SSL 证书从一台服务器迁移到另一台服务器

发布于 2024-10-07 11:31:55 字数 50 浏览 0 评论 0原文

将有效的 SSL 证书从一台服务器和服务提供商迁移到另一台服务器和服务提供商需要什么?

What's necessary to migrate valid SSL certificate from one server and service provider to another?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

握住你手 2024-10-14 11:31:55

在某些情况下,可能只需将密钥复制到新服务器并更改新服务器上的 apache 配置即可。

例如:
http://www.digicert.com/ssl-support/apache-ssl -export.htm

某些证书颁发机构可能会将 SSL 证书绑定到特定服务器。

In some cases it may be simply a matter of copying the keys to and changing apache configuration on the new server.

For example:
http://www.digicert.com/ssl-support/apache-ssl-export.htm

Some certificate authorities may tie an SSL certificate to a specific server.

等风来 2024-10-14 11:31:55

本质上,您从当前安装 SSL 证书的服务器导出 SSL 证书,将 SSL 证书移至新服务器,然后在新服务器上导入 SSL 证书。但这仅适用于您坚持使用相同的证书颁发机构(“提供商”)的情况......从您的问题来看,您不是。

请记住,即使您坚持使用同一提供商,许多提供商也要求您为安装 SSL 证书的每台服务器购买“服务器许可证”,即使它使用相同的私钥。说到私钥,复制 SSL 证书并在不同的服务器上使用相同的私钥的安全性稍差。如果攻击者闯入一台服务器并获取私钥,他将能够侦听其他服务器正在进行的连接。

因此,既然您想切换提供商,我给您的建议是,一旦您移动到新服务器,就与新提供商一起购买一个新的提供商......但也许我误解了您的问题。

Essentially, you export SSL certificates from the server that they are currently installed on, move SSL certificates to the new server, and then import SSL certificates on the new server. But this only really only applies if you are sticking with the same certificate authority ("provider")... which it sounds by your question that you are not.

Keep in mind that even if you stick with the same provider, many require that you purchase a "server license" for each server that you install an SSL certificate to, even if it uses the same private key. And speaking of private keys, it is slightly less secure to copy the SSL certificate and use the same private key on a different server. If an attacker breaks into one server and gets the private key, he will be able to listen in on the connections that other servers are making.

So my advice to you since you want to switch providers is just purchase a new one all together with the new provider once you move to the new server... But maybe I'm misunderstanding your question.

简美 2024-10-14 11:31:55

首先确定安装了证书的设备是否将私钥存储在硬件/软件中。在当今的大多数服务器中,它们位于软件 *.key 文件中(例如 Web 服务器 SSL)。
在密钥文件附近可以找到证书,甚至 CSR。通常允许将这些文件移动到另一台服务器(考虑到目标服务器将具有相同的主机名),从而保持相同的 CA。大多数 CA 并不关心这样做的客户。

但如果您只是想将服务提供商从一个提供商切换到另一个提供商,只需要求当前 CA“撤销”证书即可。然后开始使用新 CA 的新证书购买流程。

First determine if the device installed with the certs are storing the private key in hardware/software. In most today's servers, they are in software *.key files (e.g. web server SSL).
To be found near the key files are the certificate and perhaps even CSR. Moving these files to another server is generally allowed (Considering the destination server will have the same hostname) and hence keeping the same CA. Most CAs have no concern to customers who does that.

But if you are just looking to switch the service provider from one to another, simply ask current CA to 'revoke' the cert. Then start with the new Cert buying process with the new CA.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文