From bbea2fe77a74d142cd90d4e68cd1d4e4e794c913 Mon Sep 17 00:00:00 2001 From: Timmy Date: Thu, 9 Apr 2026 10:30:00 +0800 Subject: [PATCH] =?UTF-8?q?docs:=20=E6=9B=B4=E6=96=B0=20SSL=20=E6=86=91?= =?UTF-8?q?=E8=AD=89=E7=B4=80=E9=8C=84=E7=82=BA=E7=9B=AE=E5=89=8D=E9=83=A8?= =?UTF-8?q?=E7=BD=B2=E7=8B=80=E6=85=8B?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - 新憑證(GCA G3)已於 2026-04-09 部署完成 - 補充憑證鏈結構與 GRCA 信任庫說明 - 更新歷史紀錄 Co-Authored-By: Claude Opus 4.6 (1M context) --- ssl_cert_note.md | 50 +++++++++++++++++++++++++++++++-------------- ssl_deploy_guide.md | 8 ++++++-- 2 files changed, 41 insertions(+), 17 deletions(-) diff --git a/ssl_cert_note.md b/ssl_cert_note.md index 2bde825..e388880 100644 --- a/ssl_cert_note.md +++ b/ssl_cert_note.md @@ -1,35 +1,55 @@ # SSL 憑證紀錄 - tpesupporter.tpech.gov.tw -## 憑證資訊 +## 目前使用中的憑證(已於 2026-04-09 部署) | 項目 | 內容 | |---|---| | CN | tpesupporter.tpech.gov.tw | -| 組織 | 政府機關-臺北市立聯合醫院 | -| 簽發者 | HiPKI OV TLS CA - G1(中華電信) | -| 有效期起 | 2025-04-23 | -| 有效期迄 | 2026-04-23 | +| 組織 | 市政府 / 衛生局 / 市立聯合醫院 | +| 簽發者 | 政府憑證管理中心 - G3(GCA) | +| 有效期起 | 2026-04-01 | +| 有效期迄 | 2028-04-01 | | TLS 版本 | TLSv1.3 | | 加密套件 | TLS_AES_256_GCM_SHA384 | | 金鑰 | RSA 2048 bit | -## 待處理事項 +## 憑證鏈 -- [ ] 憑證將於 **2026-04-23** 到期,需提前更新 -- [ ] 憑證鏈不完整:伺服器僅送出終端憑證,缺少中繼 CA(HiPKI OV TLS CA - G1),需在 NPM 補上中繼憑證 +``` +0: tpesupporter.tpech.gov.tw (伺服器憑證) + └─ issued by: 政府憑證管理中心 - G3 +1: 政府憑證管理中心 (中繼憑證) + └─ issued by: Government Root Certification Authority +2: 政府憑證管理中心 - G3 (中繼憑證) + └─ issued by: Government Root Certification Authority - G3 +``` -## 中繼憑證補充方式 +> 注意:GRCA G3 根憑證不在 Linux 預設信任庫中,伺服器端 openssl 驗證會顯示 +> `Verify return code: 20 (unable to get local issuer certificate)`, +> 但瀏覽器端(Chrome/Edge/Firefox)通常可正常驗證。 -1. 下載中繼憑證:https://tls.hinet.net/certs/OVCA-G1.crt -2. 在 NPM 管理後台 (localhost:8181) → SSL Certificates → 編輯對應憑證 -3. 將中繼憑證內容附加到憑證檔案中(或上傳為 intermediate certificate) +## 歷史紀錄 + +| 期間 | 簽發者 | 到期日 | 備註 | +|---|---|---|---| +| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1(中華電信) | 2026-04-23 | 已替換 | +| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3(GCA) | 2028-04-01 | 目前使用中 | ## 檢查指令 ```bash # 在 hospital_web 上檢查憑證 -echo | openssl s_client -connect localhost:443 -servername tpesupporter.tpech.gov.tw 2>/dev/null | openssl x509 -noout -dates -subject -issuer +ssh hospital_web "echo | openssl s_client -connect localhost:443 \ + -servername tpesupporter.tpech.gov.tw 2>/dev/null \ + | openssl x509 -noout -dates -subject -issuer" -# 檢查憑證鏈完整性 -echo | openssl s_client -connect localhost:443 -servername tpesupporter.tpech.gov.tw 2>&1 | grep "Verify return code" +# 檢查憑證鏈 +ssh hospital_web "echo | openssl s_client -connect localhost:443 \ + -servername tpesupporter.tpech.gov.tw 2>&1 \ + | grep -E 'depth|s:|i:|Verify return'" ``` + +## 相關文件 + +- `ssl_deploy_guide.md` — 憑證部署 SOP +- `ssl_certs/` — 憑證檔案存放目錄 diff --git a/ssl_deploy_guide.md b/ssl_deploy_guide.md index 1a88a7f..09b0403 100644 --- a/ssl_deploy_guide.md +++ b/ssl_deploy_guide.md @@ -110,6 +110,10 @@ ssh hospital_web "echo | openssl s_client -connect localhost:443 \ 預期:`Verify return code: 0 (ok)` +> 注意:GCA 憑證的根 CA(GRCA G3)不在 Linux 預設信任庫, +> 伺服器端會顯示 `Verify return code: 20`,這是正常的。 +> 瀏覽器端通常可正常驗證。 + --- ## 替代方案:透過 NPM 管理後台 @@ -127,5 +131,5 @@ ssh hospital_web "echo | openssl s_client -connect localhost:443 \ | 期間 | 簽發者 | 到期日 | 備註 | |---|---|---|---| -| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1(中華電信) | 2026-04-23 | 憑證鏈不完整,缺中繼 CA | -| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3(GCA) | 2028-04-01 | 待部署,私鑰待確認 | +| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1(中華電信) | 2026-04-23 | 已替換 | +| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3(GCA) | 2028-04-01 | 2026-04-09 部署完成 |