在 Linux 上使用 OpenSSL 更新证书,通常分为 更新自签名证书 或 更新 CA 签发的证书 两种场景。下面按常见情况给你说明。
openssl req -x509 -newkey rsa:2048 -nodes \
-keyout /path/to/your.key \
-out /path/to/your.crt \
-days 365 \
-subj "/CN=your.domain.com"
说明:
-days 365:证书有效期-nodes:不加密私钥openssl x509 -req -in your.csr \
-signkey your.key \
-out your.crt \
-days 365
openssl req -new -key your.key -out your.csr
如果私钥也要换:
openssl genrsa -out your.key 2048
openssl req -new -key your.key -out your.csr
your.csrcertbotcertbot renew
或强制更新:
certbot renew --force-renewal
# Nginx
systemctl restart nginx
# Apache
systemctl restart httpd
# Tomcat(需重启)
systemctl restart tomcat
openssl x509 -in your.crt -noout -dates
查看是否生效:
echo | openssl s_client -connect your.domain.com:443 | openssl x509 -noout -dates
如果你能告诉我:
我可以给你更精确的命令。