ubuntu22.04使用certbot实现证书自动续期

6/20/2025 ubuntucertbot自动续期

# 1. 准备好server模块

在nginx中将需要使用ssl证书的server模块提前进行配置
certbot是根据server模块的server_name来进行匹配的
例如创建一个配置/etc/nginx/conf.d/fastgpt.conf

server {
    listen 80;
    server_name fastgpt.openedu.tech;

    # HTTP 跳转到 HTTPS
    return 301 https://$host$request_uri;
}
server {
    listen 443 ssl;
    server_name fastgpt.openedu.tech;


    location / {
        proxy_pass http://localhost:3000;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;

        #为支持 HTTP 流(如 SSE 或聊天流式响应)
        proxy_buffering off;
    }
}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24

检查配置并重启nginx

sudo nginx -t
sudo systemctl restart nginx
1
2

# 2. 安装certbot和python3-certbot-nginx

sudo apt update
sudo apt install certbot python3-certbot-nginx
1
2

# 3. 使用certbot申请ssl证书

sudo certbot --nginx -d fastgpt.openedu.tech
1

在申请ssl证书时需要指定域名,certbot会在所有的server中去寻找server_name与此处一致的配置文件
安装过程中会让你输入任意邮箱以及若干次确认
完成后会出现如下信息:

Deploying certificate
Successfully deployed certificate for fastgpt.openedu.tech to /etc/nginx/conf.d/fastgpt.conf
Congratulations! You have successfully enabled HTTPS on https://fastgpt.openedu.tech
1
2
3

查看fastgpt.openedu.conf文件,可以看到certbot已经对其进行了修改, 多出了'managed by Certbot'的内容':

server {
    if ($host = fastgpt.openedu.tech) {
        return 301 https://$host$request_uri;
    } # managed by Certbot


    listen 80;
    server_name fastgpt.openedu.tech;

    # HTTP 跳转到 HTTPS
    return 301 https://$host$request_uri;


}

server {
    listen 443 ssl;
    server_name fastgpt.openedu.tech;


    location / {
        proxy_pass http://localhost:3000;
        proxy_http_version 1.1;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection 'upgrade';
        proxy_set_header Host $host;
        proxy_cache_bypass $http_upgrade;

        #为支持 HTTP 流(如 SSE 或聊天流式响应)
        proxy_buffering off;
    }

    ssl_certificate /etc/letsencrypt/live/fastgpt.openedu.tech/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/fastgpt.openedu.tech/privkey.pem; # managed by Certbot
}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35

# 4. 查看定时任务

certbot会以定时任务的方式进行ssl的续期。
在ubuntu22.04下。该定时任务文件路径为/etc/cron.d/certbot,内容大致为:

# /etc/cron.d/certbot: crontab entries for the certbot package
#
# Upstream recommends attempting renewal twice a day
#
# Eventually, this will be an opportunity to validate certificates
# haven't been revoked, etc.  Renewal will only occur if expiration
# is within 30 days.
#
# Important Note!  This cronjob will NOT be executed if you are
# running systemd as your init system.  If you are running systemd,
# the cronjob.timer function takes precedence over this cronjob.  For
# more details, see the systemd.timer manpage, or use systemctl show
# certbot.timer.
SHELL=/bin/sh
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin

0 */12 * * * root test -x /usr/bin/certbot -a \! -d /run/systemd/system && perl -e 'sleep int(rand(43200))' && certbot -q renew
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17

# 5. 重启nginx脚本

certbot会定时重新申请ssl,但是并不会重启nginx,而新证书需要重启nginx后才能生效
因此需要配置重启脚本。同时,certbot提供了一个特定文件夹,在certbot自动申请ssl证书的各种时机自动运行文件夹中的脚本
该文件夹路径为/etc/letsencrypt/renewal-hooks,下面有3个子文件件:

  • pre: 续期前执行脚本
  • deploy: 续期成功后执行(💡放nginx的reload脚本)
  • post: 续期完成后总是执行

因此在/etc/letsencrypt/renewal-hooks/deploy中创建一份nginx-reload.sh脚本:

#!/bin/bash
echo "[Certbot Hook]Running as: $(whoami). 重启 nginx..."
systemctl reload nginx
1
2
3

保存该脚本后,确保其拥有可执行权限:

sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/nginx-reload.sh
1

# 6. 日志

certbot的执行日志都记录在/var/log/letsencrypt/letsencrypt.log

# 7. 其它指令

# (1)尝试续期

sudo certbot renew
1
  • 实际检查所有证书是否“即将过期”(通常是30天内);
  • 对于符合续期条件的证书,真的去联系 Let's Encrypt 正式服务器进行续期;
  • 会消耗 Let's Encrypt 的“签发次数额度”
  • 续期成功会触发renewal-hooks/deploy中的脚本

# (2)模拟续期

sudo certbot renew --dry-run
1
  • 会连接 Let's Encrypt 的 测试服务器(staging environment)
  • 模拟续期整个流程,但 不真正更改任何本地证书文件;
  • 不消耗正式额度;
  • renewal-hooks/deploy中的脚本不会执行;
  • 主要用于测试配置是否正常、hook 是否有效、端口是否放通等

# (3)强制续期

sudo certbot renew --force-renewal
1
  • 直接进行证书续期

# (4)签发额度

  • 每 7 天同一域名(完全一样的域名集)最多5次证书签发
  • 每周最多50个证书
  • 每小时最多 5 次验证失败
  • 每 3 小时最多 10 个账户
  • 如果证书还有30天以上,renew不会续期(所以不会触发配额)
  • 签发额度没有具体的位置可以查看,可以通过网站 crt.sh 来查看域名已签发的证书来进行估算
    • 单域名: https://crt.sh/?q=fastgpt.openedu.tech
    • 主域名: https://crt.sh/?q=openedu.tech
Last Updated: 10/9/2025, 8:15:34 PM