温馨提示×

linux openssl如何续期证书

小樊
53
2026-09-22 20:38:57
栏目: 云计算

在 Linux 上使用 OpenSSL 续期证书,本质上就是用原来的私钥和 CSR(或重新生成 CSR)再签发一次证书。是否“真正续期”取决于你的证书是自签名、内部 CA 签发还是公网 CA(如 Let’s Encrypt)。

下面按常见场景说明。


一、自签名证书续期(最常见)

1. 已有私钥和 CSR(推荐)

如果你还保留着原来的:

  • 私钥:example.key
  • CSR:example.csr

直接重新签发:

openssl x509 -req \
  -in example.csr \
  -signkey example.key \
  -out example.crt \
  -days 365

✅ 私钥不变,证书更新


2. 只有私钥,没有 CSR

用私钥重新生成 CSR:

openssl req -new \
  -key example.key \
  -out example.csr

再签发:

openssl x509 -req \
  -in example.csr \
  -signkey example.key \
  -out example.crt \
  -days 365

3. 私钥也丢了(不推荐)

重新生成一套:

openssl genrsa -out example.key 2048
openssl req -new -key example.key -out example.csr
openssl x509 -req -in example.csr -signkey example.key -out example.crt -days 365

⚠️ 客户端需要重新信任新证书


二、使用内部 CA 续期证书

假设你有:

  • CA 私钥:ca.key
  • CA 证书:ca.crt

1. 用原 CSR 续期

openssl x509 -req \
  -in example.csr \
  -CA ca.crt \
  -CAkey ca.key \
  -CAcreateserial \
  -out example.crt \
  -days 365

2. 沿用旧证书信息(高级)

如果你只有旧证书,可以用它生成新 CSR:

openssl x509 -x509toreq \
  -in example.crt \
  -signkey example.key \
  -out example.csr

然后按上面方式签发。


三、Let’s Encrypt 证书(不要用 OpenSSL 续)

❌ 不要用 OpenSSL 续 Let’s Encrypt

正确方式:

certbot renew

或指定域名:

certbot renew --cert-name example.com

四、验证新证书

openssl x509 -in example.crt -noout -dates

查看:

  • notBefore
  • notAfter

五、续期后必须做的

  1. 替换旧证书文件
  2. 重启服务:
    systemctl restart nginx
    systemctl restart apache2
    
  3. 确认端口监听正常

如果你愿意,可以告诉我:

  • 证书类型(自签 / CA / Let’s Encrypt)
  • 使用服务(Nginx / Apache / 其他)
  • 是否有原私钥和 CSR

我可以给你精确命令。

0 踩