使用Let's Encrypt证书的Gitlab:将您的ACME客户端升级到ACMEv2

spa*_*pam 6 ssl-certificate gitlab

我在Ubuntu 14.04上安装了Gitlab。无法续订我们的加密证书。我已将Ubuntu升级到16.04,然后进行apt-get update和&& apt-get upgrade升级,但似乎它没有将ACME客户端升级到v2,这使我可以更新证书。如何更新证书?

gitlab-cli renew-le-certs 
Run Code Online (Sandbox Code Playgroud)

结果是:

letsencrypt_certificate[elenx.net] (letsencrypt::http_authorization
line 3) had an error: Acme::Client::Error::Unauthorized:
acme_certificate[staging]
(/opt/gitlab/embedded/cookbooks/cache/cookbooks/letsencrypt/resources/certificate.rb
line 20) had an error: Acme::Client::Error::Unauthorized: Account
creation on ACMEv1 is disabled. Please upgrade your ACME client to a
version that supports ACMEv2 / RFC 8555. See
https://community.letsencrypt.org/t/end-of-life-plan-for-acmev1/88430
for details.
Run Code Online (Sandbox Code Playgroud)

Rya*_*der 11

https://gitlab.com/gitlab-org/omnibus-gitlab/issues/4614#note_232009029

有趣的困境。我们已经在 GitLab 12.1 中的 !3420(合并)中升级了 ACME 客户端,但是在成功重新配置之前,您无法升级。

所以需要升级到gitlab >= 12.1

  1. 关闭letsencrypt: nano /etc/gitlab/gitlab.rb 向下几页查找:letsencrypt['enable'] = true并将其设置为false然后保存

  2. 升级到您的主要版本的最新版本 apt-get upgrade gitlab-ee=11.11.8

  3. 跑 gitlab-ctl reconfigure

  4. 升级到 Gitlab 12 apt-get upgrade gitlab-ee

  5. 跑 gitlab-ctl reconfigure

  6. 重启 sudo reboot

  7. 返回letsencrypt['enable'] = true在/etc/gitlab/gitlab.rb

  8. 跑 gitlab-ctl reconfigure

  9. 跑 gitlab-ctl renew-le-certs

  • 您可能必须转到 11.11.8 之前的中间步骤版本。例如:我必须先升级到 11.4.7-ee.0,然后再升级到 11.11.8。您可以使用以下命令列出可用版本: sudo apt list -a --upgradable (3认同)