公开网站都应该以 HTTPS 提供服务,而 Let's Encrypt 的免费 SSL 证书让这件事变得很简单。本文说明如何在 JUSTG 云服务器或独立服务器上以 Nginx 搭建网站、用 certbot 申请 Let's Encrypt 证书、确认自动续期正常,并强制使用 HTTPS。命令分别提供 Debian/Ubuntu 与 CentOS/Rocky Linux/AlmaLinux 版本。示例域名为 example.com,服务器 IP 为 203.0.113.10,请替换成您自己的域名和 IP。
步骤 1:将域名指向 JUSTG 服务器(A 与 AAAA 记录)
在域名注册商或 DNS 服务商创建 A 记录,让主域名与 www 指向服务器的 IPv4。JUSTG 云服务器也免费提供 IPv6;只有在服务器已配置 IPv6 且 Nginx 在 IPv6 上监听时,才添加 AAAA 记录。请等记录生效后再申请证书,因为 Let's Encrypt 会从互联网验证域名。
# A example.com -> 203.0.113.10
# A www.example.com -> 203.0.113.10
# AAAA example.com -> 2001:db8::10 (optional, only if IPv6 is configured)
# check from the server (Debian/Ubuntu: apt install -y dnsutils, Rocky: dnf install -y bind-utils)
dig +short example.com A
dig +short www.example.com A
dig +short example.com AAAA步骤 2:在 Debian 或 Ubuntu 安装 Nginx 与 certbot
certbot 的 Nginx 插件可以自动修改 Nginx 设置。从默认软件源安装:
apt update
apt install -y nginx certbot python3-certbot-nginx
systemctl enable --now nginx
ufw allow 'Nginx Full' # if UFW is enabled步骤 3:在 Rocky Linux、AlmaLinux 或 CentOS 安装 Nginx 与 certbot
RHEL 系统的 certbot 来自 EPEL 软件源,同时要在 firewalld 开放 HTTP 与 HTTPS:
dnf install -y epel-release
dnf install -y nginx certbot python3-certbot-nginx
systemctl enable --now nginx
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reload步骤 4:创建网站与 Nginx server 块
创建网站根目录与测试页面。在启用 SELinux 的系统上,restorecon 可确保 Nginx 有权读取文件。
mkdir -p /var/www/example.com
echo '<h1>example.com is online</h1>' > /var/www/example.com/index.html
restorecon -Rv /var/www/example.com # Rocky/Alma/CentOS with SELinux only接着为域名添加 server 块:
server {
listen 80;
listen [::]:80;
server_name example.com www.example.com;
root /var/www/example.com;
index index.html;
location / {
try_files $uri $uri/ =404;
}
}依发行版存放到正确位置,检查语法并重新加载 Nginx:
# Debian / Ubuntu: save as /etc/nginx/sites-available/example.com, then
ln -s /etc/nginx/sites-available/example.com /etc/nginx/sites-enabled/
# CentOS / Rocky / AlmaLinux: save as /etc/nginx/conf.d/example.com.conf
nginx -t && systemctl reload nginx
curl -I http://example.com若 curl -I 返回 200 OK,代表网站已能通过 HTTP 访问,可以开始申请证书。
步骤 5:用 certbot --nginx 申请 Let's Encrypt 免费 SSL 证书
运行 certbot 并列出证书要涵盖的所有域名。首次运行会要求输入接收到期通知的邮箱地址,并同意 Let's Encrypt 条款。--redirect 参数会自动加上 HTTP 转 HTTPS 的重定向。
certbot --nginx -d example.com -d www.example.com --redirectcertbot 会通过 Nginx 提供的临时文件验证域名所有权,将证书安装到 server 块,并重新加载 Nginx。
步骤 6:确认自动续期正常工作
Let's Encrypt 证书有效期较短,必须自动续期。模拟续期可测试完整流程而不影响实际证书:
certbot renew --dry-run
# Debian / Ubuntu: the timer is enabled by the package
systemctl list-timers | grep certbot
# Rocky / AlmaLinux (EPEL): enable the renewal timer once
systemctl enable --now certbot-renew.timer若模拟续期显示成功且计时器为启用状态,就不需要再做其他设置。
步骤 7:强制 HTTPS 并验证结果
如果先前没有加 --redirect,可以自行把 80 端口的 server 块改为重定向,并保留 certbot 创建的 HTTPS server 块:
server {
listen 80;
listen [::]:80;
server_name example.com www.example.com;
return 301 https://$host$request_uri;
}重新加载 Nginx 后验证:
curl -I http://example.com # expect 301 to https://
curl -I https://example.com # expect 200
certbot certificates替代方案:在 aaPanel 一键申请 SSL
若服务器已安装 aaPanel,可以省略上述手动步骤。在“网站”中添加站点,打开站点设置,进入 SSL 选项,选择 Let's Encrypt,勾选域名后申请,再打开“强制 HTTPS”开关即可,aaPanel 会自动续期。步骤 1 的 DNS 记录仍然必要。
常见问题
certbot 出现连接失败或超时错误,该检查什么?
确认 A 与 AAAA 记录指向本服务器、UFW 或 firewalld 已开放 80 与 443 端口,且 Nginx 正在运行。AAAA 记录错误是常见原因,因为验证可能通过 IPv6 进行。
一张证书可以涵盖多个域名吗?
可以。在 certbot 命令加上更多 -d 参数即可,每个域名都必须解析到此服务器。
续期后需要重新启动 Nginx 吗?
不需要。certbot 的 Nginx 插件在续期成功后会自动重新加载 Nginx。
如仍无法解决,请提交工单联系 JUSTG 技术支持。