在 Debian 上,如果你是用 Let’s Encrypt + Certbot 申请的 SSL 证书,SSL 一般是自动续签的;下面分情况说明。
certbot --version
如果没有:
sudo apt update
sudo apt install certbot python3-certbot-nginx
sudo certbot --nginx -d example.com -d www.example.com
Certbot 会:
查看 timer 是否启用:
systemctl list-timers | grep certbot
或
systemctl status certbot.timer
sudo certbot renew --dry-run
Certbot 的 nginx 插件会自动:
如果你用的是 webroot / standalone 方式,需确保:
sudo certbot renew
执行后有 reload:
renew_hook = systemctl reload nginx
那就不能自动续,只能:
查看日志:
sudo journalctl -u certbot
或
sudo certbot renew --verbose
Certbot 默认需要 80 端口(HTTP-01)
✅ Debian 上 Certbot + Nginx = 自动续 SSL
✅ 不用你每天管
✅ 只需确认 timer 在跑
如果你愿意,可以贴一下:
nginx -vcertbot --versionsystemctl status certbot.timer我可以帮你确认是否真的在自动续。