diff --git a/ssl_cert_note.md b/ssl_cert_note.md index 2bde825..e388880 100644 --- a/ssl_cert_note.md +++ b/ssl_cert_note.md @@ -1,35 +1,55 @@ # SSL 憑證紀錄 - tpesupporter.tpech.gov.tw -## 憑證資訊 +## 目前使用中的憑證(已於 2026-04-09 部署) | 項目 | 內容 | |---|---| | CN | tpesupporter.tpech.gov.tw | -| 組織 | 政府機關-臺北市立聯合醫院 | -| 簽發者 | HiPKI OV TLS CA - G1(中華電信) | -| 有效期起 | 2025-04-23 | -| 有效期迄 | 2026-04-23 | +| 組織 | 市政府 / 衛生局 / 市立聯合醫院 | +| 簽發者 | 政府憑證管理中心 - G3(GCA) | +| 有效期起 | 2026-04-01 | +| 有效期迄 | 2028-04-01 | | TLS 版本 | TLSv1.3 | | 加密套件 | TLS_AES_256_GCM_SHA384 | | 金鑰 | RSA 2048 bit | -## 待處理事項 +## 憑證鏈 -- [ ] 憑證將於 **2026-04-23** 到期,需提前更新 -- [ ] 憑證鏈不完整:伺服器僅送出終端憑證,缺少中繼 CA(HiPKI OV TLS CA - G1),需在 NPM 補上中繼憑證 +``` +0: tpesupporter.tpech.gov.tw (伺服器憑證) + └─ issued by: 政府憑證管理中心 - G3 +1: 政府憑證管理中心 (中繼憑證) + └─ issued by: Government Root Certification Authority +2: 政府憑證管理中心 - G3 (中繼憑證) + └─ issued by: Government Root Certification Authority - G3 +``` -## 中繼憑證補充方式 +> 注意:GRCA G3 根憑證不在 Linux 預設信任庫中,伺服器端 openssl 驗證會顯示 +> `Verify return code: 20 (unable to get local issuer certificate)`, +> 但瀏覽器端(Chrome/Edge/Firefox)通常可正常驗證。 -1. 下載中繼憑證:https://tls.hinet.net/certs/OVCA-G1.crt -2. 在 NPM 管理後台 (localhost:8181) → SSL Certificates → 編輯對應憑證 -3. 將中繼憑證內容附加到憑證檔案中(或上傳為 intermediate certificate) +## 歷史紀錄 + +| 期間 | 簽發者 | 到期日 | 備註 | +|---|---|---|---| +| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1(中華電信) | 2026-04-23 | 已替換 | +| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3(GCA) | 2028-04-01 | 目前使用中 | ## 檢查指令 ```bash # 在 hospital_web 上檢查憑證 -echo | openssl s_client -connect localhost:443 -servername tpesupporter.tpech.gov.tw 2>/dev/null | openssl x509 -noout -dates -subject -issuer +ssh hospital_web "echo | openssl s_client -connect localhost:443 \ + -servername tpesupporter.tpech.gov.tw 2>/dev/null \ + | openssl x509 -noout -dates -subject -issuer" -# 檢查憑證鏈完整性 -echo | openssl s_client -connect localhost:443 -servername tpesupporter.tpech.gov.tw 2>&1 | grep "Verify return code" +# 檢查憑證鏈 +ssh hospital_web "echo | openssl s_client -connect localhost:443 \ + -servername tpesupporter.tpech.gov.tw 2>&1 \ + | grep -E 'depth|s:|i:|Verify return'" ``` + +## 相關文件 + +- `ssl_deploy_guide.md` — 憑證部署 SOP +- `ssl_certs/` — 憑證檔案存放目錄 diff --git a/ssl_deploy_guide.md b/ssl_deploy_guide.md index 1a88a7f..09b0403 100644 --- a/ssl_deploy_guide.md +++ b/ssl_deploy_guide.md @@ -110,6 +110,10 @@ ssh hospital_web "echo | openssl s_client -connect localhost:443 \ 預期:`Verify return code: 0 (ok)` +> 注意:GCA 憑證的根 CA(GRCA G3)不在 Linux 預設信任庫, +> 伺服器端會顯示 `Verify return code: 20`,這是正常的。 +> 瀏覽器端通常可正常驗證。 + --- ## 替代方案:透過 NPM 管理後台 @@ -127,5 +131,5 @@ ssh hospital_web "echo | openssl s_client -connect localhost:443 \ | 期間 | 簽發者 | 到期日 | 備註 | |---|---|---|---| -| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1(中華電信) | 2026-04-23 | 憑證鏈不完整,缺中繼 CA | -| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3(GCA) | 2028-04-01 | 待部署,私鑰待確認 | +| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1(中華電信) | 2026-04-23 | 已替換 | +| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3(GCA) | 2028-04-01 | 2026-04-09 部署完成 |