← 返回
效率工具 中文

SSL

Set up HTTPS, manage TLS certificates, and debug secure connection issues.
配置HTTPS,管理TLS证书,并调试安全连接问题。
ivangdavila
效率工具 clawhub v1.0.2 1 版本 99935.4 Key: 无需
★ 2
Stars
📥 1,508
下载
💾 30
安装
1
版本
#latest

概述

Triggers

Activate on: SSL certificate, HTTPS setup, Let's Encrypt, certbot, TLS configuration, certificate expired, mixed content, certificate chain error.

Core Tasks

TaskTool/Method
-------------------
Get free certcertbot, acme.sh, Caddy (auto)
Check cert statusopenssl s_client -connect host:443
View cert detailsopenssl x509 -in cert.pem -text -noout
Test configssllabs.com/ssltest or testssl.sh
Convert formatsSee formats.md

Quick Cert Commands

# Let's Encrypt with certbot (most common)
certbot certonly --nginx -d example.com -d www.example.com

# Check expiry
echo | openssl s_client -connect example.com:443 2>/dev/null | openssl x509 -noout -dates

# Verify chain is complete
openssl s_client -connect example.com:443 -servername example.com
# Look for "Verify return code: 0 (ok)"

Common Errors

ErrorCauseFix
-------------------
certificate has expiredCert past valid dateRenew with certbot renew
unable to verify / self signedMissing intermediate certInclude full chain in config
hostname mismatchCert doesn't cover this domainGet cert for correct domain or add SAN
mixed contentHTTP resources on HTTPS pageChange all URLs to HTTPS or use //
ERR_CERT_AUTHORITY_INVALIDSelf-signed or untrusted CAUse Let's Encrypt or install CA cert

For detailed troubleshooting steps, see troubleshooting.md.

Server Config Patterns

Nginx:

server {
    listen 443 ssl http2;
    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
}

Apache:

SSLEngine on
SSLCertificateFile /path/to/cert.pem
SSLCertificateKeyFile /path/to/privkey.pem
SSLCertificateChainFile /path/to/chain.pem

For Node.js, Caddy, Traefik, and HAProxy, see servers.md.

Renewal

Let's Encrypt certs expire in 90 days. Always automate:

# Test renewal
certbot renew --dry-run

# Cron (certbot usually adds this)
0 0 * * * certbot renew --quiet

Certificate Types

TypeUse case
----------------
Single domainOne site (example.com)
Wildcard (*.domain.com)All subdomains
Multi-domain (SAN)Multiple different domains on one cert
Self-signedLocal dev only — browsers will warn

What This Doesn't Cover

  • Application auth (JWT, OAuth) → see oauth skill
  • SSH keys → see linux or server skills
  • VPN/tunnel setup → see networking skills
  • Firewall configuration → see server/infrastructure skills

版本历史

共 1 个版本

  • v1.0.2 当前
    2026-03-29 01:58 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

productivity

Baidu web search

ide-rea
使用百度AI搜索引擎(BDSE)进行网络搜索。适用于获取实时信息、文档资料或研究课题。
★ 239 📥 105,848
productivity

Weather

steipete
获取当前天气和预报(无需API密钥)
★ 446 📥 226,503
productivity

Word / DOCX

ivangdavila
创建、检查和编辑 Microsoft Word 文档及 DOCX 文件,支持样式、编号、修订记录、表格、分节符及兼容性检查等功能。
★ 440 📥 148,314