一、适用场景

当域名解析可以指向运行 Certbot 的服务器,且服务器的 80 端口可以从公网访问时,使用 HTTP-01 验证是最简单的方式。

优势:

  • 全自动验证,无需手动添加 DNS 记录

  • 支持自动续期

  • Certbot 可自动修改 Nginx 配置并部署证书

示例:为 www.test.com 申请证书,域名解析指向运行 Certbot 的服务器。


二、前置条件

项目要求
服务器CentOS 7/8、openEuler、RHEL 等
域名www.test.com 的 A 记录指向本服务器公网 IP
端口80 端口对公网开放(安全组 + 系统防火墙均需放行)
Nginx已安装并运行,配置了 www.test.com 的 server 块
网络服务器可访问外网

三、Certbot 安装方式

方式一:yum 安装(CentOS/RHEL 推荐)

bash

# 1. 安装 EPEL 源
sudo yum install -y epel-release

# 2. 安装 Certbot 及 Nginx 插件
sudo yum install -y certbot python2-certbot-nginx

# 3. 验证安装
certbot --version

注意:CentOS 8 及以上版本使用 dnf:

bash

sudo dnf install -y certbot python3-certbot-nginx

方式二:Snap 安装(官方推荐,版本最新)

bash

# 1. 安装 snapd
sudo yum install -y epel-release
sudo yum install -y snapd

# 2. 启用 snapd
sudo systemctl enable --now snapd.socket
sudo ln -s /var/lib/snapd/snap /snap

# 3. 安装 Certbot
sudo snap install --classic certbot

# 4. 创建软链接
sudo ln -s /snap/bin/certbot /usr/bin/certbot

# 5. 验证
certbot --version

方式三:pip 安装(通用,适合 openEuler)

bash

# 1. 安装 pip
sudo yum install -y python3-pip

# 2. 安装 Certbot 及 Nginx 插件
sudo pip3 install certbot certbot-nginx

# 3. 验证
certbot --version

方式四:openEuler 系统

openEuler 的默认源可能没有 Certbot,推荐使用 pip 方式:

bash

sudo yum install -y python3-pip
sudo pip3 install certbot certbot-nginx
certbot --version

如果 pip 安装后提示 certbot: command not found,检查 pip 的 bin 目录是否在 PATH 中:

bash

export PATH=$PATH:/usr/local/bin

验证安装是否成功

bash

certbot --version

输出版本号(如 certbot 1.0.0 或 certbot 2.x.x)即表示安装成功。


四、操作步骤

步骤 1:确认域名解析

bash

dig www.test.com +short
# 或
nslookup www.test.com

期望结果:输出本服务器的公网 IP。

如果解析不对,先去域名服务商处修改 A 记录,等 DNS 生效后再继续。

步骤 2:确认 Nginx 配置

确保 /etc/nginx/conf.d/ 下有 www.test.com 的 server 块,例如 /etc/nginx/conf.d/www.test.com.conf:

nginx

server {
    listen 80;
    server_name www.test.com;

    location / {
        root /usr/share/nginx/html;
        index index.html;
    }
}

验证配置并重载:

bash

nginx -t
nginx -s reload

步骤 3:确认 80 端口对公网开放

3.1 检查系统防火墙

bash

# firewalld
firewall-cmd --list-all | grep http

# 如果没有放行,执行:
firewall-cmd --permanent --add-service=http
firewall-cmd --reload

# 或者使用 iptables
iptables -L -n | grep 80
3.2 检查云服务器安全组

登录云控制台(阿里云/腾讯云/华为云等),找到该服务器,检查安全组入方向规则,确保有:

协议端口来源
TCP800.0.0.0/0
TCP4430.0.0.0/0
3.3 从外部验证 80 端口可达

在另一台机器上执行:

bash

curl -I http://www.test.com

期望结果:返回 HTTP/1.1 200 OK 或 404(只要有响应就说明端口通)。

如果超时,说明 80 端口被防火墙或安全组拦截,需先解决。

步骤 4:执行 Certbot 申请证书

bash

certbot --nginx -d www.test.com

参数说明:

  • --nginx:使用 Nginx 插件,自动验证 + 自动配置

  • -d www.test.com:指定域名(多个域名可写多个 -d)

交互流程:

  1. 输入邮箱(用于证书到期提醒):

    text

    Enter email address (used for urgent renewal and security notices)
    (Enter 'c' to cancel): your-email@example.com
  2. 同意服务条款:

    text

    Please read the Terms of Service at
    https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf.
    You must agree in order to register with the ACME server.
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    (A)gree/(C)ancel: A
  3. 是否接收 EFF 邮件(可选):

    text

    Would you be willing to share your email address with the Electronic Frontier
    Foundation, a founding partner of the Let's Encrypt project and the non-profit
    organization that develops Certbot? I consent to sending my email address to EFF.
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    (Y)es/(N)o: N
  4. 是否重定向 HTTP 到 HTTPS:

    text

    Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    1: No redirect - Make no further changes to the webserver configuration.
    2: Redirect - Make all requests redirect to secure HTTPS access.
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Select the appropriate number [1-2] then [enter]:
    • 输入 1:保留 HTTP 和 HTTPS 双通道

    • 输入 2:强制所有 HTTP 跳转 HTTPS(推荐生产环境)

步骤 5:验证申请结果

成功输出:

text

Congratulations! You have successfully enabled https://www.test.com

IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/www.test.com/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/www.test.com/privkey.pem
   Your cert will expire on 2026-12-27.

查看证书:

bash

certbot certificates

验证 Nginx 配置:

bash

nginx -t

浏览器访问:

text

https://www.test.com

确认地址栏有锁图标,证书信息正确。


五、证书信息

项目路径
证书链/etc/letsencrypt/live/www.test.com/fullchain.pem
私钥/etc/letsencrypt/live/www.test.com/privkey.pem
证书文件/etc/letsencrypt/live/www.test.com/cert.pem
中间证书/etc/letsencrypt/live/www.test.com/chain.pem
有效期90 天

六、自动续期

6.1 检查续期任务

Certbot 安装时通常会自动创建续期任务:

bash

# 查看 systemd timer
systemctl list-timers | grep certbot

# 或查看 cron
crontab -l | grep certbot
ls /etc/cron.d/ | grep certbot

预期结果:看到 certbot.timer 或 /etc/cron.d/certbot。

6.2 手动测试续期

bash

certbot renew --dry-run

期望结果:所有证书显示 Congratulations, all renewals succeeded。

6.3 续期后自动重载 Nginx

Certbot 的 --nginx 插件默认会在续期后自动重载 Nginx,无需额外配置。

如果使用 certonly 模式,需要手动配置:

bash

certbot renew --deploy-hook "nginx -s reload"

6.4 手动续期

bash

certbot renew

七、Nginx 配置示例

Certbot --nginx 模式会自动修改配置。以下是申请证书后的典型配置:

7.1 选择 1(不重定向)

nginx

server {
    listen 80;
    listen 443 ssl;
    server_name www.test.com;

    ssl_certificate /etc/letsencrypt/live/www.test.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/www.test.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    location / {
        root /usr/share/nginx/html;
        index index.html;
    }
}

7.2 选择 2(重定向)

nginx

server {
    listen 443 ssl;
    server_name www.test.com;

    ssl_certificate /etc/letsencrypt/live/www.test.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/www.test.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    location / {
        root /usr/share/nginx/html;
        index index.html;
    }
}

server {
    listen 80;
    server_name www.test.com;
    return 301 https://$host$request_uri;
}

八、常见问题

Q1:报错 "Timeout during connect (likely firewall problem)"

原因:Let's Encrypt 无法访问服务器的 80 端口。

排查:

  1. 确认域名解析正确:dig www.test.com +short

  2. 确认 80 端口监听:ss -tlnp | grep :80

  3. 确认系统防火墙放行:firewall-cmd --list-all

  4. 确认云安全组放行 80 端口

  5. 从外部测试:curl -I http://www.test.com

Q2:报错 "conflicting server name"

原因:多个配置文件定义了相同的 server_name。

排查:

bash

grep -rln "www.test.com" /etc/nginx/

找到重复文件,删除或重命名(改成 .bak),然后 nginx -t && nginx -s reload。

Q3:报错 "No package certbot available"(openEuler)

原因:openEuler 默认源没有 Certbot。

解决:使用 pip 安装:

bash

sudo yum install -y python3-pip
sudo pip3 install certbot certbot-nginx

Q4:Certbot 版本过老(1.0.0)

影响:功能可用,但部分新特性缺失。

升级方式:

bash

# Snap 方式(推荐)
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot

# 或 pip 方式
sudo pip3 install --upgrade certbot certbot-nginx

Q5:证书申请成功但浏览器报错

排查:

  1. 确认 Nginx 配置中 ssl_certificate 路径正确

  2. 确认 server_name 与证书域名一致

  3. 执行 nginx -t 和 nginx -s reload

  4. 清除浏览器缓存或用无痕模式测试

Q6:如何删除证书

bash

certbot delete --cert-name www.test.com

Q7:如何为多个域名申请一张证书

bash

certbot --nginx -d www.test.com -d api.test.com -d admin.test.com

所有域名都需解析到本服务器,且 80 端口可达。


九、命令速查

bash

# 安装 Certbot(CentOS)
sudo yum install -y epel-release
sudo yum install -y certbot python2-certbot-nginx

# 安装 Certbot(openEuler)
sudo yum install -y python3-pip
sudo pip3 install certbot certbot-nginx

# 申请证书(自动配置 Nginx)
certbot --nginx -d www.test.com

# 只申请证书(不修改 Nginx)
certbot certonly --nginx -d www.test.com

# 查看所有证书
certbot certificates

# 测试续期
certbot renew --dry-run

# 手动续期
certbot renew

# 删除证书
certbot delete --cert-name www.test.com

# 测试 Nginx 配置
nginx -t

# 重载 Nginx
nginx -s reload

# 检查 80 端口监听
ss -tlnp | grep :80

# 检查防火墙
firewall-cmd --list-all

# 验证域名解析
dig www.test.com +short

十、HTTP-01 vs DNS-01 对比

对比项HTTP-01DNS-01
验证方式80 端口 HTTP 请求DNS TXT 记录
域名解析要求必须指向本服务器无要求
80 端口要求必须对公网开放无要求
自动续期✅ 支持❌ 手动模式不支持
配置复杂度低中
适用场景常规 Web 服务器域名解析不在本机、CDN 场景
Logo

openEuler 是由开放原子开源基金会孵化的全场景开源操作系统项目,面向数字基础设施四大核心场景(服务器、云计算、边缘计算、嵌入式),全面支持 ARM、x86、RISC-V、loongArch、PowerPC、SW-64 等多样性计算架构

更多推荐