Files
106_105_181_70/ssl_cert_note.md
Timmy bbea2fe77a docs: 更新 SSL 憑證紀錄為目前部署狀態
- 新憑證(GCA G3)已於 2026-04-09 部署完成
- 補充憑證鏈結構與 GRCA 信任庫說明
- 更新歷史紀錄

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 10:30:00 +08:00

1.8 KiB
Raw Blame History

SSL 憑證紀錄 - tpesupporter.tpech.gov.tw

目前使用中的憑證(已於 2026-04-09 部署)

項目 內容
CN tpesupporter.tpech.gov.tw
組織 市政府 / 衛生局 / 市立聯合醫院
簽發者 政府憑證管理中心 - G3GCA
有效期起 2026-04-01
有效期迄 2028-04-01
TLS 版本 TLSv1.3
加密套件 TLS_AES_256_GCM_SHA384
金鑰 RSA 2048 bit

憑證鏈

0: tpesupporter.tpech.gov.tw           (伺服器憑證)
   └─ issued by: 政府憑證管理中心 - G3
1: 政府憑證管理中心                       (中繼憑證)
   └─ issued by: Government Root Certification Authority
2: 政府憑證管理中心 - G3                  (中繼憑證)
   └─ issued by: Government Root Certification Authority - G3

注意GRCA G3 根憑證不在 Linux 預設信任庫中,伺服器端 openssl 驗證會顯示 Verify return code: 20 (unable to get local issuer certificate) 但瀏覽器端Chrome/Edge/Firefox通常可正常驗證。

歷史紀錄

期間 簽發者 到期日 備註
2025-04 ~ 2026-04 HiPKI OV TLS CA - G1中華電信 2026-04-23 已替換
2026-04 ~ 2028-04 政府憑證管理中心 - G3GCA 2028-04-01 目前使用中

檢查指令

# 在 hospital_web 上檢查憑證
ssh hospital_web "echo | openssl s_client -connect localhost:443 \
  -servername tpesupporter.tpech.gov.tw 2>/dev/null \
  | openssl x509 -noout -dates -subject -issuer"

# 檢查憑證鏈
ssh hospital_web "echo | openssl s_client -connect localhost:443 \
  -servername tpesupporter.tpech.gov.tw 2>&1 \
  | grep -E 'depth|s:|i:|Verify return'"

相關文件

  • ssl_deploy_guide.md — 憑證部署 SOP
  • ssl_certs/ — 憑證檔案存放目錄