mirror of
https://github.com/certbot/certbot.git
synced 2026-08-03 08:03:10 +02:00
docs: rewrite "Revoking certificates" (#8657)
* docs: rewrite "Revoking certificates" - `--cert-name` is supported since a long time ago - `--delete-after-revoke` is default - Mention that non-default `--server` must be specified - Document difference between acme key/cert key revocation methods - Reshuffle text to keep more important things earlier * minor edits * remove revocation note * remove "preauthorization" revocation method * rewrite deletion note
This commit is contained in:
+21
-13
@@ -474,29 +474,37 @@ like
|
|||||||
Revoking certificates
|
Revoking certificates
|
||||||
---------------------
|
---------------------
|
||||||
|
|
||||||
If your account key has been compromised or you otherwise need to revoke a certificate,
|
If you need to revoke a certificate, use the ``revoke`` subcommand to do so.
|
||||||
use the ``revoke`` command to do so. Note that the ``revoke`` command takes the certificate path
|
|
||||||
(ending in ``cert.pem``), not a certificate name or domain. Example::
|
|
||||||
|
|
||||||
certbot revoke --cert-path /etc/letsencrypt/live/CERTNAME/cert.pem
|
A certificate may be revoked by providing its name (see ``certbot certificates``) or by providing
|
||||||
|
its path directly::
|
||||||
|
|
||||||
|
certbot revoke --cert-name example.com
|
||||||
|
|
||||||
|
certbot revoke --cert-path /etc/letsencrypt/live/example.com/cert.pem
|
||||||
|
|
||||||
|
If the certificate being revoked was obtained via the ``--staging``, ``--test-cert`` or a non-default ``--server`` flag,
|
||||||
|
that flag must be passed to the ``revoke`` subcommand.
|
||||||
|
|
||||||
|
.. note:: After revocation, Certbot will (by default) ask whether you want to **delete** the certificate.
|
||||||
|
Unless deleted, Certbot will try to renew revoked certificates the next time ``certbot renew`` runs.
|
||||||
|
|
||||||
You can also specify the reason for revoking your certificate by using the ``reason`` flag.
|
You can also specify the reason for revoking your certificate by using the ``reason`` flag.
|
||||||
Reasons include ``unspecified`` which is the default, as well as ``keycompromise``,
|
Reasons include ``unspecified`` which is the default, as well as ``keycompromise``,
|
||||||
``affiliationchanged``, ``superseded``, and ``cessationofoperation``::
|
``affiliationchanged``, ``superseded``, and ``cessationofoperation``::
|
||||||
|
|
||||||
certbot revoke --cert-path /etc/letsencrypt/live/CERTNAME/cert.pem --reason keycompromise
|
certbot revoke --cert-name example.com --reason keycompromise
|
||||||
|
|
||||||
Additionally, if a certificate
|
Revoking by account key or certificate private key
|
||||||
is a test certificate obtained via the ``--staging`` or ``--test-cert`` flag, that flag must be passed to the
|
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||||
``revoke`` subcommand.
|
|
||||||
Once a certificate is revoked (or for other certificate management tasks), all of a certificate's
|
|
||||||
relevant files can be removed from the system with the ``delete`` subcommand::
|
|
||||||
|
|
||||||
certbot delete --cert-name example.com
|
By default, Certbot will try revoke the certificate using your ACME account key. If the certificate was created from
|
||||||
|
the same ACME account, the revocation will be successful.
|
||||||
|
|
||||||
.. note:: If you don't use ``delete`` to remove the certificate completely, it will be renewed automatically at the next renewal event.
|
If you instead have the corresponding private key file to the certificate you wish to revoke, use ``--key-path`` to perform the
|
||||||
|
revocation from any ACME account::
|
||||||
|
|
||||||
.. note:: Revoking a certificate will have no effect on the rate limit imposed by the Let's Encrypt server.
|
certbot revoke --cert-path /etc/letsencrypt/live/example.com/cert.pem --key-path /etc/letsencrypt/live/example.com/privkey.pem
|
||||||
|
|
||||||
.. _renewal:
|
.. _renewal:
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user