申请通配符
可以不需要 ip 服务器,只用证明 域名是你的。
https://github.com/acmesh-official/acme.sh/wiki/dnsapi#dns_cf 这些提供商可以自动添加记录,不在这些运营商的需要手动添加 txt 记录
当前使用通用的方式,手动添加记录。可以添加多个, -d *.grafana.eu.org -d grafana.eu.org1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66[office-k8s-01][email protected]:~# acme.sh --issue --dns -d *.grafana.eu.org
[Wed Jul 2 17:03:47 CST 2025] It seems that you are using dns manual mode. Read this link first: https://github.com/acmesh-official/acme.sh/wiki/dns-manual-mode
[office-k8s-01][email protected]:~# acme.sh --issue --dns -d *.grafana.eu.org --yes-I-know-dns-manual-mode-enough-go-ahead-please
[Wed Jul 2 17:04:59 CST 2025] Using CA: https://acme.zerossl.com/v2/DV90
[Wed Jul 2 17:04:59 CST 2025] Creating domain key
[Wed Jul 2 17:04:59 CST 2025] The domain key is here: /root/.acme.sh/*.grafana.eu.org_ecc/*.grafana.eu.org.key
[Wed Jul 2 17:04:59 CST 2025] Single domain='*.grafana.eu.org'
[Wed Jul 2 17:07:15 CST 2025] Getting webroot for domain='*.grafana.eu.org'
[Wed Jul 2 17:07:15 CST 2025] Add the following TXT record:
[Wed Jul 2 17:07:15 CST 2025] Domain: '_acme-challenge.grafana.eu.org'
[Wed Jul 2 17:07:15 CST 2025] TXT value: 'u4aSBaAlbetG1Wkr_PNffvGgxj6vHZujFNyLyFeVMC0'
[Wed Jul 2 17:07:15 CST 2025] Please make sure to prepend '_acme-challenge.' to your domain
[Wed Jul 2 17:07:15 CST 2025] so that the resulting subdomain is: _acme-challenge.grafana.eu.org
[Wed Jul 2 17:07:15 CST 2025] Please add the TXT records to the domains, and re-run with --renew.
[Wed Jul 2 17:07:15 CST 2025] Please add '--debug' or '--log' to see more information.
[Wed Jul 2 17:07:15 CST 2025] See: https://github.com/acmesh-official/acme.sh/wiki/How-to-debug-acme.sh
## 手动添加 _acme-challenge.grafana.eu.org TXT u4aSBaAlbetG1Wkr_PNffvGgxj6vHZujFNyLyFeVMC0
[office-k8s-01][email protected]:~# acme.sh --issue --dns -d *.grafana.eu.org --yes-I-know-dns-manual-mode-enough-go-ahead-please --renew
[Wed Jul 2 17:09:12 CST 2025] The domain '*.grafana.eu.org' seems to already have an ECC cert, let's use it.
[Wed Jul 2 17:09:12 CST 2025] Renewing: '*.grafana.eu.org'
[Wed Jul 2 17:09:12 CST 2025] Renewing using Le_API=https://acme.zerossl.com/v2/DV90
[Wed Jul 2 17:09:15 CST 2025] Using CA: https://acme.zerossl.com/v2/DV90
[Wed Jul 2 17:09:15 CST 2025] Single domain='*.grafana.eu.org'
[Wed Jul 2 17:09:15 CST 2025] Verifying: *.grafana.eu.org
[Wed Jul 2 17:09:50 CST 2025] Processing. The CA is processing your order, please wait. (1/30)
[Wed Jul 2 17:10:21 CST 2025] Success
[Wed Jul 2 17:10:21 CST 2025] Verification finished, beginning signing.
[Wed Jul 2 17:10:21 CST 2025] Let's finalize the order.
[Wed Jul 2 17:10:21 CST 2025] Le_OrderFinalize='https://acme.zerossl.com/v2/DV90/order/JoDGS0BAiPIBTdNwRu5oNA/finalize'
[Wed Jul 2 17:10:55 CST 2025] Order status is 'processing', let's sleep and retry.
[Wed Jul 2 17:10:55 CST 2025] Sleeping for 15 seconds then retrying
[Wed Jul 2 17:11:11 CST 2025] Polling order status: https://acme.zerossl.com/v2/DV90/order/JoDGS0BAiPIBTdNwRu5oNA
[Wed Jul 2 17:11:14 CST 2025] Downloading cert.
[Wed Jul 2 17:11:14 CST 2025] Le_LinkCert='https://acme.zerossl.com/v2/DV90/cert/XUI_bZ_CfvW42--xLMj_ZA'
[Wed Jul 2 17:11:15 CST 2025] Cert success.
-----BEGIN CERTIFICATE-----
MIIECTCCA4+gAwIBAgIRAIfRQ6hPRFKW6tFOW1q96hwwCgYIKoZIzj0EAwMwSzEL
MAkGA1UEBhMCQVQxEDAOBgNVBAoTB1plcm9TU0wxKjAoBgNVBAMTIVplcm9TU0wg
RUNDIERvbWFpbiBTZWN1cmUgU2l0ZSBDQTAeFw0yNTA3MDIwMDAwMDBaFw0yNTA5
MzAyMzU5NTlaMB4xHDAaBgNVBAMMEyouZG9rcGxveS5ob255LmxvdmUwWTATBgcq
hkjOPQIBBggqhkjOPQMBBwNCAAT0F8Z5AEOIWX67yb/l3qGj6ngiu+RUg8dzeke/
Zq4+367XS0bvDf4hvFkCDj+hwkxjaf6vmOeeQVU4MbZJmhq2o4ICfzCCAnswHwYD
VR0jBBgwFoAUD2vmS845R672fpAeefAwkZLIX6MwHQYDVR0OBBYEFEcm3Rj4kxRu
Lj5cfEZXtoqSoImCMA4GA1UdDwEB/wQEAwIHgDAMBgNVHRMBAf8EAjAAMB0GA1Ud
JQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjBJBgNVHSAEQjBAMDQGCysGAQQBsjEB
AgJOMCUwIwYIKwYBBQUHAgEWF2h0dHBzOi8vc2VjdGlnby5jb20vQ1BTMAgGBmeB
DAECATCBiAYIKwYBBQUHAQEEfDB6MEsGCCsGAQUFBzAChj9odHRwOi8vemVyb3Nz
bC5jcnQuc2VjdGlnby5jb20vWmVyb1NTTEVDQ0RvbWFpblNlY3VyZVNpdGVDQS5j
cnQwKwYIKwYBBQUHMAGGH2h0dHA6Ly96ZXJvc3NsLm9jc3Auc2VjdGlnby5jb20w
ggEEBgorBgEEAdZ5AgQCBIH1BIHyAPAAdgDd3Mo0ldfhFgXnlTL6x5/4PRxQ39sA
OhQSdgosrLvIKgAAAZfKZ12zAAAEAwBHMEUCIQDdy145LFaIJPu7+GAw5CDH17Qj
0LspxH2Is7nzJ23/EgIga0ICn4NvC+1zn+4CuYUwhgjLoSH4m38VpJeY+So4HJ0A
dgAN4fIwK9MNwUBiEgnqVS78R3R8sdfpMO8OQh60fk6qNAAAAZfKZ12JAAAEAwBH
MEUCIQC6cx5ub4tepIZtpCoZ8srAwdviK9hS5bIRHABf3tx7swIgSZFJx/+SXMuR
24mtUIjGNAw04viIJsjyC4Utr0hIq5UwHgYDVR0RBBcwFYITKi5kb2twbG95Lmhv
bnkubG92ZTAKBggqhkjOPQQDAwNoADBlAjBeqUcSFagFKtxmKnhiw1zJMUIh5RIj
t6CftSj9bvcxv8W8p8posPEsVv++PnZVEhMCMQCfecDMrxKZPgBajDc8TKVgjGNR
1K5f6KEC5udPC264J4cm0JXROAXsxqPIbj9r/Y0=
-----END CERTIFICATE-----
[Wed Jul 2 17:11:15 CST 2025] Your cert is in: /root/.acme.sh/*.grafana.eu.org_ecc/*.grafana.eu.org.cer
[Wed Jul 2 17:11:15 CST 2025] Your cert key is in: /root/.acme.sh/*.grafana.eu.org_ecc/*.grafana.eu.org.key
[Wed Jul 2 17:11:15 CST 2025] The intermediate CA cert is in: /root/.acme.sh/*.grafana.eu.org_ecc/ca.cer
[Wed Jul 2 17:11:15 CST 2025] And the full-chain cert is in: /root/.acme.sh/*.grafana.eu.org_ecc/fullchain.cer
证书详情1
2
3
41. 证书内容(单证书) /root/.acme.sh/*.grafana.eu.org_ecc/*.grafana.eu.org.cer 仅包含你域名的证书(无 CA)
2. 证书私钥 /root/.acme.sh/*.grafana.eu.org_ecc/*.grafana.eu.org.key 证书对应的私钥,部署时用于服务器握手
3. 中间证书(CA) /root/.acme.sh/*.grafana.eu.org_ecc/ca.cer Let’s Encrypt 的中间证书
4. 完整链证书(fullchai) /root/.acme.sh/*.grafana.eu.org_ecc/fullchain.cer
一般使用 2 和 4
更新
1 | [office-k8s-01][email protected]:~# /root/.acme.sh/acme.sh --renew -d "*.grafana.eu.org" --force --home "/root/.acme.sh" --yes-I-know-dns-manual-mode-enough-go-ahead-please |
更新 txt 记录
1 | [office-k8s-01][email protected]:~# nslookup -q=TXT _acme-challenge.grafana.eu.org |
然后重新执行
1 | [office-k8s-01][email protected]:~# /root/.acme.sh/acme.sh --renew -d "*.grafana.eu.org" --force --home "/root/.acme.sh" --yes-I-know-dns-manual-mode-enough-go-ahead-please |
和 nginx 搭配使用
1 | acme.sh --install-cert -d test.com --ecc \ |
nginx 的配置
1 | server { |