双容器配置求助:LetsEncrypt 已故障数日

最近在调查 Let’s Encrypt 证书复用时,我在 cert_exists() 中遇到了一个相关问题。

在我的情况下,证书文件以及 RSA/ECDSA 目录都存在,但当前的检查仍然返回 false,因为 openssl x509 -in ca.cer 仅保留颁发者捆绑包中的第一个证书。

使用以下命令:

openssl verify -untrusted ca.cer fullchain.cer

解决了验证问题。我还使用实际的 RSA 和 ECDSA 证书进行了测试,并完成了重建,成功复用了两个现有证书,而没有触发强制重新签发。

这可能与本主题中描述的缺少 _ecc 目录的根本原因不同,但它影响了相同的 cert_exists() 路径,因此我在此链接该问题,以供大家参考,如果你们遇到类似的症状可能会有用。

报告:Let's Encrypt cert_exists() truncates the CA chain, causing forced reissuance and rate-limit failures
PR:FIX: preserve the Let's Encrypt issuer chain in cert_exists - Pull Request #1136 - discourse/discourse_docker - GitHub