lego를 이용한 let’s encrypt 와일드 카드 인증서 갱신
AWS_ACCESS_KEY_ID=”key” \ AWS_SECRET_ACCESS_KEY=”key” \ AWS_REGION=”eu-west-1″ \ lego –email “my@email” \ –domains “*.welovedoctor.com” \ –domains “welovedoctor.com” \ –dns route53 \ –path “/etc/lego” \ renew 혹은 run \ –renew-hook “nginx -s reload” 나의 경우 lego로 인증서를 처음 갱신했기 때문인지 run 명령어가 필요했다. 처음 알려준 –path 없이 실행했더니 인증서가 ~/.lego/certificates에 저장되었다. –renew-hook을 이용하면 성공적으로 갱신 후 nginx 를…
이전에 사용하던 방법은 라즈베리파이 패키지에서 관리되던 lego 였다.
Lego :: ACME client and library written in Go.
ACME client and ACME library written in Go.
Important lego is an independent, free, and open-source project, if you value it, consider supporting it! ❤️
Features Challenges
DNS-01 HTTP-01 TLS-ALPN-01 DNS-PERSIST-01 ACME servers
Multiple ACME servers support (Let’s Encrypt, ZeroSSL, etc.)
Certificate Management
Obtain, renew, revoke.
Important lego is an independent, free, and open-source project, if you value it, consider supporting it! ❤️
Features Challenges
DNS-01 HTTP-01 TLS-ALPN-01 DNS-PERSIST-01 ACME servers
Multiple ACME servers support (Let’s Encrypt, ZeroSSL, etc.)
Certificate Management
Obtain, renew, revoke.
최근 Lego를 이용해 보기로 했다. 명령어가 바뀌었다.
./lego run --email "byeon.sunju@welovedoctor.com" \
--domains "*.welovedoctor.com" \
--domains "welovedoctor.com" \
--dns route53 \
--path "/home/byun1114/.lego/" \
renew \
--deploy-hook "/home/byun1114/deploy_cert.sh"
첫 줄에 run 을 추가했다. 그리고 마지막 명령어는 이름이 바뀌었다.