📋 目录
没有 SSL 证书的网站会被浏览器标记为"不安全",在 Google 搜索排名中也会受到惩罚。Let's Encrypt 提供完全免费的 SSL 证书,而 Certbot 可在您的 VPS Nginx 服务器上自动完成证书的安装和续期,无需任何费用。
1. Certbot 与 Let's Encrypt 简介
Let's Encrypt 是由互联网安全研究组(ISRG)运营的非营利性证书颁发机构(CA),获得 EFF、Mozilla、Cisco 和 Akamai 的支持。它使用 ACME 协议(自动化证书管理环境)免费颁发 SSL/TLS 证书。
Certbot 是电子前哨基金会(EFF)开发的官方 ACME 客户端,与 Let's Encrypt 深度集成,可以:
- 自动申请新证书
- 自动修改 Nginx 或 Apache 配置以启用 HTTPS
- 在证书过期前自动续期
- 同时管理多个域名的证书
2. 安装前提条件
| 要求 | 详情 | 备注 |
|---|---|---|
| 操作系统 | Ubuntu 20.04/22.04/24.04 或 Debian 11/12 | 推荐 Ubuntu LTS |
| Web 服务器 | Nginx 已安装并运行 | 版本 1.14+ |
| 域名 | A 记录已指向 VPS IP | 等待 DNS 生效 |
| 端口 | 80(HTTP)和 443(HTTPS)已在防火墙开放 | 两个端口都需要 |
| 权限 | root 或 sudo 用户 | – |
验证域名 DNS 已指向您的 VPS:
dig +short example.com A
# 应返回您的 VPS IP 地址
3. 在 Ubuntu/Debian 上安装 Certbot
推荐通过 snap 安装,可确保始终获得最新版本:
# 更新软件包列表
sudo apt update
# 安装 snap(如未安装)
sudo apt install snapd -y
# 安装并更新 core snap
sudo snap install core
sudo snap refresh core
# 安装 Certbot
sudo snap install --classic certbot
# 创建符号链接以全局使用
sudo ln -s /snap/bin/certbot /usr/bin/certbot
验证安装:
certbot --version
# certbot 2.x.x
apt install certbot 安装,请先卸载,再通过 snap 重新安装,以确保版本最新。
4. 申请证书前的 Nginx 配置
Certbot 需要 Nginx 识别您的域名 server_name,请先检查配置文件:
sudo nano /etc/nginx/sites-available/example.com
最基础的 Nginx 配置(SSL 安装前):
server {
listen 80;
server_name example.com www.example.com;
root /var/www/example.com;
index index.html index.php;
location / {
try_files $uri $uri/ =404;
}
}
启用配置并重载 Nginx:
sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx
开放防火墙端口:
sudo ufw allow 'Nginx Full'
sudo ufw status
5. 申请 SSL 证书
申请证书并让 Certbot 自动修改 Nginx 配置:
sudo certbot --nginx -d example.com -d www.example.com
Certbot 会询问以下信息:
- 电子邮件地址:用于接收证书到期提醒
- 服务条款:按 A 同意
- 是否分享邮件给 EFF:Y 或 N 均可
- HTTP 重定向到 HTTPS:按 2 重定向所有流量
Certbot 修改 Nginx 配置后,文件大致如下:
server {
listen 443 ssl;
server_name example.com www.example.com;
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
root /var/www/example.com;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}
server {
listen 80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}
6. 验证 SSL 与 HTTPS 跳转
查看已安装的证书:
sudo certbot certificates
测试 HTTPS 跳转:
curl -I http://example.com
# 期望返回:HTTP/1.1 301 Moved Permanently
# Location: https://example.com/
curl -I https://example.com
# 期望返回:HTTP/2 200
通过 SSL Labs(ssllabs.com/ssltest)测试 SSL 质量。正确配置的 Let's Encrypt + Nginx 通常可获得 A 级评分。
7. 配置自动续期
通过 snap 安装的 Certbot 会自动创建 systemd 定时任务,验证状态:
sudo systemctl status snap.certbot.renew.timer
模拟测试自动续期(不影响正式证书):
sudo certbot renew --dry-run
也可使用 cron 替代 systemd:
# 编辑 crontab
sudo crontab -e
# 添加以下行(每天 00:00 和 12:00 执行)
0 0,12 * * * certbot renew --quiet --post-hook "systemctl reload nginx"
--post-hook "systemctl reload nginx" 可在续期成功后立即重载 Nginx,新证书立即生效,无需等待服务器重启。
8. DNS 验证申请通配符证书
通配符证书(*.example.com)可覆盖所有子域名,但需要使用 DNS-01 验证:
sudo certbot certonly --manual --preferred-challenges dns \
-d "example.com" -d "*.example.com"
Certbot 会要求在 DNS 中添加 TXT 记录:
- 添加 DNS TXT 记录:
_acme-challenge.example.com→ Certbot 提供的值 - 等待 DNS 生效(5–30 分钟)
- 按 Enter 继续验证
9. 常见问题排查
错误:连接被拒绝 / 80 端口关闭
sudo ufw allow 80
sudo ufw allow 443
sudo ufw reload
错误:DNS 未解析
等待 DNS 生效后再试,可用以下命令测试:
nslookup example.com 8.8.8.8
错误:证书申请次数过多
Let's Encrypt 限制每个域名每周最多 5 张证书。测试时使用 --staging 参数:
sudo certbot --nginx -d example.com --staging
证书已过期但未自动续期
# 查看日志
sudo journalctl -u snap.certbot.renew.service
# 手动强制续期
sudo certbot renew --force-renewal
安装 SSL 后 Nginx 返回 404
检查 Nginx 配置中的 root 路径是否正确,以及 index.html 文件是否存在:
sudo nginx -t
sudo systemctl reload nginx
常见问题(FAQ)
总结
在 VPS Nginx 上使用 Certbot 安装 Let's Encrypt SSL 并不复杂。核心步骤:通过 snap 安装 Certbot → 配置 Nginx server_name → 运行 certbot --nginx → 用 --dry-run 测试自动续期。完成后,您的网站将拥有永久免费的 HTTPS,且自动续期无需人工干预。