我有一台专门的证书签发服务器 因为域名太多了(2 万多个)
其中一个举例:
acme.sh --issue --server google --keylength ec-384 --dns dns_ali88 --fullchain-file /etc/ssl/xy-ali-all/wildcard.ecc.crt --key-file /etc/ssl/xy-ali-all/wildcard.ecc.key --reloadcmd /etc/ssl/post-cert/
xy-ali-all.sh -d "****" -d "****" --days 85
xy-ali-all.sh:
#!/bin/bash
service nginx reload
/usr/bin/python /etc/ssl/post-cert/
aliyun_upload_ssl_cert.py \
"xy-group3-auto" \
"xy-ali-all" \
"wildcard.ecc.crt" "wildcard.ecc.key"
/usr/bin/python /etc/ssl/post-cert/
ct-elb-upload.py xygroup3-ecc-auto xy-ali-all wildcard.ecc.crt wildcard.ecc.key >> /etc/ssl/post-cert/ctelb-logs.txt
scp -r /etc/ssl/xy-ali-all/* C141WEB:/etc/ssl/xy-ali-all/
scp -r /etc/ssl/xy-ali-all/* XY3M:/etc/ssl/xy-ali-all/
scp -r /etc/ssl/xy-ali-all/* XY5M:/etc/ssl/xy-ali-all/
ssh C141WEB 'service nginx reload'
ssh XY3M 'service nginx reload'
ssh XY5M 'service nginx reload'