在 Linux 上使用 OpenSSL 续期证书,通常分为两种情况:
openssl x509 -in cert.crt -noout -dates
如果你还保留原来的 CSR(证书请求文件):
openssl x509 \
-req \
-in old.csr \
-CA ca.crt \
-CAkey ca.key \
-CAcreateserial \
-out new.crt \
-days 365
✅ 优点:证书信息(CN、SAN)不变
# 生成新私钥(可选)
openssl genrsa -out new.key 2048
# 生成 CSR
openssl req -new -key new.key -out new.csr
# 用 CA 签发
openssl x509 -req -in new.csr \
-CA ca.crt -CAkey ca.key -CAcreateserial \
-out new.crt -days 365
openssl req -x509 -newkey rsa:2048 \
-keyout key.pem -out cert.pem \
-days 365 -nodes
certbot renew
或强制续期:
certbot renew --force-renewal
自动续期一般已配置:
systemctl status certbot.timer
# Nginx
nginx -t
systemctl reload nginx
# Apache
apachectl configtest
systemctl reload httpd
-extfile你的证书
CA 中间证书
| 场景 | 命令 |
|---|---|
| Let’s Encrypt | certbot renew |
| 自签名 | openssl req -x509 |
| 企业内网 CA | openssl x509 -req |
如果你愿意,可以告诉我:
我可以帮你写精确命令。