在 Debian 上搭建 LNMP(Linux + Nginx + MySQL/MariaDB + PHP) 并配置 SSL(HTTPS),通常有两种主流方式:
适合公网域名,自动签发、自动续期。
example.com)sudo apt update
sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d example.com -d www.example.com
按提示操作即可,Certbot 会自动:
sudo certbot renew --dry-run
sudo openssl req -x509 -nodes -days 365 \
-newkey rsa:2048 \
-keyout /etc/nginx/ssl/nginx.key \
-out /etc/nginx/ssl/nginx.crt
填写信息(可随意)
编辑站点配置:
sudo nano /etc/nginx/sites-available/default
示例:
server {
listen 443 ssl;
server_name example.com;
ssl_certificate /etc/nginx/ssl/nginx.crt;
ssl_certificate_key /etc/nginx/ssl/nginx.key;
root /var/www/html;
index index.php index.html;
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/run/php/php-fpm.sock;
}
}
server {
listen 80;
server_name example.com;
return 301 https://$host$request_uri;
}
sudo nginx -t
sudo systemctl restart nginx
如果你用的是 lnmp.org 一键包:
lnmp ssl add
按提示输入域名和证书路径即可。
✅ HTTPS 打不开
ufw allow 443✅ PHP 不解析
fastcgi_pass 路径正确php-fpm 正在运行如果你愿意,可以告诉我:
我可以给你精准配置文件。