
certbot ‌‌申请泛域名证书

1. 执行 certbot certonly --cert-name xwenliang.cn -d xwenliang.cn -d *.xwenliang.cn


Client with the currently selected authenticator does not support any combination of challenges that will satisfy the CA. You may need to use an authenticator plugin that can do challenges over DNS.

原来泛域名证书需要指定 --preferred-challenges dns

2. 执行 certbot certonly --manual --preferred-challenges dns --cert-name xwenliang.cn -d xwenliang.cn -d *.xwenliang.cn

按照提示去域名服务商后台配置 TXT 类型的记录后,等待几分钟再进行下一步


this certificate will not be renewed automatically

尝试执行: certbot renew --force-renewal 报错:

Failed to renew certificate xwenliang.cn with error: The manual plugin is not working; there may be problems with your existing configuration. The error was: PluginError('An authentication script must be provided with --manual-auth-hook when using the manual plugin non-interactively.')

3. 执行 certbot certonly --cert-name xwenliang.cn -d xwenliang.cn -d *.xwenliang.cn


4. 执行 certbot renew --force-renewal


  • 邢文亮3天前

    坑:泛域名证书更新需要 dns challenge 验证,比较麻烦
