certbot简介

https://certbot.eff.org/docs/intro.html


Introduction

Certbot is part of EFF’s effort to encrypt the entire Internet. Secure communication over the Web relies on HTTPS, which requires the use of a digital certificate that lets browsers verify the identify of web servers (e.g., is that really google.com?). Web servers obtain their certificates from trusted third parties called certificate authorities (CAs). Certbot is an easy-to-use client that fetches a certificate from Let’s Encrypt—an open certificate authority launched by the EFF, Mozilla, and others—and deploys it to a web server.

Anyone who has gone through the trouble of setting up a secure website knows what a hassle getting and maintaining a certificate is. Certbot and Let’s Encrypt can automate away the pain and let you turn on and manage HTTPS with simple commands. Using Certbot and Let’s Encrypt is free, so there’s no need to arrange payment.

How you use Certbot depends on the configuration of your web server. The best way to get started is to use our interactive guide. It generates instructions based on your configuration settings. In most cases, you’ll need root or administrator access to your web server to run Certbot.

If you’re using a hosted service and don’t have direct access to your web server, you might not be able to use Certbot. Check with your hosting provider for documentation about uploading certificates or using certificates issues by Let’s Encrypt.

Certbot is a fully-featured, extensible client for the Let’sEncrypt CA (or any other CA that speaks the ACMEprotocol) that can automate the tasks of obtaining certificates andconfiguring webservers to use them. This client runs on Unix-based operatingsystems.

Until May 2016, Certbot was named simply letsencrypt or letsencrypt-auto,depending on install method. Instructions on the Internet, and some pieces of thesoftware, may still refer to this older name.

Contributing

If you’d like to contribute to this project please read Developer Guide.

Installation

The easiest way to install Certbot is by visiting certbot.eff.org, where you canfind the correct installation instructions for many web server and OS combinations.For more information, see Get Certbot.

How to run the client

In many cases, you can just run certbot-auto or certbot, and theclient will guide you through the process of obtaining and installing certsinteractively.

For full command line help, you can type:

./certbot-auto --help all

You can also tell it exactly what you want it to do from the command line.For instance, if you want to obtain a cert for example.com,www.example.com, and other.example.net, using the Apache plugin to bothobtain and install the certs, you could do this:

./certbot-auto --apache -d example.com -d www.example.com -d other.example.net

(The first time you run the command, it will make an account, and ask for anemail and agreement to the Let’s Encrypt Subscriber Agreement; you canautomate those with --email and --agree-tos)

If you want to use a webserver that doesn’t have full plugin support yet, youcan still use “standalone” or “webroot” plugins to obtain a certificate:

./certbot-auto certonly --standalone --email admin@example.com -d example.com -d www.example.com -d other.example.net

Understanding the client in more depth

To understand what the client is doing in detail, it’s important tounderstand the way it uses plugins. Please see the explanation ofplugins inthe User Guide.

System Requirements

The Let’s Encrypt Client presently only runs on Unix-ish OSes that includePython 2.6 or 2.7; Python 3.x support will hopefully be added in the future. Theclient requires root access in order to write to /etc/letsencrypt,/var/log/letsencrypt, /var/lib/letsencrypt; to bind to ports 80 and 443(if you use the standalone plugin) and to read and modify webserverconfigurations (if you use the apache or nginx plugins). If none ofthese apply to you, it is theoretically possible to run without root privileges,but for most users who want to avoid running an ACME client as root, eitherletsencrypt-nosudo orsimp_le are more appropriate choices.

The Apache plugin currently requires a Debian-based OS with augeas version1.0; this includes Ubuntu 12.04+ and Debian 7+.


  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值