certbot获取免费ssl证书,自动续期

1 篇文章 0 订阅
1 篇文章 0 订阅

1,通过nginx部署网站,并添加如下节点

server {
    listen 80;
    listen [::]:80;
    server_name xxxx.xxxx.com;

    # 一定要配置这段
    location ^~ /.well-known/acme-challenge/ { 
    # 必须是真实存在的目录
        root /XXX/XXXX;
    }

    return 301 https://$server_name$request_uri;
}

2,安装certbot

yum update
yum install snap
systemctl restart snapd.service
snap install core
snap refresh core
yum remove certbot
yum install certbot
ln -s /var/lib/snapd/snap /snap
cd /snap
snap install --classic certbot
ln -s /snap/bin/certbot /usr/bin/certbot
certbot certonly --webroot  --email XXXX@XXXX -d www.XXX.cn
输出一下内容
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for www.ivall.cn
Input the webroot for www.ivall.cn: (Enter 'c' to cancel): /XXX/XXXX  #输入ngnix配置的地址

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/www.ivall.cn/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/www.ivall.cn/privkey.pem
This certificate expires on 2021-11-11.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
 * Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
 * Donating to EFF:                    https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

到此ssl证书就生成好了,证书存放在目录

Certificate is saved at: /etc/letsencrypt/live/www.ivall.cn/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/www.ivall.cn/privkey.pem

3,nginx配置ssl 访问即可

4,设置自动续期

certbot renew --force-renewal

#设置定时任务 
crontab -e 
#编辑文件并保存 
0 0 1 * * /usr/bin/certbot renew --force-renewal

此处有可能会提示snap未启动,启动即可

  • 0
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值