请教一下安装 vmbox.co 提供的 Alpha SSL 的正确姿势 - V2EX
V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
acrisliu

请教一下安装 vmbox.co 提供的 Alpha SSL 的正确姿势

  •  
  •   acrisliu Sep 24, 2015 4011 views
    This topic created in 3871 days ago, the information mentioned may be changed or developed.
    在 vmbox 弄了一个野卡,然后服务器是 Nginx 。我把他们给的 CERT(PEM format) Certificate 和 Intermediate Certificate 合并到了一个文件 server.crt ,然后私钥是 server.key 。 Nginx 配置了对应的 ssl_certificate 和 ssl_certificate_key 分别指向这两个文件,但是重启 nginx 的时候提示: nginx: [warn] "ssl_stapling" ignored, issuer certificate not found 。

    哪位 V 友用过他们证书的,麻烦指点一下应该怎样安装,感激不尽。

    另外补充一下,我用的合并方式就是简单的把 CERT(PEM format) Certificate 和 Intermediate Certificate 复制到一起再另存为 server.crt ,不知道这样是不是有什么不妥。
    Supplement 1    Sep 24, 2015
    已解决,感谢 @songjiaxin2008 的指点,同时也感谢 @mamk1222
    具体做法是在合并了 CERT(PEM format) Certificate 和 Intermediate Certificate 的证书最后再贴上 AlphaSSL Intermediate Certificates 就行了,证书内容见 4L 。多谢大家。
    7 replies    2015-09-24 23:27:20 +08:00
    acrisliu
        1
    acrisliu  
    OP
       Sep 24, 2015
    谷歌了一下,一般服务商都会给三个证书: server.crt, ca.crt, root.crt ,然后三个合到一起。但是现在 vmbox 只给了两个,要怎么操作才行呢 >_<||
    mamk1222
        2
    mamk1222  
       Sep 24, 2015   1
    acrisliu
        3
    acrisliu  
    OP
       Sep 24, 2015
    @mamk1222 麻烦告知一下 R1 GlobalSign Root Certificate 怎么使用?直接粘贴到我 server.crt 尾部么?我粘贴了,重启 nginx 还是报错: nginx: [warn] "ssl_stapling" ignored, issuer certificate not found 。
    songjiaxin2008
        4
    songjiaxin2008  
       Sep 24, 2015   1
    在你的证书下面贴上这个就行了。

    -----BEGIN CERTIFICATE-----
    MIIETTCCAzWgAwIBAgILBAAAAAABRE7wNjEwDQYJKoZIhvcNAQELBQAwVzELMAkG
    A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv
    b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw0xNDAyMjAxMDAw
    MDBaFw0yNDAyMjAxMDAwMDBaMEwxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i
    YWxTaWduIG52LXNhMSIwIAYDVQQDExlBbHBoYVNTTCBDQSAtIFNIQTI1NiAtIEcy
    MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2gHs5OxzYPt+j2q3xhfj
    kmQy1KwA2aIPue3ua4qGypJn2XTXXUcCPI9A1p5tFM3D2ik5pw8FCmiiZhoexLKL
    dljlq10dj0CzOYvvHoN9ItDjqQAu7FPPYhmFRChMwCfLew7sEGQAEKQFzKByvkFs
    MVtI5LHsuSPrVU3QfWJKpbSlpFmFxSWRpv6mCZ8GEG2PgQxkQF5zAJrgLmWYVBAA
    cJjI4e00X9icxw3A1iNZRfz+VXqG7pRgIvGu0eZVRvaZxRsIdF+ssGSEj4k4HKGn
    kCFPAm694GFn1PhChw8K98kEbSqpL+9Cpd/do1PbmB6B+Zpye1reTz5/olig4het
    ZwIDAQABo4IBIzCCAR8wDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8C
    AQAwHQYDVR0OBBYEFPXN1TwIUPlqTzq3l9pWg+Zp0mj3MEUGA1UdIAQ+MDwwOgYE
    VR0gADAyMDAGCCsGAQUFBwIBFiRodHRwczovL3d3dy5hbHBoYXNzbC5jb20vcmVw
    b3NpdG9yeS8wMwYDVR0fBCwwKjAooCagJIYiaHR0cDovL2NybC5nbG9iYWxzaWdu
    Lm5ldC9yb290LmNybDA9BggrBgEFBQcBAQQxMC8wLQYIKwYBBQUHMAGGIWh0dHA6
    Ly9vY3NwLmdsb2JhbHNpZ24uY29tL3Jvb3RyMTAfBgNVHSMEGDAWgBRge2YaRQ2X
    yolQL30EzTSo//z9SzANBgkqhkiG9w0BAQsFAAOCAQEAYEBoFkfnFo3bXKFWKsv0
    XJuwHqJL9csCP/gLofKnQtS3TOvjZoDzJUN4LhsXVgdSGMvRqOzm+3M+pGKMgLTS
    xRJzo9P6Aji+Yz2EuJnB8br3n8NA0VgYU8Fi3a8YQn80TsVD1XGwMADH45CuP1eG
    l87qDBKOInDjZqdUfy4oy9RU0LMeYmcI+Sfhy+NmuCQbiWqJRGXy2UzSWByMTsCV
    odTvZy84IOgu/5ZR8LrYPZJwR2UcnnNytGAMXOLRc3bgr07i5TelRS+KIz6HxzDm
    MTh89N1SyvNTBCVXVmaU6Avu5gMUTu79bZRknl7OedSyps9AsUSoPocZXun4IRZZUw==
    -----END CERTIFICATE-----
    acrisliu
        5
    acrisliu  
    OP
       Sep 24, 2015
    @songjiaxin2008 果然可以了,谢谢!能否告知一下这个是什么证书?
    acrisliu
        6
    acrisliu  
    OP
       Sep 24, 2015
    @songjiaxin2008 找到了,是 AlphaSSL Intermediate Certificates 吧? 多谢了。
    songjiaxin2008
        7
    songjiaxin2008  
       Sep 24, 2015   1
    @acrisliu 这个是 AlphaSSL 中级 CA
    最顶级的 GlobalSign Root CA 一般各个系统都已经内置过了 不用贴上去
    About     Help     Advertise     Blog     API     FAQ     Solana     2508 Online   Highest 6679       Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 33ms UTC 07:04 PVG 15:04 LAX 00:04 JFK 03:04
    Do have faith in what you're doing.
    ubao msn snddm index pchome yahoo rakuten mypaper meadowduck bidyahoo youbao zxmzxm asda bnvcg cvbfg dfscv mmhjk xxddc yybgb zznbn ccubao uaitu acv GXCV ET GDG YH FG BCVB FJFH CBRE CBC GDG ET54 WRWR RWER WREW WRWER RWER SDG EW SF DSFSF fbbs ubao fhd dfg ewr dg df ewwr ewwr et ruyut utut dfg fgd gdfgt etg dfgt dfgd ert4 gd fgg wr 235 wer3 we vsdf sdf gdf ert xcv sdf rwer hfd dfg cvb rwf afb dfh jgh bmn lgh rty gfds cxv xcv xcs vdas fdf fgd cv sdf tert sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf sdf shasha9178 shasha9178 shasha9178 shasha9178 shasha9178 liflif2 liflif2 liflif2 liflif2 liflif2 liblib3 liblib3 liblib3 liblib3 liblib3 zhazha444 zhazha444 zhazha444 zhazha444 zhazha444 dende5 dende denden denden2 denden21 fenfen9 fenf619 fen619 fenfe9 fe619 sdf sdf sdf sdf sdf zhazh90 zhazh0 zhaa50 zha90 zh590 zho zhoz zhozh zhozho zhozho2 lislis lls95 lili95 lils5 liss9 sdf0ty987 sdft876 sdft9876 sdf09876 sd0t9876 sdf0ty98 sdf0976 sdf0ty986 sdf0ty96 sdf0t76 sdf0876 df0ty98 sf0t876 sd0ty76 sdy76 sdf76 sdf0t76 sdf0ty9 sdf0ty98 sdf0ty987 sdf0ty98 sdf6676 sdf876 sd876 sd876 sdf6 sdf6 sdf9876 sdf0t sdf06 sdf0ty9776 sdf0ty9776 sdf0ty76 sdf8876 sdf0t sd6 sdf06 s688876 sd688 sdf86