帮助中心

服务器、网络和账户的分步教程。

Linux 服务器

网站免费 SSL 证书教程:在 Linux 用 Nginx 与 Let's Encrypt(Certbot)搭建 HTTPS 网站

网站免费 SSL 证书教程:在 Linux 用 Nginx 与 Let's Encrypt(Certbot)搭建 HTTPS 网站

公开网站都应该以 HTTPS 提供服务,而 Let's Encrypt 的免费 SSL 证书让这件事变得很简单。本文说明如何在 JUSTG 云服务器或独立服务器上以 Nginx 搭建网站、用 certbot 申请 Let's Encrypt 证书、确认自动续期正常,并强制使用 HTTPS。命令分别提供 Debian/Ubuntu 与 CentOS/Rocky Linux/AlmaLinux 版本。示例域名为 example.com,服务器 IP 为 203.0.113.10,请替换成您自己的域名和 IP。

步骤 1:将域名指向 JUSTG 服务器(A 与 AAAA 记录)

在域名注册商或 DNS 服务商创建 A 记录,让主域名与 www 指向服务器的 IPv4。JUSTG 云服务器也免费提供 IPv6;只有在服务器已配置 IPv6 且 Nginx 在 IPv6 上监听时,才添加 AAAA 记录。请等记录生效后再申请证书,因为 Let's Encrypt 会从互联网验证域名。

# A    example.com       -> 203.0.113.10
# A    www.example.com   -> 203.0.113.10
# AAAA example.com       -> 2001:db8::10   (optional, only if IPv6 is configured)

# check from the server (Debian/Ubuntu: apt install -y dnsutils, Rocky: dnf install -y bind-utils)
dig +short example.com A
dig +short www.example.com A
dig +short example.com AAAA

步骤 2:在 Debian 或 Ubuntu 安装 Nginx 与 certbot

certbot 的 Nginx 插件可以自动修改 Nginx 设置。从默认软件源安装:

apt update
apt install -y nginx certbot python3-certbot-nginx
systemctl enable --now nginx
ufw allow 'Nginx Full'     # if UFW is enabled

步骤 3:在 Rocky Linux、AlmaLinux 或 CentOS 安装 Nginx 与 certbot

RHEL 系统的 certbot 来自 EPEL 软件源,同时要在 firewalld 开放 HTTP 与 HTTPS:

dnf install -y epel-release
dnf install -y nginx certbot python3-certbot-nginx
systemctl enable --now nginx
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reload

步骤 4:创建网站与 Nginx server 块

创建网站根目录与测试页面。在启用 SELinux 的系统上,restorecon 可确保 Nginx 有权读取文件。

mkdir -p /var/www/example.com
echo '<h1>example.com is online</h1>' > /var/www/example.com/index.html
restorecon -Rv /var/www/example.com    # Rocky/Alma/CentOS with SELinux only

接着为域名添加 server 块:

server {
    listen 80;
    listen [::]:80;
    server_name example.com www.example.com;
    root /var/www/example.com;
    index index.html;

    location / {
        try_files $uri $uri/ =404;
    }
}

依发行版存放到正确位置,检查语法并重新加载 Nginx:

# Debian / Ubuntu: save as /etc/nginx/sites-available/example.com, then
ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/

# CentOS / Rocky / AlmaLinux: save as /etc/nginx/conf.d/example.com.conf

nginx -t && systemctl reload nginx
curl -I http://example.com

若 curl -I 返回 200 OK,代表网站已能通过 HTTP 访问,可以开始申请证书。

步骤 5:用 certbot --nginx 申请 Let's Encrypt 免费 SSL 证书

运行 certbot 并列出证书要涵盖的所有域名。首次运行会要求输入接收到期通知的邮箱地址,并同意 Let's Encrypt 条款。--redirect 参数会自动加上 HTTP 转 HTTPS 的重定向。

certbot --nginx -d example.com -d www.example.com --redirect

certbot 会通过 Nginx 提供的临时文件验证域名所有权,将证书安装到 server 块,并重新加载 Nginx。

步骤 6:确认自动续期正常工作

Let's Encrypt 证书有效期较短,必须自动续期。模拟续期可测试完整流程而不影响实际证书:

certbot renew --dry-run

# Debian / Ubuntu: the timer is enabled by the package
systemctl list-timers | grep certbot

# Rocky / AlmaLinux (EPEL): enable the renewal timer once
systemctl enable --now certbot-renew.timer

若模拟续期显示成功且计时器为启用状态,就不需要再做其他设置。

步骤 7:强制 HTTPS 并验证结果

如果先前没有加 --redirect,可以自行把 80 端口的 server 块改为重定向,并保留 certbot 创建的 HTTPS server 块:

server {
    listen 80;
    listen [::]:80;
    server_name example.com www.example.com;
    return 301 https://$host$request_uri;
}

重新加载 Nginx 后验证:

curl -I http://example.com      # expect 301 to https://
curl -I https://example.com     # expect 200
certbot certificates

替代方案:在 aaPanel 一键申请 SSL

若服务器已安装 aaPanel,可以省略上述手动步骤。在“网站”中添加站点,打开站点设置,进入 SSL 选项,选择 Let's Encrypt,勾选域名后申请,再打开“强制 HTTPS”开关即可,aaPanel 会自动续期。步骤 1 的 DNS 记录仍然必要。

常见问题

certbot 出现连接失败或超时错误,该检查什么?

确认 A 与 AAAA 记录指向本服务器、UFW 或 firewalld 已开放 80 与 443 端口,且 Nginx 正在运行。AAAA 记录错误是常见原因,因为验证可能通过 IPv6 进行。

一张证书可以涵盖多个域名吗?

可以。在 certbot 命令加上更多 -d 参数即可,每个域名都必须解析到此服务器。

续期后需要重新启动 Nginx 吗?

不需要。certbot 的 Nginx 插件在续期成功后会自动重新加载 Nginx。

如仍无法解决,请提交工单联系 JUSTG 技术支持。

这篇文章有帮助吗?
帮助中心
Linux 服务器 Linux SSH 密钥登录教程:设置 ed25519 密钥并禁用密码登录 只要服务器有公网 IPv4,上线几分钟内就会遇到 SSH 暴力破解机器人,而密码登录正是它们的首要目标。本文说明如何用较新的 ed25519 密钥完成 Linux SSH 密钥登录,再禁用 SSH 密码登录,全程避免把自己锁在门外。步骤适用于 Debian… Linux 服务器 Linux VPS 修改 SSH 端口与 root 密码教程(安全不断线) 把 SSH 从 22 端口移走虽然挡不住有心的攻击者,却能让日志里大部分自动扫描消失;而任何新服务器的第一件事,就是换一组新的 root 密码。本文说明如何在 Linux VPS 修改 SSH 端口与 root 密码且不断线:修改 sshd_config、在 Rocky… Linux 服务器 Linux 防火墙设置教程:VPS 使用 UFW 与 firewalld(含 IPv6) 新安装的 Linux 服务器,任何服务打开的端口都会直接对外响应,因此主机防火墙是最先要设置的项目之一。本文说明如何在 Debian / Ubuntu 用 UFW 设置 Linux 防火墙,以及在 CentOS、Rocky Linux、AlmaLinux 使用… Linux 服务器 Linux VPS 添加 Swap 交换空间教程(适合 512MB / 1GB 小内存套餐) 在 512 MB 或 1 GB 的云服务器上,数据库、PHP-FPM 加上一次软件包更新,很容易在同一时间用光内存。这时内核的 OOM killer 会强制终止进程,最常被牺牲的就是 MySQL 或 MariaDB。在 Linux VPS 添加 Swap… Linux 服务器 Linux 硬盘空间已满怎么办?VPS 找出并释放磁盘空间教程 “No space left on device”几乎会让服务器上所有东西出问题:数据库无法写入、网站返回错误、软件包更新失败,有时甚至无法正常登录。本文一步步说明如何排除 Linux 硬盘空间已满:先确认是数据块还是 inode 用完,再用 du 与 ncdu…
AlipayUnionPayVISAMastercardPayPalUSDTstripe