set +e echo "=== 既有 ACME 账号(复用,不新建) ===" ls -1 /etc/letsencrypt/accounts/acme-v02.api.letsencrypt.org/directory/ 2>/dev/null | head -3 echo "=== S1 签发 ai1net.com + *.ai1net.com(DNS-01) ===" certbot certonly \ --dns-cloudflare \ --dns-cloudflare-credentials /etc/cloudflare-ai1net.ini \ --dns-cloudflare-propagation-seconds 60 \ -d ai1net.com -d '*.ai1net.com' \ --cert-name ai1net.com \ --non-interactive --agree-tos 2>&1 | tail -18 echo "=== 证书落地核对 ===" certbot certificates 2>/dev/null | grep -A5 "Certificate Name: ai1net.com" | head -8 openssl x509 -in /etc/letsencrypt/live/ai1net.com/fullchain.pem -noout -subject -issuer -dates 2>/dev/null openssl x509 -in /etc/letsencrypt/live/ai1net.com/fullchain.pem -noout -ext subjectAltName 2>/dev/null | tr ',' '\n' | head -6