Impazamo ye-CWP7 SSL Ungasihlohla njani isiqinisekiso sasimahla seLetsencrypt?

Usifaka njani i-Letsencrypt SSL isatifikethi sasimahla se-SSL se-CWP7 yegama lomamkeli?

Impazamo ye-CWP7 SSL Ungasihlohla njani isiqinisekiso sasimahla seLetsencrypt?

  • yi le Iphaneli yokulawula yeCWP Isikhokelo se-AutoSSL sokufakela ngokuzenzekelayo i-Letsencrypt yasimahla izatifikethi ze-SSL.

Ukuba umyalezo wemposiso ye-CWP7 SSL "cwpsrv.inkonzo failed.", nceda ukhangele isisombululo sesi sifundo silandelayo▼

Ulitshintsha njani igama lomamkeli kwi-CWP?

Masithi igama lomamkeli wakho ngu server.yourdomain.com

  1. Okokuqala, yenza i-subdomain kwi-backend ye-CWP:server.yourdomain.com
  2. Yongeza irekhodi kwi-DNS, i-subdomain amanqaku kweyakhoLinuxIdilesi ye-IP yomncedisi.
  3. Yiya ku → Izicwangciso ze-CWP → Guqula igama lomamkeli kwimenyu esekhohlo ye-cwp.admin ukugcina igama lomamkeli wakho.
  • I-SSL iya kufakwa ngokuzenzekelayo, imeko kuphela kukuba usethe i-DNS irekhodi yegama lomninimzi.
  • Ukuba awunayo irekhodi i-A yegama lomamkeli, i-CWP iza kufakela isatifikethi esizisayinileyo.
  • Qaphela ukuba igama lenginginya kufuneka libe yisizinda esisezantsi kwaye ingabi ngummandla ongundoqo.

Kwi-http: // ukuya ku-https: // ulwalathiso, unako/usr/local/apache/htdocs/.htaccessYenza le fayile ye-htaccess:

RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]

Masi Fihla ligunya lesatifikethi elasungulwa nge-2016 ka-Epreli, 4, ngenjongo yokuphelisa ukwenziwa kwezandla kwangoku, ukuqinisekiswa, ukusayina, ukufakela kunye nohlaziyo lwezatifikethi zewebhusayithi ezikhuselekileyo.

Igama lomamkeli/FQDN Faka iSatifikethi seLetsencrypt SSL

Ithetha ukuthini i-FQDN??

  • FQDN (fully qualified domain name) Igama le-domain eliqeqeshwe ngokupheleleyo, eliligama elipheleleyo le-domain yekhompyutha ethile okanye inginginya kwi-Intanethi.

Ungasifaka njani isicelo seLet Encrypting?

Kukho imodyuli entsha ebandakanyiweyo kwiMenu yeCWP7 eKhohlo → Useto lweWebServer → Izatifikethi ze-SSL, ukusuka apho ungafaka izatifikethi zeLetsencrypt kuyo nayiphi na isizinda/isizinda esisezantsi usebenzisa iAutoSSL.

(Ukuba ukhetha Yenza Masi Fihla ngexesha elinye xa usongeza igama lesizinda okanye igama lesizinda, ungatsiba la manyathelo angasentla)

Iimpawu zeSatifikethi se-Letsencrypt SSL

  • I-Letsencrypt yesizinda seakhawunti ephambili kunye ne-www alias
  • I-Letsencrypt yongeza igama lesizinda kunye ne-www. alias
  • I-Letsencrypt ye-subdomains kunye ne-www.alias
  • I-Letsencrypt inokufakela isiko
  • Jonga umhla wokuphelelwa kwesatifikethi
  • ukuhlaziya okuzenzekelayo
  • Nyanzelela iqhosha lokuhlaziya
  • I-Apache port 443 i-auto-detection

Uhlaziyo oluzenzekelayo lwezatifikethi ze-Letsencrypt SSL

Ngokungagqibekanga, izatifikethi zeLetsencrypt zisebenza kangangeentsuku ezingama-90.

Uhlaziyo luyazenzekela kwaye izatifikethi zihlaziywa kwiintsuku ezingama-30 phambi kokuphelelwa yisikhathi.

Kukho imodyuli entsha ebandakanyiweyo kwiMenu yeCWP7 eKhohlo → Useto lweWebServer → Izatifikethi ze-SSL, ukusuka apho ungafaka izatifikethi zeLetsencrypt kuyo nayiphi na isizinda/isizinda esisezantsi usebenzisa iAutoSSL.

Hlela ifayile yoqwalaselo endaweni yendlela yesatifikethi se-SSL

Emva koko, kufuneka uhlele ifayile yoqwalaselo kwaye ungeze umendo wesatifikethi se-SSL (qaphela ukususa izimvo, kwaye utshintshe indlela eya kweyakho).

Hlela ifayile yoqwalaselo ye-cwpsrv ▼

/usr/local/cwpsrv/conf/cwpsrv.conf

Faka kwiMonitha esweniIzibuko le-SSL ▼

listen 2812 ssl;

Kukwakho lo mhlathi ulandelayo ▼

ssl_certificate /etc/pki/tls/certs/hostname.crt;
ssl_certificate_key /etc/pki/tls/private/hostname.key;

Faka endaweni yale ndlela ilandelayo ▼

ssl_certificate /etc/pki/tls/certs/server.yourdomain.com.bundle;
ssl_certificate_key /etc/pki/tls/private/server.yourdomain.com.key;

Nje ukuba ugqibile, ungalibali ukuqalisa kwakhona inkonzo ye-cwpsrv ngalo myalelo ulandelayo ▼

service cwpsrv restart

Emva koko uye kuSeto lweWebserver → Umhleli weWebServers Conf → Apache → /usr/local/apache/conf.d/

Hlela iProfayile ▼

hostname-ssl.conf

Beka lo mhlathi ulandelayo ▼

ssl_certificate /etc/pki/tls/certs/hostname.crt;
ssl_certificate_key /etc/pki/tls/private/hostname.key;

Faka endaweni yale ndlela ilandelayo ▼

ssl_certificate /etc/pki/tls/certs/server.yourdomain.com.bundle;
ssl_certificate_key /etc/pki/tls/private/server.yourdomain.com.key;
  • Ukuba usebenzisa iNginx, kufuneka wenze okufanayo.

Emva koko uqalise kwakhona i-Apache (kunye ne-Nginx) inkonzo kwaye uqiniseke ukuba isebenza njengesiqhelo?

systemctl restart httpd
systemctl restart nginx

Okokugqibela, hlaziya ikhonkco lokungena ukujonga i-port 2087https:// server.yourdomain. com:2087/login/index.phpIngaba ikhona idongle?

Ndiyathemba Chen Weiliang Blog ( https://www.chenweiliang.com/ ) kwabelwana "impazamo ye-CWP7 SSL? Igama lomninimzi lifaka njani isiqinisekiso sasimahla seLetsencrypt?", eluncedo kuwe.

Wamkelekile ukwabelana ngekhonkco leli nqaku:https://www.chenweiliang.com/cwl-27950.html

Wamkelekile kwisitishi seTelegram sebhlog kaChen Weiliang ukufumana uhlaziyo lwamva nje!

🔔 Yiba ngowokuqala ukufumana iSikhokelo sokuSetyenziswa kweSixhobo se-"ChatGPT yeNtengiso ye-AI" kuluhlu oluphezulu lwetshaneli! 🌟
📚 Esi sikhokelo sinexabiso elikhulu, 🌟Eli lithuba elinqabileyo, ungaliphoswa! ⏰⌛💨
Yabelana kwaye uthanda ukuba uyathanda!
Ukwabelana kwakho kunye nezinto ozithandayo ziyinkuthazo yethu eqhubekayo!

 

Shiya uluvo

Idilesi ye-imeyile ayizukupapashwa. Iinkalo ezifunekayo zisetyenzisiwe * Ileyibheli

skrolela phezulu