VPS

VPS Nginx 使用 Certbot 自动安装 Let's Encrypt SSL 证书完整教程

📅 2026年10月9日 ⏱ 阅读约12分钟 🔒 Let's Encrypt · Certbot · Nginx · Ubuntu
VPS Nginx 使用 Certbot 自动安装 Let's Encrypt SSL 证书

没有 SSL 证书的网站会被浏览器标记为"不安全",在 Google 搜索排名中也会受到惩罚。Let's Encrypt 提供完全免费的 SSL 证书,而 Certbot 可在您的 VPS Nginx 服务器上自动完成证书的安装和续期,无需任何费用。

1. Certbot 与 Let's Encrypt 简介

Let's Encrypt 是由互联网安全研究组(ISRG)运营的非营利性证书颁发机构(CA),获得 EFF、Mozilla、Cisco 和 Akamai 的支持。它使用 ACME 协议(自动化证书管理环境)免费颁发 SSL/TLS 证书。

Certbot 是电子前哨基金会(EFF)开发的官方 ACME 客户端,与 Let's Encrypt 深度集成,可以:

💡 重要提示:Let's Encrypt 证书有效期为 90 天,但 Certbot 会每 60 天自动续期,配置完成后无需任何手动操作。

2. 安装前提条件

要求详情备注
操作系统Ubuntu 20.04/22.04/24.04 或 Debian 11/12推荐 Ubuntu LTS
Web 服务器Nginx 已安装并运行版本 1.14+
域名A 记录已指向 VPS IP等待 DNS 生效
端口80(HTTP)和 443(HTTPS)已在防火墙开放两个端口都需要
权限root 或 sudo 用户–

验证域名 DNS 已指向您的 VPS:

dig +short example.com A
# 应返回您的 VPS IP 地址

3. 在 Ubuntu/Debian 上安装 Certbot

推荐通过 snap 安装,可确保始终获得最新版本:

# 更新软件包列表
sudo apt update

# 安装 snap(如未安装)
sudo apt install snapd -y

# 安装并更新 core snap
sudo snap install core
sudo snap refresh core

# 安装 Certbot
sudo snap install --classic certbot

# 创建符号链接以全局使用
sudo ln -s /snap/bin/certbot /usr/bin/certbot

验证安装:

certbot --version
# certbot 2.x.x
⚠️ 注意:如果之前通过 apt install certbot 安装,请先卸载,再通过 snap 重新安装,以确保版本最新。

4. 申请证书前的 Nginx 配置

Certbot 需要 Nginx 识别您的域名 server_name,请先检查配置文件:

sudo nano /etc/nginx/sites-available/example.com

最基础的 Nginx 配置(SSL 安装前):

server {
    listen 80;
    server_name example.com www.example.com;

    root /var/www/example.com;
    index index.html index.php;

    location / {
        try_files $uri $uri/ =404;
    }
}

启用配置并重载 Nginx:

sudo ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx

开放防火墙端口:

sudo ufw allow 'Nginx Full'
sudo ufw status

5. 申请 SSL 证书

申请证书并让 Certbot 自动修改 Nginx 配置:

sudo certbot --nginx -d example.com -d www.example.com

Certbot 会询问以下信息:

  1. 电子邮件地址:用于接收证书到期提醒
  2. 服务条款:按 A 同意
  3. 是否分享邮件给 EFF:Y 或 N 均可
  4. HTTP 重定向到 HTTPS:按 2 重定向所有流量

Certbot 修改 Nginx 配置后,文件大致如下:

server {
    listen 443 ssl;
    server_name example.com www.example.com;

    ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;

    root /var/www/example.com;
    index index.html;

    location / {
        try_files $uri $uri/ =404;
    }
}

server {
    listen 80;
    server_name example.com www.example.com;
    return 301 https://$host$request_uri;
}

6. 验证 SSL 与 HTTPS 跳转

查看已安装的证书:

sudo certbot certificates

测试 HTTPS 跳转:

curl -I http://example.com
# 期望返回:HTTP/1.1 301 Moved Permanently
# Location: https://example.com/

curl -I https://example.com
# 期望返回:HTTP/2 200

通过 SSL Labs(ssllabs.com/ssltest)测试 SSL 质量。正确配置的 Let's Encrypt + Nginx 通常可获得 A 级评分。

✅ 浏览器验证:在地址栏看到 🔒 锁形图标表示 SSL 已正常工作。

7. 配置自动续期

通过 snap 安装的 Certbot 会自动创建 systemd 定时任务,验证状态:

sudo systemctl status snap.certbot.renew.timer

模拟测试自动续期(不影响正式证书):

sudo certbot renew --dry-run

也可使用 cron 替代 systemd:

# 编辑 crontab
sudo crontab -e

# 添加以下行(每天 00:00 和 12:00 执行)
0 0,12 * * * certbot renew --quiet --post-hook "systemctl reload nginx"
💡 提示:加入 --post-hook "systemctl reload nginx" 可在续期成功后立即重载 Nginx,新证书立即生效,无需等待服务器重启。

8. DNS 验证申请通配符证书

通配符证书(*.example.com)可覆盖所有子域名,但需要使用 DNS-01 验证:

sudo certbot certonly --manual --preferred-challenges dns \
  -d "example.com" -d "*.example.com"

Certbot 会要求在 DNS 中添加 TXT 记录:

  1. 添加 DNS TXT 记录:_acme-challenge.example.com → Certbot 提供的值
  2. 等待 DNS 生效(5–30 分钟)
  3. 按 Enter 继续验证
⚠️ 通配符证书限制:DNS 验证每次续期(每 60 天)都需要手动操作。如需全自动续期,需使用支持您 DNS 服务商的 Certbot 插件(如 Cloudflare、Route53)。

9. 常见问题排查

错误:连接被拒绝 / 80 端口关闭

sudo ufw allow 80
sudo ufw allow 443
sudo ufw reload

错误:DNS 未解析

等待 DNS 生效后再试,可用以下命令测试:

nslookup example.com 8.8.8.8

错误:证书申请次数过多

Let's Encrypt 限制每个域名每周最多 5 张证书。测试时使用 --staging 参数:

sudo certbot --nginx -d example.com --staging

证书已过期但未自动续期

# 查看日志
sudo journalctl -u snap.certbot.renew.service

# 手动强制续期
sudo certbot renew --force-renewal

安装 SSL 后 Nginx 返回 404

检查 Nginx 配置中的 root 路径是否正确,以及 index.html 文件是否存在:

sudo nginx -t
sudo systemctl reload nginx

常见问题(FAQ)

Certbot 是什么?与 Let's Encrypt 有什么区别?
Let's Encrypt 是由 ISRG 运营的免费证书颁发机构(CA)。Certbot 是 EFF 开发的 ACME 客户端,可在服务器上自动获取和续期 Let's Encrypt 颁发的 SSL 证书。
Let's Encrypt 证书有效期多长?需要手动续期吗?
Let's Encrypt 证书有效期为 90 天。Certbot 会通过 systemd 定时任务或 cron 每 60 天自动续期,初次配置完成后无需手动操作。
Certbot 同时支持 Nginx 和 Apache 吗?
支持。Nginx 使用 certbot --nginx,Apache 使用 certbot --apache,各自的插件会自动修改 Web 服务器配置。本文主要介绍 Nginx 的配置方法。
Certbot 需要开放哪些端口?
需要开放 80 端口(HTTP,ACME 验证用)和 443 端口(HTTPS)。运行 Certbot 前请确保防火墙(UFW 或 iptables)已放行这两个端口。
Certbot 支持通配符 SSL 证书吗?
支持,但通配符证书需要使用 DNS-01 验证。需要有域名 DNS 的编辑权限,部分 DNS 服务商提供 Certbot 插件,可实现全自动通配符证书续期。
如何验证自动续期是否正常工作?
运行 sudo certbot renew --dry-run 模拟续期过程,不会影响正式证书。若命令执行完成且无报错,说明自动续期配置正确。

总结

在 VPS Nginx 上使用 Certbot 安装 Let's Encrypt SSL 并不复杂。核心步骤:通过 snap 安装 Certbot → 配置 Nginx server_name → 运行 certbot --nginx → 用 --dry-run 测试自动续期。完成后,您的网站将拥有永久免费的 HTTPS,且自动续期无需人工干预。

需要一台开箱即用的 VPS?月付仅需 500 泰铢起

AsiaGB.com 提供泰国、新加坡和 OVHcloud 俄勒冈 (US-WEST-OR) VPS,SSD 存储,Uptime 99%。

查看 VPS 方案 →