Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[建议] 免费证书申请增加 DNS-01 验证支持,并支持通配符证书申请 #590

Closed
best opened this issue Jan 9, 2024 · 6 comments
Labels
duplicate This issue or pull request already exists

Comments

@best
Copy link

best commented Jan 9, 2024

背景与遇到的问题

  1. 免费证书仅支持 HTTP-01 方法,在多节点部署时灵活性较差(如主备部署时仅主节点可以申请免费证书);
  2. HTTP-01 下无法支持通配符证书申请,多站点情况下需要多次申请证书无法,易用性不足。

建议的解决方案

  1. “免费证书申请” 支持 DNS-01 方法;
  2. DNS-01 方法支持申请通配符证书;
  3. DNS-01 方法支持阿里云DNS、DNSPod、CloudFlare 等国内使用广泛的 DNS 厂商。
@GodRuiAn
Copy link

GodRuiAn commented Jan 9, 2024

支持,因为没有80和443端口可用,现在在雷池部署的服务器上使用acme.sh自动申请泛域名证书,然后每隔2个月手动更新到雷池里,真的是很麻烦。acme.sh本来是支持自动安装到nginx并自动重载的。

@yrluke
Copy link
Collaborator

yrluke commented Jan 10, 2024

既然都已经是多节点部署了,要不要考虑来一套企业版,安全公司都要饿死了

@best
Copy link
Author

best commented Jan 10, 2024

既然都已经是多节点部署了,要不要考虑来一套企业版,安全公司都要饿死了

没办法呀,个人爱好拿来玩一玩上不了企业版,但是你们的专业版肯定支持,昨晚上在你们的直播也刷了些礼物支持。

@best
Copy link
Author

best commented Jan 10, 2024

希望如果开源版本因为人力无法做到的话,你们的专业版可以支持 DNS-01 方法

@GodRuiAn
Copy link

我觉得DNS验证的方式恰恰是更适合于个人用户吧,企业用户都是购买商业证书而不会使用这种稳定性和兼容性都很低的免费证书,以及需要自行进行DNS验证。acme申请的免费的泛域名证书,只支持3个月,需要频繁更新,有哪个生产环境的站点会使用这种证书?

@Lorna0
Copy link
Collaborator

Lorna0 commented Jan 17, 2024

@Lorna0 Lorna0 closed this as not planned Won't fix, can't repro, duplicate, stale Jan 17, 2024
@Lorna0 Lorna0 added the duplicate This issue or pull request already exists label Jan 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate This issue or pull request already exists
Projects
None yet
Development

No branches or pull requests

4 participants