mirror of
https://github.com/XTLS/Xray-docs-next.git
synced 2026-10-11 08:48:14 +03:00
zh/en: add buildChain in CertificateObject (#547)
This commit is contained in:
@@ -436,6 +436,7 @@ CipherSuites 用于配置受支持的密码套件列表, 每个套件名称之
|
||||
"ocspStapling": 3600,
|
||||
"oneTimeLoading": false,
|
||||
"usage": "encipherment",
|
||||
"buildChain": false,
|
||||
"certificateFile": "/path/to/certificate.crt",
|
||||
"keyFile": "/path/to/key.key",
|
||||
"certificate": [
|
||||
@@ -533,6 +534,14 @@ OCSP 装订更新,与证书热重载的时间间隔。 单位:秒。默认
|
||||
如已经拥有一个域名, 可以使用工具便捷的获取免费第三方证书,如[acme.sh](https://github.com/acmesh-official/acme.sh)
|
||||
:::
|
||||
|
||||
> `buildChain`: true | false
|
||||
|
||||
仅当证书用途为 `issue` 时生效,若值为 `true` ,签发证书时将CA证书嵌入证书链。
|
||||
|
||||
::: tip TIP 1
|
||||
不应该将根证书嵌入证书链。该选项只适合在签名CA证书为中间证书时启用。
|
||||
:::
|
||||
|
||||
> `certificateFile`: string
|
||||
|
||||
证书文件路径,如使用 OpenSSL 生成,后缀名为 .crt。
|
||||
|
||||
Reference in New Issue
Block a user