Certbot 申请证书操作方式(Let‘s Encrypt )
一、适用场景
当域名解析可以指向运行 Certbot 的服务器,且服务器的 80 端口可以从公网访问时,使用 HTTP-01 验证是最简单的方式。
优势:
-
全自动验证,无需手动添加 DNS 记录
-
支持自动续期
-
Certbot 可自动修改 Nginx 配置并部署证书
示例:为 www.test.com 申请证书,域名解析指向运行 Certbot 的服务器。
二、前置条件
| 项目 | 要求 |
|---|---|
| 服务器 | CentOS 7/8、openEuler、RHEL 等 |
| 域名 | www.test.com 的 A 记录指向本服务器公网 IP |
| 端口 | 80 端口对公网开放(安全组 + 系统防火墙均需放行) |
| Nginx | 已安装并运行,配置了 www.test.com 的 server 块 |
| 网络 | 服务器可访问外网 |
三、Certbot 安装方式
方式一:yum 安装(CentOS/RHEL 推荐)
bash
# 1. 安装 EPEL 源 sudo yum install -y epel-release # 2. 安装 Certbot 及 Nginx 插件 sudo yum install -y certbot python2-certbot-nginx # 3. 验证安装 certbot --version
注意:CentOS 8 及以上版本使用
dnf:bash
sudo dnf install -y certbot python3-certbot-nginx
方式二:Snap 安装(官方推荐,版本最新)
bash
# 1. 安装 snapd sudo yum install -y epel-release sudo yum install -y snapd # 2. 启用 snapd sudo systemctl enable --now snapd.socket sudo ln -s /var/lib/snapd/snap /snap # 3. 安装 Certbot sudo snap install --classic certbot # 4. 创建软链接 sudo ln -s /snap/bin/certbot /usr/bin/certbot # 5. 验证 certbot --version
方式三:pip 安装(通用,适合 openEuler)
bash
# 1. 安装 pip sudo yum install -y python3-pip # 2. 安装 Certbot 及 Nginx 插件 sudo pip3 install certbot certbot-nginx # 3. 验证 certbot --version
方式四:openEuler 系统
openEuler 的默认源可能没有 Certbot,推荐使用 pip 方式:
bash
sudo yum install -y python3-pip sudo pip3 install certbot certbot-nginx certbot --version
如果 pip 安装后提示
certbot: command not found,检查 pip 的 bin 目录是否在 PATH 中:bash
export PATH=$PATH:/usr/local/bin
验证安装是否成功
bash
certbot --version
输出版本号(如 certbot 1.0.0 或 certbot 2.x.x)即表示安装成功。
四、操作步骤
步骤 1:确认域名解析
bash
dig www.test.com +short # 或 nslookup www.test.com
期望结果:输出本服务器的公网 IP。
如果解析不对,先去域名服务商处修改 A 记录,等 DNS 生效后再继续。
步骤 2:确认 Nginx 配置
确保 /etc/nginx/conf.d/ 下有 www.test.com 的 server 块,例如 /etc/nginx/conf.d/www.test.com.conf:
nginx
server {
listen 80;
server_name www.test.com;
location / {
root /usr/share/nginx/html;
index index.html;
}
}
验证配置并重载:
bash
nginx -t nginx -s reload
步骤 3:确认 80 端口对公网开放
3.1 检查系统防火墙
bash
# firewalld firewall-cmd --list-all | grep http # 如果没有放行,执行: firewall-cmd --permanent --add-service=http firewall-cmd --reload # 或者使用 iptables iptables -L -n | grep 80
3.2 检查云服务器安全组
登录云控制台(阿里云/腾讯云/华为云等),找到该服务器,检查安全组入方向规则,确保有:
| 协议 | 端口 | 来源 |
|---|---|---|
| TCP | 80 | 0.0.0.0/0 |
| TCP | 443 | 0.0.0.0/0 |
3.3 从外部验证 80 端口可达
在另一台机器上执行:
bash
curl -I http://www.test.com
期望结果:返回 HTTP/1.1 200 OK 或 404(只要有响应就说明端口通)。
如果超时,说明 80 端口被防火墙或安全组拦截,需先解决。
步骤 4:执行 Certbot 申请证书
bash
certbot --nginx -d www.test.com
参数说明:
-
--nginx:使用 Nginx 插件,自动验证 + 自动配置 -
-d www.test.com:指定域名(多个域名可写多个-d)
交互流程:
-
输入邮箱(用于证书到期提醒):
text
Enter email address (used for urgent renewal and security notices) (Enter 'c' to cancel): your-email@example.com
-
同意服务条款:
text
Please read the Terms of Service at https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must agree in order to register with the ACME server. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (A)gree/(C)ancel: A
-
是否接收 EFF 邮件(可选):
text
Would you be willing to share your email address with the Electronic Frontier Foundation, a founding partner of the Let's Encrypt project and the non-profit organization that develops Certbot? I consent to sending my email address to EFF. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: N
-
是否重定向 HTTP 到 HTTPS:
text
Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: No redirect - Make no further changes to the webserver configuration. 2: Redirect - Make all requests redirect to secure HTTPS access. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-2] then [enter]:
-
输入
1:保留 HTTP 和 HTTPS 双通道 -
输入
2:强制所有 HTTP 跳转 HTTPS(推荐生产环境)
-
步骤 5:验证申请结果
成功输出:
text
Congratulations! You have successfully enabled https://www.test.com IMPORTANT NOTES: - Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/www.test.com/fullchain.pem Your key file has been saved at: /etc/letsencrypt/live/www.test.com/privkey.pem Your cert will expire on 2026-12-27.
查看证书:
bash
certbot certificates
验证 Nginx 配置:
bash
nginx -t
浏览器访问:
text
https://www.test.com
确认地址栏有锁图标,证书信息正确。
五、证书信息
| 项目 | 路径 |
|---|---|
| 证书链 | /etc/letsencrypt/live/www.test.com/fullchain.pem |
| 私钥 | /etc/letsencrypt/live/www.test.com/privkey.pem |
| 证书文件 | /etc/letsencrypt/live/www.test.com/cert.pem |
| 中间证书 | /etc/letsencrypt/live/www.test.com/chain.pem |
| 有效期 | 90 天 |
六、自动续期
6.1 检查续期任务
Certbot 安装时通常会自动创建续期任务:
bash
# 查看 systemd timer systemctl list-timers | grep certbot # 或查看 cron crontab -l | grep certbot ls /etc/cron.d/ | grep certbot
预期结果:看到 certbot.timer 或 /etc/cron.d/certbot。
6.2 手动测试续期
bash
certbot renew --dry-run
期望结果:所有证书显示 Congratulations, all renewals succeeded。
6.3 续期后自动重载 Nginx
Certbot 的 --nginx 插件默认会在续期后自动重载 Nginx,无需额外配置。
如果使用 certonly 模式,需要手动配置:
bash
certbot renew --deploy-hook "nginx -s reload"
6.4 手动续期
bash
certbot renew
七、Nginx 配置示例
Certbot --nginx 模式会自动修改配置。以下是申请证书后的典型配置:
7.1 选择 1(不重定向)
nginx
server {
listen 80;
listen 443 ssl;
server_name www.test.com;
ssl_certificate /etc/letsencrypt/live/www.test.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/www.test.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
location / {
root /usr/share/nginx/html;
index index.html;
}
}
7.2 选择 2(重定向)
nginx
server {
listen 443 ssl;
server_name www.test.com;
ssl_certificate /etc/letsencrypt/live/www.test.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/www.test.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
location / {
root /usr/share/nginx/html;
index index.html;
}
}
server {
listen 80;
server_name www.test.com;
return 301 https://$host$request_uri;
}
八、常见问题
Q1:报错 "Timeout during connect (likely firewall problem)"
原因:Let's Encrypt 无法访问服务器的 80 端口。
排查:
-
确认域名解析正确:
dig www.test.com +short -
确认 80 端口监听:
ss -tlnp | grep :80 -
确认系统防火墙放行:
firewall-cmd --list-all -
确认云安全组放行 80 端口
-
从外部测试:
curl -I http://www.test.com
Q2:报错 "conflicting server name"
原因:多个配置文件定义了相同的 server_name。
排查:
bash
grep -rln "www.test.com" /etc/nginx/
找到重复文件,删除或重命名(改成 .bak),然后 nginx -t && nginx -s reload。
Q3:报错 "No package certbot available"(openEuler)
原因:openEuler 默认源没有 Certbot。
解决:使用 pip 安装:
bash
sudo yum install -y python3-pip sudo pip3 install certbot certbot-nginx
Q4:Certbot 版本过老(1.0.0)
影响:功能可用,但部分新特性缺失。
升级方式:
bash
# Snap 方式(推荐) sudo snap install --classic certbot sudo ln -s /snap/bin/certbot /usr/bin/certbot # 或 pip 方式 sudo pip3 install --upgrade certbot certbot-nginx
Q5:证书申请成功但浏览器报错
排查:
-
确认 Nginx 配置中
ssl_certificate路径正确 -
确认
server_name与证书域名一致 -
执行
nginx -t和nginx -s reload -
清除浏览器缓存或用无痕模式测试
Q6:如何删除证书
bash
certbot delete --cert-name www.test.com
Q7:如何为多个域名申请一张证书
bash
certbot --nginx -d www.test.com -d api.test.com -d admin.test.com
所有域名都需解析到本服务器,且 80 端口可达。
九、命令速查
bash
# 安装 Certbot(CentOS) sudo yum install -y epel-release sudo yum install -y certbot python2-certbot-nginx # 安装 Certbot(openEuler) sudo yum install -y python3-pip sudo pip3 install certbot certbot-nginx # 申请证书(自动配置 Nginx) certbot --nginx -d www.test.com # 只申请证书(不修改 Nginx) certbot certonly --nginx -d www.test.com # 查看所有证书 certbot certificates # 测试续期 certbot renew --dry-run # 手动续期 certbot renew # 删除证书 certbot delete --cert-name www.test.com # 测试 Nginx 配置 nginx -t # 重载 Nginx nginx -s reload # 检查 80 端口监听 ss -tlnp | grep :80 # 检查防火墙 firewall-cmd --list-all # 验证域名解析 dig www.test.com +short
十、HTTP-01 vs DNS-01 对比
| 对比项 | HTTP-01 | DNS-01 |
|---|---|---|
| 验证方式 | 80 端口 HTTP 请求 | DNS TXT 记录 |
| 域名解析要求 | 必须指向本服务器 | 无要求 |
| 80 端口要求 | 必须对公网开放 | 无要求 |
| 自动续期 | ✅ 支持 | ❌ 手动模式不支持 |
| 配置复杂度 | 低 | 中 |
| 适用场景 | 常规 Web 服务器 | 域名解析不在本机、CDN 场景 |
openEuler 是由开放原子开源基金会孵化的全场景开源操作系统项目,面向数字基础设施四大核心场景(服务器、云计算、边缘计算、嵌入式),全面支持 ARM、x86、RISC-V、loongArch、PowerPC、SW-64 等多样性计算架构
更多推荐

所有评论(0)