在 Debian 上让域名通过 HTTPS 访问,通常分三步:域名解析 → Web 服务 → 证书(SSL/TLS)。下面给你一个最常见、最省事的方案(Nginx + Let’s Encrypt)。
example.com)sudo apt update
sudo apt install nginx -y
测试访问:
http://你的域名
sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d example.com -d www.example.com
按提示:
✅ 完成后,访问:
https://example.com
测试续期:
sudo certbot renew --dry-run
Debian 会通过 systemd timer 自动续期。
sudo ufw allow 80
sudo ufw allow 443
sudo apt install apache2
sudo apt install certbot python3-certbot-apache
sudo certbot --apache -d example.com
ping example.com
必须能 ping 到服务器 IP。
确保 80 和 443 端口对外放行。
Let’s Encrypt 不支持内网域名,只能用:
sudo openssl req -x509 -nodes -days 365 \
-newkey rsa:2048 \
-keyout /etc/ssl/private/nginx.key \
-out /etc/ssl/certs/nginx.crt
如果你告诉我:
我可以给你精确配置示例。