在 Debian 上迁移 Nginx + SSL 通常指把 Nginx 配置和证书从一台服务器迁移到另一台(或重装系统后恢复)。下面按最稳妥、通用的方式说明。
一般在:
/etc/nginx/
重点包括:
/etc/nginx/nginx.conf/etc/nginx/sites-available//etc/nginx/sites-enabled//etc/nginx/conf.d/常见位置:
/etc/nginx/ssl/
/etc/ssl/nginx/
/etc/letsencrypt/ # 如果是 Let's Encrypt
/var/www/
tar czf nginx-conf.tar.gz /etc/nginx
tar czf nginx-ssl.tar.gz /etc/nginx/ssl
tar czf letsencrypt.tar.gz /etc/letsencrypt
scp nginx-conf.tar.gz nginx-ssl.tar.gz user@new-server:/root
apt update
apt install nginx -y
tar xzf nginx-conf.tar.gz -C /
tar xzf nginx-ssl.tar.gz -C /
如果是 Let’s Encrypt:
tar xzf letsencrypt.tar.gz -C /
apt install certbot python3-certbot-nginx -y
nginx -t
systemctl restart nginx
chmod 600 /etc/nginx/ssl/*.key
chown root:root /etc/nginx/ssl/*.key
检查 nginx.conf 或 sites-enabled 中:
ssl_certificate /etc/nginx/ssl/example.com.crt;
ssl_certificate_key /etc/nginx/ssl/example.com.key;
certbot renew --dry-run
如果你用的是 Let’s Encrypt:
/etc/letsencryptcertbotcertbot renew不需要手动复制证书文件
如果你能说明:
我可以给你更精确的命令。