VM
certbot certonly --rsa-key-size 4096 --server https://acme-v02.api.letsencrypt.org/directory --webroot -w /tmp/ -d zigzag.io
Size: a a a
VM
certbot certonly --rsa-key-size 4096 --server https://acme-v02.api.letsencrypt.org/directory --webroot -w /tmp/ -d zigzag.io
VM
location /.well-known/acme-challenge {
auth_basic off;
root /tmp/;
}
VM
certbot certonly --cert-name deathstar.name --rsa-key-size 4096 --dns-rfc2136 --dns-rfc2136-credentials /usr/local/etc/letsencrypt/rfc2136.ini --server https://acme-v02.api.letsencrypt.org/directory --domain 'deathstar.name' --domain '*.deathstar.name’
#certbot_bindVM
/usr/local/etc/letsencrypt/rfc2136.ini
тут прописан ключдля управления зоной, и в named.conf разрешен этот ключ, который позволит менять файл зоныVM
certbot certonly --cert-name wpmix.net --dns-cloudflare --dns-cloudflare-credentials /root/cloudflareapi.cfg --server https://acme-v02.api.letsencrypt.org/directory -d "wpmix.net" -d *.wpmix.net
/root/cloudflareapi.cfg
dns_cloudflare_email = deathstar@deathstar.name
dns_cloudflare_api_key =
API_KEYVM
certbot certonly --rsa-key-size 4096 --server https://acme-v02.api.letsencrypt.org/directory --dns-digitalocean --dns-digitalocean-credentials /root/digitalocean.ini -d premiagi.ru -d *.premiagi.ru
/root/digitalocean.ini
тут просто API_TOKKEN прописанA
certbot certonly --cert-name deathstar.name --rsa-key-size 4096 --dns-rfc2136 --dns-rfc2136-credentials /usr/local/etc/letsencrypt/rfc2136.ini --server https://acme-v02.api.letsencrypt.org/directory --domain 'deathstar.name' --domain '*.deathstar.name’
#certbot_bindVM
root@deathstar:~ # cat /usr/local/etc/letsencrypt/rfc2136.ini
dns_rfc2136_server = 127.0.0.1
dns_rfc2136_name = certbot.
dns_rfc2136_secret =
KEY
dns_rfc2136_algorithm = HMAC-SHA512
A
VM
zone "deathstar.name" {
type master;
file "/usr/local/etc/namedb/master/deathstar.name";
allow-update { key deathstar.name; key certbot.; };
allow-transfer { ns2;};
allow-query { any; };
notify yes;
};
VM
VM
VM
root@deathstar:~ # pkg info | grep certbot
py37-certbot-1.1.0,1 Let's Encrypt client
py37-certbot-dns-cloudflare-1.1.0 Cloudflare DNS plugin for Certbot
py37-certbot-dns-digitalocean-1.1.0 DigitalOcean DNS Authenticator plugin for Certbot
py37-certbot-dns-rfc2136-1.1.0 RFC 2136 DNS Authenticator plugin for Certbot
VM
VM
VM
A
VM
AS