


查看: 687|回复: 2

R6300V2 380版本如何更新Let’s Encrypt根证书?

本帖最后由 king1027 于 2022-11-22 17:38 编辑


WARN[0413] [TCP] dial ⚓️其他流量 (match Match/) --> assets.msn.com:443 error: 123123.ga:443 connect error: x509: certificate has expired or is not yet valid: current time 2022-11-21T17:20:27Z is after 2021-09-30T14:01:15Z

网上搜索了一番,发现是Let’s Encrypt根证书过期问题。

请问坛友们如何更新Let’s Encrypt根证书?我在R6300V2登录SSH找不到对应的证书,update-ca-certificates命令也无效。

直接SSH运行curl测试,网站用其他证书正常,用let's encrypt证书不正常
admin@R6300V2-A9C5:/tmp/home/root# curl https://qq.com
<head><title>302 Found</title></head>
<center><h1>302 Found</h1></center>
admin@R6300V2-A9C5:/tmp/home/root# curl https://163.com
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
admin@R6300V2-A9C5:/tmp/home/root# curl https://123123.ga
curl: (60) SSL certificate problem: certificate has expired
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.


使用道具 举报

 楼主| | 显示全部楼层
atshot 发表于 2022-11-22 09:34

我觉得是的。直接SSH运行curl测试,网站用其他证书正常,用let's encrypt证书不正常
admin@R6300V2-A9C5:/tmp/home/root# curl https://qq.com
<head><title>302 Found</title></head>
<center><h1>302 Found</h1></center>
admin@R6300V2-A9C5:/tmp/home/root# curl https://163.com
<head><title>301 Moved Permanently</title></head>
<body bgcolor="white">
<center><h1>301 Moved Permanently</h1></center>
admin@R6300V2-A9C5:/tmp/home/root# curl https://123123.ga
curl: (60) SSL certificate problem: certificate has expired
More details here: http://curl.haxx.se/docs/sslcerts.html

curl performs SSL certificate verification by default, using a "bundle"
of Certificate Authority (CA) public keys (CA certs). If the default
bundle file isn't adequate, you can specify an alternate file
using the --cacert option.
If this HTTPS server uses a certificate signed by a CA represented in
the bundle, the certificate verification probably failed due to a
problem with the certificate (it might be expired, or the name might
not match the domain name in the URL).
If you'd like to turn off curl's verification of the certificate, use
the -k (or --insecure) option.


使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册



欢迎大家光临恩山无线论坛上一条 /1 下一条

有疑问请添加管理员QQ86788181|手机版|小黑屋|Archiver|恩山无线论坛(常州市恩山计算机开发有限公司版权所有) ( 苏ICP备05084872号 )

GMT+8, 2024-5-10 13:15

Powered by Discuz! X3.5

© 2001-2024 Discuz! Team.

| 江苏省互联网有害信息举报中心 举报信箱:js12377 | @jischina.com.cn 举报电话:025-88802724 本站不良内容举报信箱:68610888@qq.com 举报电话:0519-86695797

快速回复 返回顶部 返回列表