash as prefered. [Mon Dec 12 14:01:44 CST 2016] OK [root@UCT-PRD acme.sh]#
[root@UCT-PRD acme.sh]# ./acme.sh --issue -d iamtim.wang -d www.iamtim.wang -w /var/www/html [Mon Dec 12 14:03:31 CST 2016] Registering account [Mon Dec 12 14:03:55 CST 2016] Registered [Mon Dec 12 14:04:07 CST 2016] Update success. [Mon Dec 12 14:04:07 CST 2016] Creating domain key [Mon Dec 12 14:04:07 CST 2016] Multi domain='DNS:www.iamtim.wang' [Mon Dec 12 14:04:07 CST 2016] Getting domain auth token for each domain [Mon Dec 12 14:04:07 CST 2016] Getting webroot for domain='iamtim.wang' [Mon Dec 12 14:04:07 CST 2016] _w='/var/www/html' [Mon Dec 12 14:04:07 CST 2016] Getting new-authz for domain='iamtim.wang' [Mon Dec 12 14:04:19 CST 2016] The new-authz request is ok. [Mon Dec 12 14:04:19 CST 2016] Getting webroot for domain='www.iamtim.wang' [Mon Dec 12 14:04:19 CST 2016] _w='/var/www/html' [Mon Dec 12 14:04:19 CST 2016] Getting new-authz for domain='www.iamtim.wang' [Mon Dec 12 14:04:31 CST 2016] The new-authz request is ok. [Mon Dec 12 14:04:31 CST 2016] Verifying:iamtim.wang [Mon Dec 12 14:04:57 CST 2016] Success [Mon Dec 12 14:04:57 CST 2016] Verifying:www.iamtim.wang [Mon Dec 12 14:05:21 CST 2016] Success [Mon Dec 12 14:05:21 CST 2016] Verify finished, start to sign. [Mon Dec 12 14:05:33 CST 2016] Cert success. -----BEGIN CERTIFICATE----- ... -----END CERTIFICATE----- [Mon Dec 12 14:05:33 CST 2016] Your cert is in /root/.acme.sh/iamtim.wang/iamtim.wang.cer [Mon Dec 12 14:05:33 CST 2016] Your cert key is in /root/.acme.sh/iamtim.wang/iamtim.wang.key [Mon Dec 12 14:05:45 CST 2016] The intermediate CA cert is in /root/.acme.sh/iamtim.wang/ca.cer [Mon Dec 12 14:05:45 CST 2016] And the full chain certs is there: /root/.acme.sh/iamtim.wang/fullchain.cer [root@UCT-PRD acme.sh]#
拷贝证书到相应目录
证书申请成功后,拷贝证书到相应目录中(ssl.conf定义位置):
1 2 3 4 5 6 7 8 9
[root@UCT-PRD acme.sh]# ./acme.sh --installcert -d iamtim.wang --certpath /etc/httpd/conf/iamtim.wang/cert.pem --keypath /etc/httpd/conf/iamtim.wang/key.pem --fullchainpath /etc/httpd/conf/iamtim.wang/fullchain.pem --reloadcmd "service httpd restart" [Mon Dec 12 14:13:40 CST 2016] Installing cert to:/etc/httpd/conf/iamtim.wang/cert.pem [Mon Dec 12 14:13:40 CST 2016] Installing key to:/etc/httpd/conf/iamtim.wang/key.pem [Mon Dec 12 14:13:40 CST 2016] Installing full chain to:/etc/httpd/conf/iamtim.wang/fullchain.pem [Mon Dec 12 14:13:40 CST 2016] Run Le_ReloadCmd: service httpd restart Stopping httpd: [ OK ] Starting httpd: [ OK ] [Mon Dec 12 14:13:40 CST 2016] Reload success [root@UCT-PRD acme.sh]#