温馨提示×

debian nginxssl怎么自动续

小樊
45
2026-10-05 15:35:15
栏目: 云计算

在 Debian 上,如果你是用 Let’s Encrypt + Certbot 申请的 SSL 证书,SSL 一般是自动续签的;下面分情况说明。


一、最常见情况:使用 Certbot(推荐)

1. 确认是否已安装 Certbot

certbot --version

如果没有:

sudo apt update
sudo apt install certbot python3-certbot-nginx

2. 申请证书(如果还没申请)

sudo certbot --nginx -d example.com -d www.example.com

3. 自动续签原理

Certbot 会:

  • 安装一个 systemd timer 或 cron 任务
  • 每天检查证书
  • 证书 < 30 天到期时自动续签

查看 timer 是否启用:

systemctl list-timers | grep certbot

或

systemctl status certbot.timer

4. 手动测试续签(不真正替换)

sudo certbot renew --dry-run

二、Nginx 配置无需手动重启

Certbot 的 nginx 插件会自动:

  • 修改 nginx 配置
  • reload nginx

如果你用的是 webroot / standalone 方式,需确保:

sudo certbot renew

执行后有 reload:

renew_hook = systemctl reload nginx

三、如果你不是用 Certbot(如自签/商业证书)

那就不能自动续,只能:

  • 商业证书:手动续费并替换
  • 自签:写脚本 + cron(不推荐生产)

四、常见问题排查

1. 续签失败

查看日志:

sudo journalctl -u certbot

或

sudo certbot renew --verbose

2. 80 端口被占用

Certbot 默认需要 80 端口(HTTP-01)


总结

✅ Debian 上 Certbot + Nginx = 自动续 SSL
✅ 不用你每天管
✅ 只需确认 timer 在跑

如果你愿意,可以贴一下:

  • nginx -v
  • certbot --version
  • systemctl status certbot.timer

我可以帮你确认是否真的在自动续。

0 踩