Appearance
profile —— 参数模板
Profile 是 CertiMan 的账号级参数模板,保存在 ~/.certiman/cc/profiles/<name>.yaml。可将常用参数组合(产品 ID、组织信息、验证方式、部署 hook、输出格式等)保存为一个 profile,之后通过 certiman issue --profile <name> 复用。
与证书级配置的区别
Profile 是账号级默认,作用于所有引用它的证书;证书级 cert.yaml 是单张证书的固定参数,两者可以组合使用。
与 cert.yaml 的合并规则
Profile 仅在 certiman issue 首次生成 cert.yaml 时作为模板写入,之后 cert.yaml 独立存在。Profile 后续的 edit / delete 操作不影响已有证书。
修改 Profile 不会影响已有证书,已有证书 cert.yaml 中的修改也不会被模板覆盖。如需将 Profile 的新参数应用到已有证书,直接编辑该证书的 cert.yaml;如需以已有证书的参数生成新模板,运行 certiman profile save-from <cn>。
什么时候用 profile
- 参数复用:批量申请组织与验证方式相同的证书时,将公共参数保存为 profile,申请时只需使用
-d <主域名> --profile <name>两个 flag - CI / 自动化:CI 脚本引用同一个 profile,无需在每次运行时重复传入大量 flag
- 反向抽取:运行
certiman profile save-from <cn>,将手工调整过的证书参数保存为模板,供后续证书复用
用法示例
bash
# 1. 先手工申请一张证书,把参数调好
certiman issue -d example.com \
--product-id trustasia_ssl_dv_v2 --validity-months 12 \
--dcv.method dns-persist --dcv.present ./tc-present.sh \
--dcv.cleanup ./tc-cleanup.sh \
--deploy-hook "sh ./deploy-log.sh"
# 2. 把这张证书的参数存成 profile
certiman profile save-from example.com my-dv-template
# 3. 后续申请同款证书只需要两个 flag
certiman issue -d api.example.com --profile my-dv-template
# 4. 需要变体时,先复制再编辑(不覆盖原模板)
certiman profile copy my-dv-template my-ov-template
certiman profile edit my-ov-template子命令一览
| 子命令 | 作用 |
|---|---|
profile list | 列出所有已保存的 profile |
profile show | 打印指定 profile 的原始 YAML |
profile save-from | 从已下载证书反向抽取参数生成 profile |
profile copy | 复制现有 profile 到新名称 |
profile edit | 在系统编辑器中打开 profile |
profile delete | 删除指定 profile |
相关文档
- 证书命令 · issue —— 用
--profile <name>引用模板 - 证书命令 · cert.yaml —— 证书级配置文件
- 账号命令 · login / logout —— 账号凭证管理
