Appearance
renew —— 续期证书
对已签发的证书发起续期。证书配置中开启 renew.auto_cert 后,cron 命令会自动执行续期。
- 续期判定:
renew.days_before与 ARI 二选一。renew.days_before大于0时按剩余天数判定,不请求 ARI;等于0时按 ARI 建议窗口判定。两种方式均以证书已过期为最高优先级,并以剩余有效期比例作为回退判据。使用-f时忽略续期窗口,强制续期。 - 私钥策略:每次续期都生成新私钥,新证书下载完成后才替换现役私钥;续期中断时,现役私钥保持不变。
用法
bash
certiman renew [flags]参数
| flag | 短名 | 类型 | 默认 | 说明 |
|---|---|---|---|---|
--domain | -d | []string | 选择器:按主域名指定 | |
--conf | -c | string | 选择器:证书配置文件路径 | |
--all | bool | false | 批量处理所有 renew.auto_cert=true 的证书(与选择器 -d / -c 互斥) |
示例
bash
# 续期单张证书(未到窗口时幂等跳过)
certiman renew -d example.com
# 忽略续期窗口强制续期
certiman renew -d example.com -f
# 批量续期所有开启自动续期的证书
certiman renew --all
# 手动指定证书配置文件
certiman renew -c /etc/certiman/shop-cert.yaml