Download the PHP package likun-mci/acme without Composer

On this page you can find all versions of the php package likun-mci/acme. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package acme

mci-acme

用原生 PHP 实现的 ACME v2(RFC 8555)证书客户端 —— acme.sh 的功能对等实现。

申请、续期、吊销、部署 Let's Encrypt / ZeroSSL / BuyPass / Google Trust Services / SSL.com 的免费 TLS 证书, 全程不调用任何外部进程。

为什么又造一个轮子

acme.sh 很好用,但它是 shell 脚本,依赖 openssl 命令行、curl、crontab、sed/awk。 这在两类环境里会直接卡死:

mci-acme 把这些依赖全部换成 PHP 自己的能力:

acme.sh 依赖 mci-acme 的做法
openssl genrsa / ecparam ext-openssl 的 openssl_pkey_new()
openssl req -new(要配 openssl.cnf 才能写 SAN) 自己用 ASN.1 DER 编码器拼 CSR,不碰配置文件
openssl x509 -noout -dates openssl_x509_parse()
curl curl 扩展优先,没有则退回 stream wrapper
crontab -e 打印该加的那行让你自己贴,或输出 systemd timer 配置
systemctl reload nginx 读 pid 文件 + posix_kill() 发 SIGHUP
dns_*.sh(150 个 shell 脚本) src/Challenge/Dns01/Provider/ 下的 PHP 类

源码里没有一处 exec/shell_exec/system/passthru/proc_open/popen/反引号, tests/no_exec_test.php 每次跑测试都会扫一遍守着这条线。

安装

跑不了 composer 的机器上,直接下载解压也能用 —— 项目自带零依赖的 bootstrap.php:

要求:PHP >= 7.2,ext-openssl、ext-json、ext-mbstring。 建议装 ext-curl(更稳的 HTTP)与 ext-posix(发重载信号)。

命令行用法

签发

调试时请用 staging:--ca letsencrypt_test。正式环境每组域名每周只能签 5 张, 调参数很容易把额度用光,而额度是按周滚动的,用光了只能等。

安装到服务并自动重载

这套配置会被记进证书的 .conf,之后每次续期成功都自动重放一遍,不用再手工执行。

--reload-service 支持 nginx / apache / httpd / haproxy / php-fpm / postfix / dovecot, 原理是读 pid 文件后发对应的信号(nginx 是 SIGHUP,Apache 是 SIGUSR1……)。

没有 ext-posix 或者服务不在本机时,改用标记文件:

配一个 systemd path unit 监听那个文件,由它去执行 systemctl reload nginx。

续期

续期用的验证方式、CA、密钥类型、DNS 凭据都从证书目录的 .conf 读,不用重复指定。 单张失败不影响其他证书,最后统一汇报。

其他

网络受限时走代理

所有出网请求(CA 接口、DNS 提供商 API、ZeroSSL 换 EAB)都能走代理:

也认 curl 那套环境变量,运维配好的不用重配: HTTPS_PROXY、HTTP_PROXY、ALL_PROXY、NO_PROXY(大小写都行)。

优先级:--direct > --proxy > account.conf 里的 PROXY > 环境变量。

支持 http / https / socks5 / socks5h 四种。受限网络下建议用 socks5h: 它把域名交给代理去解析,而 socks5 是本地解析——如果本地 DNS 本身就不通 (这往往正是要用代理的原因),socks5 会卡在解析那一步。

作为库使用时:

dns-01 的传播检测走的是 UDP DNS,不经过代理。 HTTP 代理转发不了 UDP, 而 SOCKS5 的 UDP associate 在多数代理上是关闭的。本库的做法是: 直接查权威 NS 失败时自动回退到系统解析器。如果连系统 DNS 都不通, 把 --dns-sleep 调大让它盲等,或改用 http-01。

acme.sh 风格的写法也能用,现有脚本改个程序名就行:

数据目录也是同一个(默认 ~/.acme.sh),所以 acme.sh 签过的证书这边 mci-acme renew -d example.com 直接就能续,不用重签、不用导入。详见文件布局。

作为库使用

各层都可以单独拿出来用:

支持的 CA

短名 CA 需要 EAB
letsencrypt Let's Encrypt(默认) 否
letsencrypt_test Let's Encrypt Staging 否
zerossl ZeroSSL 是(可用邮箱自动换取)
buypass / buypass_test Buypass Go SSL 否
google / google_test Google Trust Services 是
sslcom / sslcom_ecc SSL.com 是
actalis Actalis 是

也可以直接写目录 URL,用没列在这里的 CA。

支持的 DNS 提供商

短名与环境变量都与 acme.sh 保持一致,已经 export 过的变量继续有效:

短名 提供商 环境变量
dns_cf Cloudflare CF_Token(推荐)或 CF_Key + CF_Email
dns_ali 阿里云 DNS Ali_Key、Ali_Secret
dns_dp DNSPod DP_Id、DP_Key
dns_tencent 腾讯云 DNSPod Tencent_SecretId、Tencent_SecretKey
dns_huaweicloud 华为云 DNS HUAWEICLOUD_AccessKey、HUAWEICLOUD_SecretKey
dns_gd GoDaddy GD_Key、GD_Secret
dns_aws AWS Route 53 AWS_ACCESS_KEY_ID、AWS_SECRET_ACCESS_KEY
dns_dgon DigitalOcean DO_API_KEY
dns_vultr Vultr VULTR_API_KEY
dns_linode_v4 Linode LINODE_V4_API_KEY
dns_hetzner Hetzner DNS HETZNER_Token
dns_gandi_livedns Gandi LiveDNS GANDI_LIVEDNS_TOKEN 或 GANDI_LIVEDNS_KEY
dns_namesilo NameSilo Namesilo_Key
dns_duckdns DuckDNS DuckDNS_Token
dns_he Hurricane Electric HE_DDNS_Key
dns_manual 手动(打印记录让你自己加) —

签发时凭据会存进证书目录的 .conf(带 SAVED_ 前缀,与 acme.sh 一致),之后续期不用再 export。

加一家新的很简单:实现 DnsProviderInterface 的两个方法,在 ProviderFactory::MAP 注册短名, 在 tests/dns_provider_test.php 里用假的 HTTP transport 补一条测试,断言请求的 URL、方法、鉴权头与请求体——不要打真实 API。

文件布局

默认目录就是 acme.sh 的 ~/.acme.sh/,不是另起一个。机器上装过 acme.sh 的话, 原有的账户密钥和证书直接就能用——mci-acme list 列得出来,mci-acme renew -d ... 续的就是那张证书,不用重签(重签还会白白吃掉 CA 的速率限制额度)。 反过来也一样:本库写出来的文件 acme.sh 认得,两个客户端可以随时换着用。

目录位置按这个顺序决定,acme.sh 那套环境变量照认:

来源 说明
--home <目录>(别名 --config-home) 命令行,优先级最高
MCI_ACME_CONFIG_HOME 本库专用,想和 acme.sh 分开存就设这个
LE_CONFIG_HOME acme.sh 的 --config-home
LE_WORKING_DIR acme.sh 的 --home
~/.acme.sh 默认

证书目录还能单独挪走(acme.sh 的 --cert-home):命令行 --cert-home > 环境变量 CERT_HOME > account.conf 里的 CERT_HOME > 跟着上面的根目录。 acme.sh 用 --cert-home 挪过证书的机器,这个键已经写在 account.conf 里了, 本库读得到,什么都不用配。

一些实现上的取舍

CSR 自己拼 DER。 openssl_csr_new() 要通过 openssl.cnf 里的 req_extensions 才能写 subjectAltName,那意味着运行时得往磁盘写临时配置文件 —— 在 open_basedir 受限、 临时目录只读的主机上直接歇菜。自己拼字节就完全绕开了这个问题, openssl 扩展只负责最后那一次签名。生成的 CSR 通过了 openssl req -verify 的校验。

dns-01 的传播检测直接问权威 NS。 不用 dns_get_record():它走系统解析器, 而刚写完 TXT 记录马上查的话,本地解析器很可能还留着几分钟前的负缓存。 src/Util/DnsResolver.php 是一个轻量 DNS 客户端,先查域名的 NS 再直接问它们, UDP 响应被截断(TC 位)时自动换 TCP。

服务重载用信号而不是 shell。 nginx -s reload 本质就是读 pid 文件然后 kill -HUP, systemctl reload 也只是转发信号。直接 posix_kill() 效果一样,还少一层依赖。

代理的 CONNECT 隧道是自己写的。 PHP 的 stream wrapper 有个 proxy 选项, 但它只能把绝对 URI 发给 HTTP 代理——访问 https:// 需要先发 CONNECT 建隧道 再在隧道里握手 TLS,PHP 的 https wrapper 不做这件事,SOCKS5 更是完全没有。 所以 src/Http/Proxy/ProxyConnector.php 手写了 CONNECT 与 SOCKS5 握手 (RFC 1928 / RFC 1929),SocketTransport 在拿到的裸 socket 上自己收发 HTTP/1.1。 有 curl 时用不到这些(curl 全都支持),它们是为「没有 curl + 网络受限」 这个组合准备的,而那恰恰是本库的目标环境之一。

通配符只能用 dns-01,这是 CA 的硬规则 —— 服务端根本不会为 *.example.com 提供 http-01 挑战。本库在构造请求时就拦下来,而不是等到跑一半才失败。

测试

离线测试有 22 个文件、1000 多项断言,全部不打真实 CA、不打真实 DNS API:

协作与开发约定

许可

MIT


All versions of acme with dependencies

PHP Build Version
Package Version
Requires php Version >=7.2
ext-json Version *
ext-openssl Version *
ext-mbstring Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package likun-mci/acme contains the following files

Loading the files please wait ...