MHSanaei:3x-ui 应固定签发 CA 而非叶子证书,证书续期才不会破坏 pin
MHSanaei 在 3x-ui issue #6660(NethminaYasas 于 2026-09-26 提交、已关闭,反映域名 SSL 证书续期后「Pinned Peer Cert SHA-256」不更新)下于 2026-09-27 19:49:43Z 答复:这是预期行为——pin 是固定值,而叶子证书的哈希每次续期都会变;就算让面板自动更新也帮助不大,已经导入链接的客户端仍保留旧 pin,在刷新之前照样失败。 他给出的做法是固定签发 CA 而不是叶子证书:据他所称,Xray 接受与所提供证书链中某个 CA 相匹配的 pin,并据此校验叶子证书,这样续期就不会破坏 pin。具体操作是在入站的 TLS 设置里把证书指向 fullchain.pem(而不是 cert.pem),再点「pin from certificate」,这样会连同叶子一起加入中间 CA 的哈希。他还提醒:Let's Encrypt 会在多个中间证书之间随机选取(RSA 为 R10/R11、ECDSA 为 E5/E6),因此应把自己密钥类型对应的全部当前中间证书哈希都加上。
作者原文@MHSanaeiThis is expected behaviour. The pin is a fixed value, and the leaf certificate's hash changes on every renewal. Having the panel update it automatically wouldn't help much either: clients that already imported a link keep the old pin and would still fail until they refresh.
Instead, pin the issuing CA rather than the leaf. Xray accepts a pin that matches a CA in the served chain and then verifies the leaf against it, so renewals don't break the pin. In the inbound's TLS settings, point the certificate at
fullchain.pem(notcert.pem) and press the "pin from certificate" button. That adds the intermediate CA's hash along with the leaf's. Let's Encrypt picks between several intermediates at random (e.g. R10/R11 for RSA, E5/E6 for ECDSA), so add the hashes of all current intermediates for your key type.