Isalathiso senqaku
Usifaka njani i-Letsencrypt SSL isatifikethi sasimahla se-SSL se-CWP7 yegama lomamkeli?
- yi le Iphaneli yokulawula yeCWP Isikhokelo se-AutoSSL sokufakela ngokuzenzekelayo i-Letsencrypt yasimahla izatifikethi ze-SSL.
Ukuba umyalezo wemposiso ye-CWP7 SSL "cwpsrv.inkonzo failed.", nceda ukhangele isisombululo sesi sifundo silandelayo▼
Ulitshintsha njani igama lomamkeli kwi-CWP?
Masithi igama lomamkeli wakho ngu server.yourdomain.com
- Okokuqala, yenza i-subdomain kwi-backend ye-CWP:
server.yourdomain.com
- Yongeza irekhodi kwi-DNS, i-subdomain amanqaku kweyakhoLinuxIdilesi ye-IP yomncedisi.
- Yiya ku → Izicwangciso ze-CWP → Guqula igama lomamkeli kwimenyu esekhohlo ye-cwp.admin ukugcina igama lomamkeli wakho.
- I-SSL iya kufakwa ngokuzenzekelayo, imeko kuphela kukuba usethe i-DNS irekhodi yegama lomninimzi.
- Ukuba awunayo irekhodi i-A yegama lomamkeli, i-CWP iza kufakela isatifikethi esizisayinileyo.
- Qaphela ukuba igama lenginginya kufuneka libe yisizinda esisezantsi kwaye ingabi ngummandla ongundoqo.
Kwi-http: // ukuya ku-https: // ulwalathiso, unako/usr/local/apache/htdocs/.htaccess
Yenza le fayile ye-htaccess:
RewriteEngine On RewriteCond %{HTTPS} off RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
Masi Fihla ligunya lesatifikethi elasungulwa nge-2016 ka-Epreli, 4, ngenjongo yokuphelisa ukwenziwa kwezandla kwangoku, ukuqinisekiswa, ukusayina, ukufakela kunye nohlaziyo lwezatifikethi zewebhusayithi ezikhuselekileyo.
Igama lomamkeli/FQDN Faka iSatifikethi seLetsencrypt SSL
- FQDN (
fully qualified domain name
) Igama le-domain eliqeqeshwe ngokupheleleyo, eliligama elipheleleyo le-domain yekhompyutha ethile okanye inginginya kwi-Intanethi.
Ungasifaka njani isicelo seLet Encrypting?
Kukho imodyuli entsha ebandakanyiweyo kwiMenu yeCWP7 eKhohlo → Useto lweWebServer → Izatifikethi ze-SSL, ukusuka apho ungafaka izatifikethi zeLetsencrypt kuyo nayiphi na isizinda/isizinda esisezantsi usebenzisa iAutoSSL.
(Ukuba ukhetha Yenza Masi Fihla ngexesha elinye xa usongeza igama lesizinda okanye igama lesizinda, ungatsiba la manyathelo angasentla)
Iimpawu zeSatifikethi se-Letsencrypt SSL
- I-Letsencrypt yesizinda seakhawunti ephambili kunye ne-www alias
- I-Letsencrypt yongeza igama lesizinda kunye ne-www. alias
- I-Letsencrypt ye-subdomains kunye ne-www.alias
- I-Letsencrypt inokufakela isiko
- Jonga umhla wokuphelelwa kwesatifikethi
- ukuhlaziya okuzenzekelayo
- Nyanzelela iqhosha lokuhlaziya
- I-Apache port 443 i-auto-detection
Uhlaziyo oluzenzekelayo lwezatifikethi ze-Letsencrypt SSL
Ngokungagqibekanga, izatifikethi zeLetsencrypt zisebenza kangangeentsuku ezingama-90.
Uhlaziyo luyazenzekela kwaye izatifikethi zihlaziywa kwiintsuku ezingama-30 phambi kokuphelelwa yisikhathi.
Kukho imodyuli entsha ebandakanyiweyo kwiMenu yeCWP7 eKhohlo → Useto lweWebServer → Izatifikethi ze-SSL, ukusuka apho ungafaka izatifikethi zeLetsencrypt kuyo nayiphi na isizinda/isizinda esisezantsi usebenzisa iAutoSSL.
Hlela ifayile yoqwalaselo endaweni yendlela yesatifikethi se-SSL
Emva koko, kufuneka uhlele ifayile yoqwalaselo kwaye ungeze umendo wesatifikethi se-SSL (qaphela ukususa izimvo, kwaye utshintshe indlela eya kweyakho).
Hlela ifayile yoqwalaselo ye-cwpsrv ▼
/usr/local/cwpsrv/conf/cwpsrv.conf
Faka kwiMonitha esweniIzibuko le-SSL ▼
listen 2812 ssl;
Kukwakho lo mhlathi ulandelayo ▼
ssl_certificate /etc/pki/tls/certs/hostname.crt; ssl_certificate_key /etc/pki/tls/private/hostname.key;
Faka endaweni yale ndlela ilandelayo ▼
ssl_certificate /etc/pki/tls/certs/server.yourdomain.com.bundle; ssl_certificate_key /etc/pki/tls/private/server.yourdomain.com.key;
Nje ukuba ugqibile, ungalibali ukuqalisa kwakhona inkonzo ye-cwpsrv ngalo myalelo ulandelayo ▼
service cwpsrv restart
Emva koko uye kuSeto lweWebserver → Umhleli weWebServers Conf → Apache → /usr/local/apache/conf.d/
Hlela iProfayile ▼
hostname-ssl.conf
Beka lo mhlathi ulandelayo ▼
ssl_certificate /etc/pki/tls/certs/hostname.crt; ssl_certificate_key /etc/pki/tls/private/hostname.key;
Faka endaweni yale ndlela ilandelayo ▼
ssl_certificate /etc/pki/tls/certs/server.yourdomain.com.bundle; ssl_certificate_key /etc/pki/tls/private/server.yourdomain.com.key;
- Ukuba usebenzisa iNginx, kufuneka wenze okufanayo.
Emva koko uqalise kwakhona i-Apache (kunye ne-Nginx) inkonzo kwaye uqiniseke ukuba isebenza njengesiqhelo?
systemctl restart httpd systemctl restart nginx
Okokugqibela, hlaziya ikhonkco lokungena ukujonga i-port 2087https:// server.yourdomain. com:2087/login/index.php
Ingaba ikhona idongle?
Ndiyathemba Chen Weiliang Blog ( https://www.chenweiliang.com/ ) kwabelwana "impazamo ye-CWP7 SSL? Igama lomninimzi lifaka njani isiqinisekiso sasimahla seLetsencrypt?", eluncedo kuwe.
Wamkelekile ukwabelana ngekhonkco leli nqaku:https://www.chenweiliang.com/cwl-27950.html
Wamkelekile kwisitishi seTelegram sebhlog kaChen Weiliang ukufumana uhlaziyo lwamva nje!
📚 Esi sikhokelo sinexabiso elikhulu, 🌟Eli lithuba elinqabileyo, ungaliphoswa! ⏰⌛💨
Yabelana kwaye uthanda ukuba uyathanda!
Ukwabelana kwakho kunye nezinto ozithandayo ziyinkuthazo yethu eqhubekayo!