VPS侦探论坛
标题:
求助 acme配置问题
[打印本页]
作者:
sushome
时间:
2024-7-17 16:00
标题:
求助 acme配置问题
本帖最后由 sushome 于 2024-7-17 16:03 编辑
这个问题困扰我几年了,最近一直想搞好,每次ssl过期都手动申请然后替换文件太痛苦了,我是在freessl中通过acme专属链接去申请证书的:
当前lnmp版本1.4
acme.sh --issue -d domain.com --dns dns_dp --server https://acme.freessl.cn/v2/DV90/directory/xxx
复制代码
然后就报这个错:
[Wed Jul 17 15:44:00 CST 2024] Error creating new order. Le_OrderFinalize not found. {
"type": "urn:ietf:params:acme:error:malformed",
"detail": "Trace-ID: 2ecba9be28aeb3df2354f5fa1e350679, KeyID header contained an invalid account URL: "https://acme.freessl.cn/acme/acct/1187"",
"status": 400
}
[Wed Jul 17 15:44:00 CST 2024] Please check log file for more details: /root/.acme.sh/acme.sh.log
复制代码
我已经配置了一个80端口和443端口,80端口重定向到443,但是一直这个问题,以下是log:
[Wed Jul 17 15:14:41 CST 2024] LE_WORKING_DIR='/root/.acme.sh'
[Wed Jul 17 15:14:41 CST 2024] Running cmd: issue
[Wed Jul 17 15:14:41 CST 2024] _main_domain='domain.com'
[Wed Jul 17 15:14:41 CST 2024] _alt_domains='no'
[Wed Jul 17 15:14:41 CST 2024] Using config home: /root/.acme.sh
[Wed Jul 17 15:14:41 CST 2024] ACME_DIRECTORY='https://acme.freessl.cn/v2/DV90/directory/xxx'
[Wed Jul 17 15:14:41 CST 2024] _ACME_SERVER_HOST='acme.freessl.cn'
[Wed Jul 17 15:14:41 CST 2024] _ACME_SERVER_PATH='v2/DV90/directory/xxx'
[Wed Jul 17 15:14:41 CST 2024] DOMAIN_PATH='/root/.acme.sh/domain.com_ecc'
[Wed Jul 17 15:14:41 CST 2024] 'dns_dp' does not contain 'dns'
[Wed Jul 17 15:14:41 CST 2024] Le_NextRenewTime
[Wed Jul 17 15:14:41 CST 2024] Using ACME_DIRECTORY: https://acme.freessl.cn/v2/DV90/directory/xxx
[Wed Jul 17 15:14:41 CST 2024] _init API for server: https://acme.freessl.cn/v2/DV90/directory/xxx
[Wed Jul 17 15:14:41 CST 2024] GET
[Wed Jul 17 15:14:41 CST 2024] url='https://acme.freessl.cn/v2/DV90/directory/xxx'
[Wed Jul 17 15:14:41 CST 2024] timeout=
[Wed Jul 17 15:14:41 CST 2024] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g '
[Wed Jul 17 15:14:42 CST 2024] ret='0'
[Wed Jul 17 15:14:42 CST 2024] response='{
字数限制此处省略
}'
[Wed Jul 17 15:14:42 CST 2024] ACME_KEY_CHANGE='https://acme.freessl.cn/v2/DV90/key-change/xxx'
[Wed Jul 17 15:14:42 CST 2024] ACME_NEW_AUTHZ
[Wed Jul 17 15:14:42 CST 2024] ACME_NEW_ORDER='https://acme.freessl.cn/v2/DV90/new-order/xxx'
[Wed Jul 17 15:14:42 CST 2024] ACME_NEW_ACCOUNT='https://acme.freessl.cn/v2/DV90/new-account/xxx'
[Wed Jul 17 15:14:42 CST 2024] ACME_REVOKE_CERT='https://acme.freessl.cn/v2/DV90/revoke-cert/xxx'
[Wed Jul 17 15:14:42 CST 2024] ACME_AGREEMENT='https://secure.trust-provider.com/repository/docs/Legacy/20201020_Certificate_Subscriber_Agreement_v_2_4_click.pdf'
[Wed Jul 17 15:14:42 CST 2024] ACME_NEW_NONCE='https://acme.freessl.cn/v2/DV90/new-nonce/xxx'
[Wed Jul 17 15:14:43 CST 2024] Using CA: https://acme.freessl.cn/v2/DV90/directory/xxx
[Wed Jul 17 15:14:43 CST 2024] _on_before_issue
[Wed Jul 17 15:14:43 CST 2024] _chk_main_domain='domain.com'
[Wed Jul 17 15:14:43 CST 2024] _chk_alt_domains
[Wed Jul 17 15:14:43 CST 2024] 'dns_dp' does not contain 'no'
[Wed Jul 17 15:14:43 CST 2024] Le_LocalAddress
[Wed Jul 17 15:14:43 CST 2024] d='domain.com'
[Wed Jul 17 15:14:43 CST 2024] Checking for domain='domain.com'
[Wed Jul 17 15:14:43 CST 2024] _currentRoot='dns_dp'
[Wed Jul 17 15:14:43 CST 2024] d
[Wed Jul 17 15:14:43 CST 2024] 'dns_dp' does not contain 'apache'
[Wed Jul 17 15:14:43 CST 2024] _saved_account_key_hash='SRiWDVHyGE80gxpaoQEU7R70B1rlhmYJIDfIo9oZK1g='
[Wed Jul 17 15:14:43 CST 2024] _saved_account_key_hash was not changed, skipping account registration.
[Wed Jul 17 15:14:43 CST 2024] Read key length: ec-256
[Wed Jul 17 15:14:43 CST 2024] _createcsr
[Wed Jul 17 15:14:43 CST 2024] domain='domain.com'
[Wed Jul 17 15:14:43 CST 2024] domainlist
[Wed Jul 17 15:14:43 CST 2024] csrkey='/root/.acme.sh/domain.com_ecc/domain.com.key'
[Wed Jul 17 15:14:43 CST 2024] csr='/root/.acme.sh/domain.com_ecc/domain.com.csr'
[Wed Jul 17 15:14:43 CST 2024] csrconf='/root/.acme.sh/domain.com_ecc/domain.com.csr.conf'
[Wed Jul 17 15:14:43 CST 2024] Single domain='domain.com'
[Wed Jul 17 15:14:43 CST 2024] seg='domain'
[Wed Jul 17 15:14:43 CST 2024] _is_idn_d='domain.com'
[Wed Jul 17 15:14:43 CST 2024] _idn_temp
[Wed Jul 17 15:14:43 CST 2024] _is_idn_d='domain.com'
[Wed Jul 17 15:14:43 CST 2024] _idn_temp
[Wed Jul 17 15:14:43 CST 2024] _csr_cn='domain.com'
[Wed Jul 17 15:14:43 CST 2024] seg='domain'
[Wed Jul 17 15:14:43 CST 2024] Getting domain auth token for each domain
[Wed Jul 17 15:14:43 CST 2024] seg='domain'
[Wed Jul 17 15:14:43 CST 2024] _is_idn_d='domain.com'
[Wed Jul 17 15:14:43 CST 2024] _idn_temp
[Wed Jul 17 15:14:43 CST 2024] d
[Wed Jul 17 15:14:43 CST 2024] _identifiers='{"type":"dns","value":"domain.com"}'
[Wed Jul 17 15:14:43 CST 2024] _notBefore
[Wed Jul 17 15:14:43 CST 2024] _notAfter
[Wed Jul 17 15:14:43 CST 2024] STEP 1, Ordering a Certificate
[Wed Jul 17 15:14:43 CST 2024] =======Sending Signed Request=======
[Wed Jul 17 15:14:43 CST 2024] url='https://acme.freessl.cn/v2/DV90/new-order/xxx'
[Wed Jul 17 15:14:43 CST 2024] payload='{"identifiers": [{"type":"dns","value":"domain.com"}]}'
[Wed Jul 17 15:14:43 CST 2024] RSA key
[Wed Jul 17 15:14:43 CST 2024] _URGLY_PRINTF
[Wed Jul 17 15:14:43 CST 2024] xargs
[Wed Jul 17 15:14:43 CST 2024] _URGLY_PRINTF
[Wed Jul 17 15:14:43 CST 2024] xargs
[Wed Jul 17 15:14:43 CST 2024] Get nonce with HEAD. ACME_NEW_NONCE='https://acme.freessl.cn/v2/DV90/new-nonce/xxx'
[Wed Jul 17 15:14:43 CST 2024] HEAD
[Wed Jul 17 15:14:43 CST 2024] _post_url='https://acme.freessl.cn/v2/DV90/new-nonce/xxx'
[Wed Jul 17 15:14:43 CST 2024] body
[Wed Jul 17 15:14:43 CST 2024] _postContentType='application/jose+json'
[Wed Jul 17 15:14:43 CST 2024] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g -I '
[Wed Jul 17 15:14:44 CST 2024] _ret='0'
[Wed Jul 17 15:14:44 CST 2024] _headers='HTTP/1.1 200 OK
Date: Wed, 17 Jul 2024 07:27:01 GMT
Connection: keep-alive
Cache-Control: no-store
Link: <https://acme.freessl.cn/v2/DV90/directory/xxx>;rel="index"
Replay-Nonce: tnjwvoL8wKi-yFZT9s9Crf8JXquWuGq-4vcrIq7a-Io
X-Trace-Id: 000c89ad320e4976f44cfb43895cef0b
Server: nginx
'
[Wed Jul 17 15:14:44 CST 2024] _CACHED_NONCE='tnjwvoL8wKi-yFZT9s9Crf8JXquWuGq-4vcrIq7a-Io'
[Wed Jul 17 15:14:44 CST 2024] nonce='tnjwvoL8wKi-yFZT9s9Crf8JXquWuGq-4vcrIq7a-Io'
[Wed Jul 17 15:14:44 CST 2024] POST
[Wed Jul 17 15:14:44 CST 2024] _post_url='https://acme.freessl.cn/v2/DV90/new-order/xxx'
[Wed Jul 17 15:14:44 CST 2024] body='{"protected": "eyJub25jZSI6ICJ0bmp3dm9MOHdLaS15RlpUOXM5Q3JmOEpYcXVXdUdxLTR2Y3JJcTdhLUlvIiwgInVybCI6ICJodHRwczovL2FjbWUuZnJlZXNzbC5jbi92Mi9EVjkwL25ldy1vcmRlci9iczMydm84cGZ6dWE5d2tzMTRtMiIsICJhbGciOiAiUlMyNTYiLCAia2lkIjogImh0dHBzOi8vYWNtZS5mcmVlc3NsLmNuL2FjbWUvYWNjdC8xMTg3In0", "payload": "eyJpZGVudGlmaWVycyI6IFt7InR5cGUiOiJkbnMiLCJ2YWx1ZSI6InN1c2hvbWUudXMifV19", "signature": "orCWYYfOxtSSRJjwabcxuUoZwqariasJUuF0_S0tlR60tyeLt2iUzmCds9w3J8dAfCFukp7GadOE5PCroSMTg1QZklmVMymVs0QXVBZxzoK4BD81PdOKWgGgKiZRyJST_tGUSMm4T5t6AZvNoWriLKxYtFopvSlZsq5BFzgBQv46h22SueEyudFBr4hpcdL7pZKDFCNZStSNqH9qrLtisJs7MuknUUxMnZWnrSMLqRUv9IFzwojEgSOYr-YCRrb1-Xx8UhXQsUA-RWdH-hSODLYmmwG-1SxQeydFs7-cf-PqVW9VloHQf7PvTUpGUseXytjbvQO0cTigDAq5XOvxqQ"}'
[Wed Jul 17 15:14:44 CST 2024] _postContentType='application/jose+json'
[Wed Jul 17 15:14:44 CST 2024] Http already initialized.
[Wed Jul 17 15:14:44 CST 2024] _CURL='curl --silent --dump-header /root/.acme.sh/http.header -L -g '
[Wed Jul 17 15:14:46 CST 2024] _ret='0'
[Wed Jul 17 15:14:46 CST 2024] responseHeaders='HTTP/1.1 400 Bad Request
Date: Wed, 17 Jul 2024 07:27:03 GMT
Content-Type: application/problem+json
Content-Length: 218
Connection: keep-alive
Cache-Control: no-store
Link: <https://acme.freessl.cn/v2/DV90/directory/xxx>;rel="index"
Replay-Nonce: P5ClDaTWcHsQptuPzxYNgNEs3HE_p1r-g6OGarrxVdE
X-Trace-Id: 33edf47a336eb04e262ec0d0f82be84f
Server: nginx
'
[Wed Jul 17 15:14:46 CST 2024] code='400'
[Wed Jul 17 15:14:46 CST 2024] original='{
"type": "urn:ietf:params:acme:error:malformed",
"detail": "Trace-ID: 33edf47a336eb04e262ec0d0f82be84f, KeyID header contained an invalid account URL: "https://acme.freessl.cn/acme/acct/1187"",
"status": 400
}'
[Wed Jul 17 15:14:46 CST 2024] response='{
"type": "urn:ietf:params:acme:error:malformed",
"detail": "Trace-ID: 33edf47a336eb04e262ec0d0f82be84f, KeyID header contained an invalid account URL: "https://acme.freessl.cn/acme/acct/1187"",
"status": 400
}'
[Wed Jul 17 15:14:46 CST 2024] Le_LinkOrder
[Wed Jul 17 15:14:46 CST 2024] Le_OrderFinalize
[Wed Jul 17 15:14:46 CST 2024] Error creating new order. Le_OrderFinalize not found. {
"type": "urn:ietf:params:acme:error:malformed",
"detail": "Trace-ID: 33edf47a336eb04e262ec0d0f82be84f, KeyID header contained an invalid account URL: "https://acme.freessl.cn/acme/acct/1187"",
"status": 400
}
[Wed Jul 17 15:14:46 CST 2024] pid
[Wed Jul 17 15:14:46 CST 2024] No need to restore nginx config, skipping.
[Wed Jul 17 15:14:46 CST 2024] _clearupdns
[Wed Jul 17 15:14:46 CST 2024] dns_entries
[Wed Jul 17 15:14:46 CST 2024] Skipping dns.
[Wed Jul 17 15:14:46 CST 2024] _on_issue_err
[Wed Jul 17 15:14:46 CST 2024] Please check log file for more details: /root/.acme.sh/acme.sh.log
[Wed Jul 17 15:14:46 CST 2024] _chk_vlist
复制代码
作者:
sushome
时间:
2024-7-17 16:10
一直不知道咋整,一发帖立马就找到原因,已解决:
卸载acme.sh,清理acme.sh缓存信息,重装acme.sh,重新生成证书。
a. 卸载acme.sh
acme.sh –uninstall
b. 清理acme.sh缓存
cd /root/.acme.sh
rm -rf *
c. 重装acme.sh
欢迎光临 VPS侦探论坛 (https://bbs.lnmp.com/)
Powered by Discuz! X3.4