git clone https://github.com/letsencrypt/letsencrypt cd letsencrypt ./letsencrypt-auto certonly --standalone --email aaa@qq.com -d aaa.com -d www.aaa.com
(第二个-d 如果不是需要www的域名可不加)
执行好了之后会在 /etc/letsencrypt/live/aaa.com 下面生成4个密钥文件,然后再nginx里面配置
ssl_certificate /etc/letsencrypt/live/aaa.com/fullchain.pem; ssl_certificate_key /etc/letsencrypt/live/aaa.com/privkey.pem;然后重启nginx ssl就配置好了
过时了就执行
./letsencrypt-auto certonly --renew-by-default --email aaa@qq.com -d aaa.com -d www.aaa.com记得在执行之前需要关闭nginx