如何申请https免费证书并自动续签
·
Certbot 是一款由 EFF(电子前哨基金会)开发的开源工具,用于自动化获取和部署 Let‘s Encrypt 提供的免费 SSL/TLS 证书。Let`s Encrypt 的推出极大地推动了互联网的 HTTPS 化,但其证书有效期较短(90天),对自动化续期提出了较高要求。
标准单域名证书获取与配置
安装 Certbot
# CentOS 7
sudo yum install epel-release
sudo yum install certbot
准备工作
- 域名解析:确保域名已正确解析至服务器 IP。
- 防火墙:开放 HTTP(80) 端口用于验证。
# 使用 firewalld 示例
sudo firewall-cmd --add-port=80/tcp --permanent
sudo firewall-cmd --reload
申请证书
# Nginx(自动配置)
sudo certbot --nginx
# 仅获取证书(不修改配置)
sudo certbot certonly --nginx
sudo certbot certonly --webroot -w /var/www/html -d your-domain.com
证书位置
申请成功后,证书会保存在:
/etc/letsencrypt/live/your-domain.com/
├── cert.pem # 证书文件
├── chain.pem # 中间证书链
├── fullchain.pem # 完整证书链(证书+中间证书)
└── privkey.pem # 私钥文件
注意:务必用你的真实域名替换 your-domain.com,否则会申请失败。
Nginx配置示例
server {
listen 443 ssl;
server_name your-domain.com;
ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;
location / {
proxy_pass http://192.168.0.91:8081/;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto "https";
}
}
续签证书
# 测试续签(不实际更新)
sudo certbot renew --dry-run
# 查看证书信息
sudo certbot certificates
Certbot 会自动创建定时任务:
# 查看自动续签定时任务
sudo systemctl list-timers | grep certbot
sudo cat /etc/cron.d/certbot
# 手动续签所有证书
sudo certbot renew
# 续签后重启 Nginx
sudo certbot renew --post-hook "systemctl reload nginx"
正式自动续期与重载 Nginx
使用 Systemd 定时器是一种可靠的方式。
创建服务文件
/etc/systemd/system/certbot-redownload.service
[Unit]
Description=Force redownload Certbot SSL certificate for specific domain
After=network-online.target
[Service]
Type=oneshot
ExecStart=/usr/bin/certbot certonly --webroot -w /var/www/html -d your-domain.com --register-unsafely-without-email
ExecStartPost=/bin/systemctl reload nginx
创建定时器文件
/etc/systemd/system/certbot-redownload.timer:每月19号,16:56分执行
[Unit]
Description=Run Certbot redownload every 3 months
[Timer]
OnCalendar=*-*-19 16:56:00
Persistent=true
[Install]
WantedBy=timers.target
启用定时器
sudo systemctl enable --now certbot-redownload.timer
阿里云DNS证书续签示例
snap方式安装certbot
以下按照官方推荐的安装方式进行操作,以避免某些系统自带的软件源版本较旧,导致不兼容等问题。
# 安装 snapd
sudo yum install snapd
# 启用 snapd
sudo systemctl enable --now snapd.socket
sudo ln -s /var/lib/snapd/snap /snap
# 安装 core
sudo snap install core
# 安装 certbot
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot
安装 aliyun cli 工具
wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz
tar xzvf aliyun-cli-linux-latest-amd64.tgz
sudo cp aliyun /usr/local/bin
rm aliyun
安装完成后需要配置 凭证信息
aliyun configure set \
--profile AkProfile \
--mode AK \
--access-key-id <yourAccessKeyID> \
--access-key-secret <yourAccessKeySecret> \
--region "cn-hangzhou"
安装 certbot-dns-aliyun 插件
wget https://cdn.jsdelivr.net/gh/justjavac/certbot-dns-aliyun@main/alidns.sh
sudo cp alidns.sh /usr/local/bin
sudo chmod +x /usr/local/bin/alidns.sh
sudo ln -s /usr/local/bin/alidns.sh /usr/local/bin/alidns
rm alidns.sh
申请证书
# RSA 证书:--key-type rsa ,默认是ECDSA 证书。
certbot certonly \
-d *.helloworld.com --manual --preferred-challenges dns --manual-auth-hook "alidns" --manual-cleanup-hook "alidns clean" \
--email xx@qq.com \
--config-dir /etc/ssl \
--key-type rsa
--dry-run # 正式申请时去掉
证书续期
certbot renew --manual --preferred-challenges dns --manual-auth-hook "alidns" --manual-cleanup-hook "alidns clean" --email xx@qq.com --config-dir /etc/ssl --key-type rsa --dry-run
# 如果以上命令没有错误,把 --dry-run 参数去掉。
自动续期
添加定时任务 crontab。
crontab -e
输入
1 9 * * * certbot renew --manual --preferred-challenges dns --manual-auth-hook "alidns" --manual-cleanup-hook "alidns clean" --email xx@qq.com --config-dir /etc/ssl --key-type rsa >> /etc/ssl/renew_log.txt
上面脚本中每天的9点1分会执行一次, --deploy-hook "nginx -s re load" 表示在续期成功后自动重启 nginx。
可以在 /var/spool/cron/目录查看刚才新建的定时任务。
删除证书
sudo certbot delete --cert-name 证书名称 --config-dir /etc/ssl
总结
通过以上步骤,你可以成功申请免费 HTTPS 证书并设置自动续签。这样,你就可以确保你的网站始终保持安全,用户的访问数据也得到保护。
最后一句话,记得定期检查证书的状态和续签是否正常。
更多推荐
所有评论(0)