{"id":2880,"date":"2020-11-23T14:36:49","date_gmt":"2020-11-23T07:36:49","guid":{"rendered":"https:\/\/halink.vn\/?p=2880"},"modified":"2020-11-23T14:37:24","modified_gmt":"2020-11-23T07:37:24","slug":"lets-encrypt-la-gi","status":"publish","type":"post","link":"https:\/\/halink.vn\/lets-encrypt-la-gi\/","title":{"rendered":"Let’s Encrypt l\u00e0 g\u00ec?"},"content":{"rendered":"
Let’s Encrypt l\u00e0 c\u01a1 quan c\u1ea5p ch\u1ee9ng ch\u1ec9 SSL mi\u1ec5n ph\u00ed \u0111\u01b0\u1ee3c ph\u00e1t tri\u1ec3n b\u1edfi nh\u00f3m nghi\u00ean c\u1ee9u b\u1ea3o m\u1eadt Internet (ISRG). Let\u2019s Encrypt cung c\u1ea5p ch\u1ee9ng nh\u1eadn (CA) m\u1edf, mi\u1ec5n ph\u00ed v\u00e0 t\u1ef1 \u0111\u1ed9ng, ho\u1ea1t \u0111\u1ed9ng v\u00ec l\u1ee3i \u00edch c\u1ed9ng \u0111\u1ed3ng.<\/p>\n
C\u00e1c ch\u1ee9ng ch\u1ec9 SSL<\/strong><\/a> n\u00e0y c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c s\u1eed d\u1ee5ng \u0111\u1ec3 m\u00e3 h\u00f3a giao ti\u1ebfp gi\u1eefa m\u00e1y ch\u1ee7 web v\u00e0 ng\u01b0\u1eddi d\u00f9ng c\u1ee7a b\u1ea1n. C\u00f3 h\u00e0ng t\u00e1 \u1ee9ng d\u1ee5ng kh\u00e1ch c\u00f3 s\u1eb5n, \u0111\u01b0\u1ee3c vi\u1ebft b\u1eb1ng nhi\u1ec1u ng\u00f4n ng\u1eef l\u1eadp tr\u00ecnh kh\u00e1c nhau v\u00e0 nhi\u1ec1u t\u00edch h\u1ee3p v\u1edbi c\u00e1c c\u00f4ng c\u1ee5, d\u1ecbch v\u1ee5 v\u00e0 m\u00e1y ch\u1ee7 qu\u1ea3n tr\u1ecb ph\u1ed5 bi\u1ebfn.<\/p>\n Let’s Encrypt cung c\u1ea5p hai lo\u1ea1i ch\u1ee9ng ch\u1ec9.\u00a0SSL t\u00ean mi\u1ec1n \u0111\u01a1n ti\u00eau chu\u1ea9n v\u00e0 SSL k\u00fd t\u1ef1 \u0111\u1ea1i di\u1ec7n, kh\u00f4ng ch\u1ec9 bao g\u1ed3m m\u1ed9t t\u00ean mi\u1ec1n m\u00e0 c\u00f2n bao g\u1ed3m t\u1ea5t c\u1ea3 c\u00e1c t\u00ean mi\u1ec1n ph\u1ee5 c\u1ee7a n\u00f3.\u00a0C\u1ea3 hai lo\u1ea1i ch\u1ee9ng ch\u1ec9 SSL \u0111\u1ec1u \u0111\u01b0\u1ee3c c\u1ea5p trong th\u1eddi h\u1ea1n 90 ng\u00e0y v\u00e0 c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c c\u00e0i \u0111\u1eb7t tr\u00ean c\u00e1c Hosting Control Panel. Th\u00f4ng th\u01b0\u1eddng ch\u00fang s\u1ebd t\u1ef1 \u0111\u1ed9ng \u0111\u01b0\u1ee3c gia h\u1ea1n sau 90 ng\u00e0y.<\/p>\n C\u00e1c \u0111i\u1ec3m \u0111\u1eb7c bi\u1ec7t ch\u00ednh c\u1ee7a Let\u2019s Encrypt l\u00e0:<\/strong><\/em><\/p>\n T\u1ed5 ch\u1ee9c ph\u00e1t h\u00e0nh ch\u1ee9ng ch\u1ec9 (CA) l\u00e0 c\u00e1c th\u1ef1c th\u1ec3 k\u00fd m\u00e3 h\u00f3a ch\u1ee9ng ch\u1ec9 TLS \/ SSL \u0111\u1ec3 \u0111\u1ea3m b\u1ea3o t\u00ednh x\u00e1c th\u1ef1c c\u1ee7a ch\u00fang.\u00a0C\u00e1c tr\u00ecnh duy\u1ec7t v\u00e0 h\u1ec7 \u0111i\u1ec1u h\u00e0nh c\u00f3 danh s\u00e1ch CA \u0111\u00e1ng tin c\u1eady m\u00e0 ch\u00fang s\u1eed d\u1ee5ng \u0111\u1ec3 x\u00e1c minh ch\u1ee9ng ch\u1ec9 trang web.<\/p>\n Cho \u0111\u1ebfn g\u1ea7n \u0111\u00e2y, h\u1ea7u h\u1ebft c\u00e1c CA l\u00e0 ho\u1ea1t \u0111\u1ed9ng th\u01b0\u01a1ng m\u1ea1i thu ph\u00ed d\u1ecbch v\u1ee5 x\u00e1c minh v\u00e0 k\u00fd k\u1ebft c\u1ee7a h\u1ecd. Let’s Encrypt l\u00e0 \u0111\u01a1n v\u1ecb cung c\u1ea5p quy tr\u00ecnh n\u00e0y mi\u1ec5n ph\u00ed cho ng\u01b0\u1eddi d\u00f9ng b\u1eb1ng c\u00e1ch t\u1ef1 \u0111\u1ed9ng h\u00f3a ho\u00e0n to\u00e0n quy tr\u00ecnh. H\u1ecd d\u1ef1a v\u00e0o c\u00e1c t\u00e0i tr\u1ee3 v\u00e0 quy\u00ean g\u00f3p \u0111\u1ec3 \u0111\u1ea7u t\u01b0 cho c\u01a1 s\u1edf h\u1ea1 t\u1ea7ng c\u1ea7n thi\u1ebft. >> \u0110\u0103ng k\u00fd SSL<\/a><\/em><\/p>\n Giao th\u1ee9c ACME c\u1ee7a Let’s Encrypt x\u00e1c \u0111\u1ecbnh c\u00e1ch kh\u00e1ch h\u00e0ng giao ti\u1ebfp v\u1edbi m\u00e1y ch\u1ee7 c\u1ee7a n\u00f3 \u0111\u1ec3 y\u00eau c\u1ea7u ch\u1ee9ng ch\u1ec9, x\u00e1c minh quy\u1ec1n s\u1edf h\u1eefu mi\u1ec1n v\u00e0 t\u1ea3i xu\u1ed1ng ch\u1ee9ng ch\u1ec9.\u00a0N\u00f3 hi\u1ec7n \u0111ang trong qu\u00e1 tr\u00ecnh tr\u1edf th\u00e0nh m\u1ed9t\u00a0ti\u00eau chu\u1ea9n\u00a0ch\u00ednh th\u1ee9c c\u1ee7a\u00a0IETF\u00a0.<\/p>\n Let’s Encrypt cung c\u1ea5p c\u00e1c ch\u1ee9ng ch\u1ec9 \u0111\u00e3 \u0111\u01b0\u1ee3c x\u00e1c th\u1ef1c mi\u1ec1n, ngh\u0129a l\u00e0 h\u1ecd ph\u1ea3i ki\u1ec3m tra xem y\u00eau c\u1ea7u ch\u1ee9ng ch\u1ec9 c\u00f3 \u0111\u1ebfn t\u1eeb m\u1ed9t ng\u01b0\u1eddi th\u1ef1c s\u1ef1 ki\u1ec3m so\u00e1t mi\u1ec1n hay kh\u00f4ng. H\u1ecd th\u1ef1c hi\u1ec7n \u0111i\u1ec1u n\u00e0y b\u1eb1ng c\u00e1ch g\u1eedi cho kh\u00e1ch h\u00e0ng m\u1ed9t m\u00e3 th\u00f4ng b\u00e1o duy nh\u1ea5t, sau \u0111\u00f3 y\u00eau c\u1ea7u DNS \u0111\u1ec3 truy xu\u1ea5t kh\u00f3a b\u1eaft ngu\u1ed3n t\u1eeb m\u00e3 th\u00f4ng b\u00e1o \u0111\u00f3.<\/p>\n V\u00ed d\u1ee5: v\u1edbi m\u1ed9t ki\u1ec3m tra d\u1ef1a tr\u00ean HTTP, m\u00e1y kh\u00e1ch s\u1ebd t\u00ednh kh\u00f3a t\u1eeb m\u00e3 th\u00f4ng b\u00e1o duy nh\u1ea5t v\u00e0 m\u00e3 th\u00f4ng b\u00e1o t\u00e0i kho\u1ea3n, sau \u0111\u00f3 \u0111\u1eb7t k\u1ebft qu\u1ea3 v\u00e0o m\u1ed9t t\u1ec7p \u0111\u1ec3 m\u00e1y ch\u1ee7 web cung c\u1ea5p. C\u00e1c m\u00e1y ch\u1ee7 Let’s Encrypt sau \u0111\u00f3 truy xu\u1ea5t t\u1ec7p t\u1ea1i. N\u1ebfu kh\u00f3a ch\u00ednh x\u00e1c, m\u00e1y kh\u00e1ch \u0111\u00e3 ch\u1ee9ng minh r\u1eb1ng n\u00f3 c\u00f3 th\u1ec3 ki\u1ec3m so\u00e1t t\u00e0i nguy\u00ean v\u00e0 m\u00e1y ch\u1ee7 s\u1ebd k\u00fd v\u00e0 tr\u1ea3 l\u1ea1i ch\u1ee9ng ch\u1ec9 SSL<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":" Let’s Encrypt l\u00e0 g\u00ec? Let’s Encrypt l\u00e0 c\u01a1 quan c\u1ea5p ch\u1ee9ng ch\u1ec9 SSL mi\u1ec5n ph\u00ed \u0111\u01b0\u1ee3c ph\u00e1t tri\u1ec3n b\u1edfi nh\u00f3m nghi\u00ean c\u1ee9u b\u1ea3o m\u1eadt Internet (ISRG). Let\u2019s Encrypt cung c\u1ea5p ch\u1ee9ng nh\u1eadn (CA) m\u1edf, mi\u1ec5n ph\u00ed v\u00e0 t\u1ef1 \u0111\u1ed9ng, ho\u1ea1t \u0111\u1ed9ng v\u00ec l\u1ee3i \u00edch c\u1ed9ng \u0111\u1ed3ng. C\u00e1c ch\u1ee9ng ch\u1ec9 SSL n\u00e0y c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c s\u1eed … <\/p>\n<\/p>\n
\n
C\u01a1 quan c\u1ea5p ch\u1ee9ng ch\u1ec9 l\u00e0 g\u00ec?<\/h2>\n
C\u00e1ch ho\u1ea1t \u0111\u1ed9ng c\u1ee7a Let’s Encrypt<\/h2>\n