Certbot 是一款由 EFF(电子前哨基金会)开发的开源工具,用于自动化获取和部署 Let‘s Encrypt 提供的免费 SSL/TLS 证书。Let`s Encrypt 的推出极大地推动了互联网的 HTTPS 化,但其证书有效期较短(90天),对自动化续期提出了较高要求。

标准单域名证书获取与配置

安装 Certbot

# CentOS 7
sudo yum install epel-release
sudo yum install certbot

准备工作

  • 域名解析:确保域名已正确解析至服务器 IP。
  • 防火墙:开放 HTTP(80) 端口用于验证。
# 使用 firewalld 示例
sudo firewall-cmd --add-port=80/tcp --permanent
sudo firewall-cmd --reload

申请证书

# Nginx(自动配置)
sudo certbot --nginx

# 仅获取证书(不修改配置)
sudo certbot certonly --nginx
sudo certbot certonly --webroot -w /var/www/html -d your-domain.com

证书位置

申请成功后,证书会保存在:

/etc/letsencrypt/live/your-domain.com/
├── cert.pem      # 证书文件
├── chain.pem     # 中间证书链
├── fullchain.pem # 完整证书链(证书+中间证书)
└── privkey.pem   # 私钥文件

注意:务必用你的真实域名替换 your-domain.com,否则会申请失败。

Nginx配置示例

server {
    listen 443 ssl;
    server_name your-domain.com;

    ssl_certificate /etc/letsencrypt/live/your-domain.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/your-domain.com/privkey.pem;

    location / {
        proxy_pass http://192.168.0.91:8081/;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto "https";
    }
}

续签证书

# 测试续签(不实际更新)
sudo certbot renew --dry-run

# 查看证书信息
sudo certbot certificates

Certbot 会自动创建定时任务:

# 查看自动续签定时任务
sudo systemctl list-timers | grep certbot
sudo cat /etc/cron.d/certbot

# 手动续签所有证书
sudo certbot renew

# 续签后重启 Nginx
sudo certbot renew --post-hook "systemctl reload nginx"

正式自动续期与重载 Nginx

使用 Systemd 定时器是一种可靠的方式。

创建服务文件

/etc/systemd/system/certbot-redownload.service

[Unit]
Description=Force redownload Certbot SSL certificate for specific domain
After=network-online.target

[Service]
Type=oneshot
ExecStart=/usr/bin/certbot certonly --webroot -w /var/www/html -d your-domain.com --register-unsafely-without-email
ExecStartPost=/bin/systemctl reload nginx

创建定时器文件

/etc/systemd/system/certbot-redownload.timer:每月19号,16:56分执行

[Unit]
Description=Run Certbot redownload every 3 months

[Timer]
OnCalendar=*-*-19 16:56:00
Persistent=true

[Install]
WantedBy=timers.target

启用定时器

sudo systemctl enable --now certbot-redownload.timer

阿里云DNS证书续签示例

snap方式安装certbot

以下按照官方推荐的安装方式进行操作,以避免某些系统自带的软件源版本较旧,导致不兼容等问题。

# 安装 snapd
sudo yum install snapd

# 启用 snapd
sudo systemctl enable --now snapd.socket
sudo ln -s /var/lib/snapd/snap /snap

# 安装 core
sudo snap install core

# 安装 certbot
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot

安装 aliyun cli 工具

wget https://aliyuncli.alicdn.com/aliyun-cli-linux-latest-amd64.tgz
tar xzvf aliyun-cli-linux-latest-amd64.tgz
sudo cp aliyun /usr/local/bin
rm aliyun

安装完成后需要配置 凭证信息

aliyun configure set \
  --profile AkProfile \
  --mode AK \
  --access-key-id <yourAccessKeyID> \
  --access-key-secret <yourAccessKeySecret> \
  --region "cn-hangzhou"

安装 certbot-dns-aliyun 插件

wget https://cdn.jsdelivr.net/gh/justjavac/certbot-dns-aliyun@main/alidns.sh
sudo cp alidns.sh /usr/local/bin
sudo chmod +x /usr/local/bin/alidns.sh
sudo ln -s /usr/local/bin/alidns.sh /usr/local/bin/alidns
rm alidns.sh

申请证书

# RSA 证书:--key-type rsa ,默认是ECDSA 证书。
certbot certonly \
-d *.helloworld.com --manual --preferred-challenges dns --manual-auth-hook "alidns" --manual-cleanup-hook "alidns clean" \
--email xx@qq.com \
--config-dir /etc/ssl \
--key-type rsa
--dry-run  # 正式申请时去掉

证书续期

certbot renew --manual --preferred-challenges dns --manual-auth-hook "alidns" --manual-cleanup-hook "alidns clean" --email xx@qq.com --config-dir /etc/ssl --key-type rsa --dry-run

# 如果以上命令没有错误,把 --dry-run 参数去掉。

自动续期

添加定时任务 crontab。

crontab -e
输入 
1 9 * * * certbot renew --manual --preferred-challenges dns --manual-auth-hook "alidns" --manual-cleanup-hook "alidns clean" --email xx@qq.com --config-dir /etc/ssl  --key-type rsa  >> /etc/ssl/renew_log.txt

上面脚本中每天的9点1分会执行一次, --deploy-hook "nginx -s re load" 表示在续期成功后自动重启 nginx。

可以在 /var/spool/cron/目录查看刚才新建的定时任务。

删除证书

sudo certbot delete --cert-name 证书名称 --config-dir /etc/ssl

总结

通过以上步骤,你可以成功申请免费 HTTPS 证书并设置自动续签。这样,你就可以确保你的网站始终保持安全,用户的访问数据也得到保护。

最后一句话,记得定期检查证书的状态和续签是否正常。

Logo

北京人形旗下天工造物具身智能开源社区,聚焦具身天工与慧思开物两大平台

更多推荐