Traefik未获得新域的SSL证书

时间:2019-07-07 11:53:58

标签: https lets-encrypt traefik consul

我已经设置了Traefik / Docker Swarm / Let's Encrypt / Consul,并且一切正常。它设法成功获取了域admin.domain.tldregistry.domain.tldstaging.domain.tld的证书,但现在我已经尝试添加服务于domain.tldmatomo.domain.tld的容器那些没有任何证书(浏览器警告自签名证书,因为它是默认的Traefik证书)。

我的Traefik配置(已上传到Consul):

debug = false
logLevel = "DEBUG"

insecureSkipVerify = true

defaultEntryPoints = ["https", "http"]

[entryPoints]
    [entryPoints.ping]
    address = ":8082"
    [entryPoints.http]
    address = ":80"
        [entryPoints.http.redirect]
        entryPoint = "https"
    [entryPoints.https]
    address = ":443"
    [entryPoints.https.tls]

[traefikLog]
    filePath = '/var/log/traefik/traefik.log'
    format = 'json'
[accessLog]
    filePath = '/var/log/traefik/access.log'
    format = 'json'
    [accessLog.fields]
        defaultMode = 'keep'
        [accessLog.fields.headers]
            defaultMode = 'keep'
            [accessLog.fields.headers.names]
                "Authorization" = "drop"

[retry]

[api]
entryPoint = "traefik"
dashboard = true
debug = false

[ping]
entryPoint = "ping"

[metrics]
    [metrics.influxdb]
    address = "http://influxdb:8086"
    protocol = "http"
    pushinterval = "10s"
    database = "metrics"

[docker]
endpoint = "unix:///var/run/docker.sock"
domain = "domain.tld"
watch = true
exposedByDefault = false
network = "net_web"
swarmMode = true

[acme]
email = "my@mail.tld"
storage = "traefik/acme/account"
entryPoint = "https"
onHostRule = true
[acme.httpChallenge]
entryPoint = "http"

可能与之相关,在traefik.log中,我反复(几乎每秒一次)得到以下内容(但仅适用于registry子域)。听起来像是将数据持久保存为领事的问题,但是没有任何错误表明这种问题。

{"level":"debug","msg":"Looking for an existing ACME challenge for registry.domain.tld...","time":"2019-07-07T11:37:23Z"}
{"level":"debug","msg":"Looking for provided certificate to validate registry.domain.tld...","time":"2019-07-07T11:37:23Z"}
{"level":"debug","msg":"No provided certificate found for domains registry.domain.tld, get ACME certificate.","time":"2019-07-07T11:37:23Z"}
{"level":"debug","msg":"ACME got domain cert registry.domain.tld","time":"2019-07-07T11:37:23Z"}

更新:我设法在日志中找到此行:

{"level":"error","msg":"Error getting ACME certificates [matomo.domain.tld] : cannot obtain certificates: acme: Error -\u003e One or more domains had a problem:\n[matomo.domain.tld] acme: error: 400 :: urn:ietf:paramsacme:error:connection :: Fetching http://matomo.domain.tld/.well-known/acme-challenge/WJZOZ9UC1aJl9ishmL2ACKFbKoGOe_xQoSbD34v8mSk: Timeout after connect (your server may be slow or overloaded), url: \n","time":"2019-07-09T16:27:43Z"}

因此,问题似乎在于挑战因超时而失败。为什么会超时?

更新2:更多日志条目:

{"level":"debug","msg":"Looking for an existing ACME challenge for staging.domain.tld...","time":"2019-07-10T19:38:34Z"}
{"level":"debug","msg":"Looking for provided certificate to validate staging.domain.tld...","time":"2019-07-10T19:38:34Z"}
{"level":"debug","msg":"No provided certificate found for domains staging.domain.tld, get ACME certificate.","time":"2019-07-10T19:38:34Z"}
{"level":"debug","msg":"No certificate found or generated for staging.domain.tld","time":"2019-07-10T19:38:34Z"}
{"level":"debug","msg":"http: TLS handshake error from 10.255.0.2:51981: remote error: tls: unknown certificate","time":"2019-07-10T19:38:34Z"}

但是,几分钟到一个小时后,它就可以工作了(到目前为止,对于两个域)。

1 个答案:

答案 0 :(得分:0)

不确定其功能或错误,但删除以下http至https重定向对我来说解决了它:

 [entryPoints.http.redirect]
        entryPoint = "https"