我正在使用 centos 8,并安装了 let's Encrypt 证书,该证书不适用于基本(根)域,但适用于子域。我已检查根域和子域可用的证书,发现以下证书:
Certificate Name: teachersbook.pk
Serial Number: XXXXXXXXXXXXXX
Key Type: XXXXXXXX
Domains: teachersbook.pk www.teachersbook.pk
Expiry Date: 2021-12-13 06:54:33+00:00 (VALID: 89 days)
Certificate Path: /etc/letsencrypt/live/teachersbook.pk/fullchain.pem
Private Key Path: /etc/letsencrypt/live/teachersbook.pk/privkey.pem
我的 VHost 配置是
<VirtualHost *:80>
ServerName teachersbook.pk
ServerAlias www.teachersbook.pk
ServerAdmin [email protected]
DocumentRoot /var/www/teachersbook.pk/
ErrorLog /var/log/httpd/teachersbook.pk-error.log
CustomLog /var/log/httpd/teachersbook.pk-access.log combined
RewriteEngine on
RewriteCond %{SERVER_NAME} =teachersbook.pk [OR]
RewriteCond %{SERVER_NAME} =www.teachersbook.pk
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>
我的 Let's Encrypt SSL 文件配置是
<IfModule mod_ssl.c>
<VirtualHost *:443>
ServerName teachersbook.pk
ServerAlias www.teachersbook.pk
ServerAdmin [email protected]
DocumentRoot /var/www/teachersbook.pk/
ErrorLog /var/log/httpd/teachersbook.pk-error.log
CustomLog /var/log/httpd/teachersbook.pk-access.log combined
Include /etc/letsencrypt/options-ssl-apache.conf
SSLCertificateFile /etc/letsencrypt/live/teachersbook.pk/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/teachersbook.pk/privkey.pem
</VirtualHost>
</IfModule>