Files
106_105_181_70/ssl_cert_note.md
Timmy bbea2fe77a docs: 更新 SSL 憑證紀錄為目前部署狀態
- 新憑證(GCA G3)已於 2026-04-09 部署完成
- 補充憑證鏈結構與 GRCA 信任庫說明
- 更新歷史紀錄

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-09 10:30:00 +08:00

56 lines
1.8 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# SSL 憑證紀錄 - tpesupporter.tpech.gov.tw
## 目前使用中的憑證(已於 2026-04-09 部署)
| 項目 | 內容 |
|---|---|
| CN | tpesupporter.tpech.gov.tw |
| 組織 | 市政府 / 衛生局 / 市立聯合醫院 |
| 簽發者 | 政府憑證管理中心 - G3GCA |
| 有效期起 | 2026-04-01 |
| 有效期迄 | 2028-04-01 |
| TLS 版本 | TLSv1.3 |
| 加密套件 | TLS_AES_256_GCM_SHA384 |
| 金鑰 | RSA 2048 bit |
## 憑證鏈
```
0: tpesupporter.tpech.gov.tw (伺服器憑證)
└─ issued by: 政府憑證管理中心 - G3
1: 政府憑證管理中心 (中繼憑證)
└─ issued by: Government Root Certification Authority
2: 政府憑證管理中心 - G3 (中繼憑證)
└─ issued by: Government Root Certification Authority - G3
```
> 注意GRCA G3 根憑證不在 Linux 預設信任庫中,伺服器端 openssl 驗證會顯示
> `Verify return code: 20 (unable to get local issuer certificate)`
> 但瀏覽器端Chrome/Edge/Firefox通常可正常驗證。
## 歷史紀錄
| 期間 | 簽發者 | 到期日 | 備註 |
|---|---|---|---|
| 2025-04 ~ 2026-04 | HiPKI OV TLS CA - G1中華電信 | 2026-04-23 | 已替換 |
| 2026-04 ~ 2028-04 | 政府憑證管理中心 - G3GCA | 2028-04-01 | 目前使用中 |
## 檢查指令
```bash
# 在 hospital_web 上檢查憑證
ssh hospital_web "echo | openssl s_client -connect localhost:443 \
-servername tpesupporter.tpech.gov.tw 2>/dev/null \
| openssl x509 -noout -dates -subject -issuer"
# 檢查憑證鏈
ssh hospital_web "echo | openssl s_client -connect localhost:443 \
-servername tpesupporter.tpech.gov.tw 2>&1 \
| grep -E 'depth|s:|i:|Verify return'"
```
## 相關文件
- `ssl_deploy_guide.md` — 憑證部署 SOP
- `ssl_certs/` — 憑證檔案存放目錄