Updated Validity (markdown)

master
neil 2022-04-01 21:40:08 +08:00
parent b0f5cd91d5
commit 333c36dc2d
1 changed files with 31 additions and 1 deletions

@ -1 +1,31 @@
validity
The ACME protocol supported the `NotBefore` and `NotAfter` fields of the cert.
And some of the CAs supported this feature. (The Letsencrypt CA doesn't support it for now)
There are 2 command options to use:
1. The `--valid-to <date time>` option, which is for `NotAfter` field.
2. The `--valid-from <date time>` option, which is for `NotBeofre` field.
Usage:
### 1. Set the lifetime of the cert:
```
acme.sh --issue -d example.com -dns dns_cf --valid-to "2022-04-01T08:10:33Z"
```
The value of `--valid-to` is an absolute date time in the future. The issued cert will expire on that time(`NotAfter`).
Please be careful about the date time format, it Must be exact format used above.