温馨提示×

linux openssl怎么续期证书

小樊
41
2026-10-04 14:04:47
栏目: 云计算

在 Linux 上使用 OpenSSL 续期证书,通常分为两种情况:


一、你是用 OpenSSL 自己签发的证书(私有 CA / 自签名)

1️⃣ 查看原证书信息(确认是否快过期)

openssl x509 -in cert.crt -noout -dates

2️⃣ 使用原 CSR 续期(推荐)

如果你还保留原来的 CSR(证书请求文件):

openssl x509 \
  -req \
  -in old.csr \
  -CA ca.crt \
  -CAkey ca.key \
  -CAcreateserial \
  -out new.crt \
  -days 365

✅ 优点:证书信息(CN、SAN)不变


3️⃣ 重新生成 CSR 再签发(信息变了时用)

# 生成新私钥(可选)
openssl genrsa -out new.key 2048

# 生成 CSR
openssl req -new -key new.key -out new.csr

# 用 CA 签发
openssl x509 -req -in new.csr \
  -CA ca.crt -CAkey ca.key -CAcreateserial \
  -out new.crt -days 365

4️⃣ 自签名证书直接续期

openssl req -x509 -newkey rsa:2048 \
  -keyout key.pem -out cert.pem \
  -days 365 -nodes

二、你是 Let’s Encrypt 证书(非常常见)

✅ 推荐方式(certbot)

certbot renew

或强制续期:

certbot renew --force-renewal

自动续期一般已配置:

systemctl status certbot.timer

三、Nginx / Apache 使用注意事项

替换证书后重启服务

# Nginx
nginx -t
systemctl reload nginx

# Apache
apachectl configtest
systemctl reload httpd

四、常见坑提醒 ⚠️

  1. 私钥不能丢(续期不会自动生成新私钥)
  2. SAN(多域名)要用 -extfile
  3. 证书链顺序:
    你的证书
    CA 中间证书
    

五、快速判断你属于哪种情况

场景 命令
Let’s Encrypt certbot renew
自签名 openssl req -x509
企业内网 CA openssl x509 -req

如果你愿意,可以告诉我:

  • 证书类型(自签 / CA / Let’s Encrypt)
  • 用在什么服务(Nginx / Apache / 其他)
  • 是否有原 CSR / key

我可以帮你写精确命令。

0 踩