Hlanganisa isatifikethi se-SSL kwi-DomainFactory kwi-IIS

Ngamaxesha e -Encrypt , iiwebhusayithi ezifihliweyo ngoku zikumgangatho. Kodwa ikhadi lasendle okanye izatifikethi ezandisiweyo ezinokuqinisekiswa komnini ngokuthembekileyo nazo ziyimfuneko rhoqo. Umboneleli weDomainFactory unikezela ngezatifikethi ze-SSL ezingabizi kakhulu ezinokusetyenziswa nangaphandle. Ukuseta kwi- IIS yangoku kuyaphumelela ngaphandle kwe- CSR ngoncedo lwe- OpenSSL . Koku kulandelayo ndiza kubonisa ngokufutshane ukuba ngawaphi amanyathelo afunekayo koku.


Kuqala ukhetha idilesi oyifunayo njengegama ledomeyini (ngokufaka "www" ukuze kamva https://tld.com kunye https://www.tld.com zibethelwe):

Isatifikethi se-SSL IIS

Emva kokukhetha isatifikethi osifunayo kunye nexesha lokusebenza, iDomainFactory inokuvelisa i-CSR yayo:

Isatifikethi se-SSL IIS

Inketho yesibini (layisha i-CSR yakho) ayimfuneko kwaye inzima (ngokungagqibekanga, i-IIS ayinikezeli ukhetho lokuvelisa izicelo ezifihliweyo ze-SHA256 ezifunwa yi-DomainFactory). Emva komyalelo ophumeleleyo, ukhuphela isatifikethi se-SSL, isitshixo sangasese kunye nesiqendu esiphakathi se-CA:

Isatifikethi se-SSL IIS

Ngoku udibanisa isitshixo kunye nesatifikethi kwifayile ye-pfx ngoncedo lwe-OpenSSL (enika iphasiwedi ekhuselekileyo):

openssl pkcs12 -export -out www.tld.com.pfx -inkey www.tld.com.key -in www.tld.com.crt

Okokugqibela, isatifikethi esiphakathi siyalayishwa kwiseva yeWindows:

Isatifikethi se-SSL IIS

Oku kulandelwa kukungeniswa kwefayile ye-pfx eyenziwe kuMlawuli we-IIS (kwindawo yeSatifikethi seServer) ngokungenisa igama eligqithisiweyo elalabelwe oko:

Isatifikethi se-SSL IIS

Okokugqibela, uhlengahlengisa izibophelelo (ungeno olunye kunye nongeno olunye ngaphandle kwe-www):

Isatifikethi se-SSL IIS

Ukuba iserver iya kufikeleleka ngaphandle, uvula izibuko 443 kwi-router / firewall.

Emva