在 Debian 上更新 OpenSSL 相关证书,通常分几种情况。下面按常见场景说明。
Debian 使用 ca-certificates 管理受信任的 CA 证书。
sudo apt update
sudo apt upgrade ca-certificates
sudo update-ca-certificates
该命令会:
/usr/share/ca-certificates/etc/ssl/certs/ca-certificates.crt如果你说的是“更新 OpenSSL 程序版本”:
sudo apt update
sudo apt install openssl libssl3
查看版本:
openssl version
Debian 稳定版通常不会大幅升级 OpenSSL 主版本,只做安全更新。
例如:
/etc/ssl/certs/example.com.crt
/etc/ssl/private/example.com.key
# Nginx
sudo systemctl reload nginx
# Apache
sudo systemctl reload apache2
如果你用 certbot:
sudo certbot renew
测试是否自动执行:
sudo certbot renew --dry-run
Debian 通常已配置 systemd timer 自动续期。
sudo cp my-ca.crt /usr/local/share/ca-certificates/
sudo update-ca-certificates
reload 服务?openssl x509 -in example.com.crt -noout -dates
如果你能说明:
我可以给你更精确的命令。