mirror of
https://github.com/acmesh-official/acme.sh.git
synced 2026-01-03 03:09:41 +08:00
Have HAProxy do some minimal validation on the challenge (see end of §8.3 in RFC8555).
@@ -85,7 +85,7 @@ Configure your webserver to respond statelessly to challenges for a given accoun
|
||||
mode http
|
||||
bind :80
|
||||
bind :443 ssl crt /etc/haproxy/certs/
|
||||
http-request return status 200 content-type text/plain lf-string "%[path,field(-1,/)].${ACCOUNT_THUMBPRINT}\n" if { path_beg '/.well-known/acme-challenge/' }
|
||||
http-request return status 200 content-type text/plain lf-string "%[path,field(-1,/)].${ACCOUNT_THUMBPRINT}\n" if { path_reg '^/.well-known/acme-challenge/[-_a-zA-Z0-9]+$' }
|
||||
```
|
||||
3. Ok, you can issue cert now.
|
||||
```
|
||||
|
||||
Reference in New Issue
Block a user