ubuntu22.04使用certbot实现证书自动续期
qinsz 6/20/2025 ubuntucertbot自动续期
# 1. 准备好server模块
在nginx中将需要使用ssl证书的server模块提前进行配置
certbot是根据server模块的server_name来进行匹配的
例如创建一个配置/etc/nginx/conf.d/fastgpt.conf
server {
listen 80;
server_name fastgpt.openedu.tech;
# HTTP 跳转到 HTTPS
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name fastgpt.openedu.tech;
location / {
proxy_pass http://localhost:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection 'upgrade';
proxy_set_header Host $host;
proxy_cache_bypass $http_upgrade;
#为支持 HTTP 流(如 SSE 或聊天流式响应)
proxy_buffering off;
}
}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
检查配置并重启nginx
sudo nginx -t
sudo systemctl restart nginx
1
2
2
# 2. 安装certbot和python3-certbot-nginx
sudo apt update
sudo apt install certbot python3-certbot-nginx
1
2
2
# 3. 使用certbot申请ssl证书
sudo certbot --nginx -d fastgpt.openedu.tech
1
在申请ssl证书时需要指定域名,certbot会在所有的server中去寻找server_name与此处一致的配置文件
安装过程中会让你输入任意邮箱以及若干次确认
完成后会出现如下信息:
Deploying certificate
Successfully deployed certificate for fastgpt.openedu.tech to /etc/nginx/conf.d/fastgpt.conf
Congratulations! You have successfully enabled HTTPS on https://fastgpt.openedu.tech
1
2
3
2
3
查看fastgpt.openedu.conf文件,可以看到certbot已经对其进行了修改, 多出了'managed by Certbot'的内容':
server {
if ($host = fastgpt.openedu.tech) {
return 301 https://$host$request_uri;
} # managed by Certbot
listen 80;
server_name fastgpt.openedu.tech;
# HTTP 跳转到 HTTPS
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name fastgpt.openedu.tech;
location / {
proxy_pass http://localhost:3000;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection 'upgrade';
proxy_set_header Host $host;
proxy_cache_bypass $http_upgrade;
#为支持 HTTP 流(如 SSE 或聊天流式响应)
proxy_buffering off;
}
ssl_certificate /etc/letsencrypt/live/fastgpt.openedu.tech/fullchain.pem; # managed by Certbot
ssl_certificate_key /etc/letsencrypt/live/fastgpt.openedu.tech/privkey.pem; # managed by Certbot
}
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
# 4. 查看定时任务
certbot会以定时任务的方式进行ssl的续期。
在ubuntu22.04下。该定时任务文件路径为/etc/cron.d/certbot,内容大致为:
# /etc/cron.d/certbot: crontab entries for the certbot package
#
# Upstream recommends attempting renewal twice a day
#
# Eventually, this will be an opportunity to validate certificates
# haven't been revoked, etc. Renewal will only occur if expiration
# is within 30 days.
#
# Important Note! This cronjob will NOT be executed if you are
# running systemd as your init system. If you are running systemd,
# the cronjob.timer function takes precedence over this cronjob. For
# more details, see the systemd.timer manpage, or use systemctl show
# certbot.timer.
SHELL=/bin/sh
PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin
0 */12 * * * root test -x /usr/bin/certbot -a \! -d /run/systemd/system && perl -e 'sleep int(rand(43200))' && certbot -q renew
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
# 5. 重启nginx脚本
certbot会定时重新申请ssl,但是并不会重启nginx,而新证书需要重启nginx后才能生效
因此需要配置重启脚本。同时,certbot提供了一个特定文件夹,在certbot自动申请ssl证书的各种时机自动运行文件夹中的脚本
该文件夹路径为/etc/letsencrypt/renewal-hooks,下面有3个子文件件:
pre: 续期前执行脚本deploy: 续期成功后执行(💡放nginx的reload脚本)post: 续期完成后总是执行
因此在/etc/letsencrypt/renewal-hooks/deploy中创建一份nginx-reload.sh脚本:
#!/bin/bash
echo "[Certbot Hook]Running as: $(whoami). 重启 nginx..."
systemctl reload nginx
1
2
3
2
3
保存该脚本后,确保其拥有可执行权限:
sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/nginx-reload.sh
1
# 6. 日志
certbot的执行日志都记录在/var/log/letsencrypt/letsencrypt.log
# 7. 其它指令
# (1)尝试续期
sudo certbot renew
1
- 实际检查所有证书是否“即将过期”(通常是30天内);
- 对于符合续期条件的证书,真的去联系 Let's Encrypt 正式服务器进行续期;
- 会消耗 Let's Encrypt 的“签发次数额度”
- 续期成功会触发
renewal-hooks/deploy中的脚本
# (2)模拟续期
sudo certbot renew --dry-run
1
- 会连接 Let's Encrypt 的 测试服务器(staging environment)
- 模拟续期整个流程,但 不真正更改任何本地证书文件;
- 不消耗正式额度;
renewal-hooks/deploy中的脚本不会执行;- 主要用于测试配置是否正常、hook 是否有效、端口是否放通等
# (3)强制续期
sudo certbot renew --force-renewal
1
- 直接进行证书续期
# (4)签发额度
- 每 7 天同一域名(完全一样的域名集)最多5次证书签发
- 每周最多50个证书
- 每小时最多 5 次验证失败
- 每 3 小时最多 10 个账户
- 如果证书还有30天以上,renew不会续期(所以不会触发配额)
- 签发额度没有具体的位置可以查看,可以通过网站 crt.sh 来查看域名已签发的证书来进行估算
- 单域名: https://crt.sh/?q=fastgpt.openedu.tech
- 主域名: https://crt.sh/?q=openedu.tech