
certbot certonly --preferred-challenges dns --manual -d *.test.cn --server https://acme-v02.api.letsencrypt.org/directory


Saving debug log to /var/log/letsencrypt/letsencrypt.log

Requesting a certificate for *.test.cn

Please deploy a DNS TXT record under the name:


with the following value:


Before continuing, verify the TXT record has been deployed. Depending on the DNS

provider, this may take some time, from a few seconds to multiple minutes. You can

check if it has finished deploying with aid of online tools, such as the Google

Admin Toolbox: https://toolbox.googleapps.com/apps/dig/#TXT/_acme-challenge.test.cn.

Look for one or more bolded line(s) below the line ';ANSWER'. It should show the

value(s) you've just added.

Press Enter to Continue


0 0 * * * /bin/cp /etc/letsencrypt/live/test.cn/* /opt/ssl/test.cn


cp -f /etc/letsencrypt/live/test.cn/* /opt/ssl/test.cn


openssl pkcs12 -export -out test.com.pfx -in fullchain.pem -inkey privkey.pem


certbot certificates

源文档 https://eff-certbot.readthedocs.io/en/stable/using.html#dns-plugins


