可通过certbot自动获取并部署let’s encrypt免费ssl/tls证书:先安装certbot及对应web服务器插件,确保域名解析正常、web服务运行且80/443端口开放,再执行certbot --nginx或--apache命令完成证书申请与配置;若需手动部署,则用--standalone模式申请后编辑服务器配置文件指定证书路径。

如果您希望为Linux服务器上的网站启用HTTPS加密连接,但尚未配置SSL/TLS证书,则可以通过Certbot工具自动获取并部署由Let’s Encrypt签发的免费证书。以下是完成该任务的具体操作步骤:
一、安装Certbot及配套插件
Certbot是Let’s Encrypt官方推荐的ACME客户端,需根据所用Web服务器类型安装对应插件以实现自动配置。不同发行版使用不同包管理器,且Nginx与Apache需分别安装对应插件。
1、对于Ubuntu 20.04/22.04或Debian 11/12系统,先更新软件包索引:
sudo apt update
2、安装Certbot主程序及Nginx插件(若使用Nginx):
sudo apt install certbot python3-certbot-nginx
3、若运行的是Apache服务器,则执行:
sudo apt install certbot python3-certbot-apache
4、对于CentOS Stream 8/9或RHEL 8/9系统,启用EPEL源后安装:
sudo dnf install epel-release && sudo dnf install certbot python3-certbot-nginx
5、验证安装是否成功:
certbot --version
二、确保域名解析与Web服务就绪
Certbot在申请证书前必须能通过公网访问目标域名,并验证对该域名的控制权。它会临时在Web根目录下放置验证文件,因此Web服务器必须正常运行且域名已正确指向当前服务器IP。
1、确认域名(例如example.com)已添加A记录指向服务器公网IP
2、检查Nginx或Apache服务处于运行状态:
sudo systemctl is-active nginx 或 sudo systemctl is-active httpd
3、确保防火墙放行HTTP(80端口)和HTTPS(443端口):
sudo ufw allow 80 && sudo ufw allow 443(Ubuntu/Debian)
4、若使用云服务器,还需在安全组中开放80和443端口
5、访问http://your-domain.com,确认能显示默认页面或网站首页,这是证书颁发前必须满足的前提条件
三、使用Certbot自动获取并配置证书(Nginx)
此方法适用于Nginx服务器,Certbot将自动修改Nginx配置文件,添加SSL监听、证书路径及重定向规则,无需手动编辑配置。
1、执行交互式证书申请命令:
sudo certbot --nginx -d example.com -d www.example.com
2、按提示输入邮箱地址用于紧急通知
3、阅读并同意Let’s Encrypt服务条款(输入A表示同意)
4、选择是否将HTTP请求自动重定向至HTTPS(推荐选2,启用强制跳转)
5、Certbot完成配置后,会显示证书存放路径:
/etc/letsencrypt/live/example.com/fullchain.pem 和 privkey.pem
四、使用Certbot自动获取并配置证书(Apache)
此方式专用于Apache环境,Certbot将自动启用mod_ssl模块、更新虚拟主机配置,并设置HTTP到HTTPS重写规则。
1、执行证书申请命令:
sudo certbot --apache -d example.com -d www.example.com
2、输入管理员邮箱地址
3、接受服务条款(输入A)
4、选择启用HTTPS重定向(输入2)
5、Certbot重启Apache服务并完成配置,证书路径同样位于:
/etc/letsencrypt/live/example.com/fullchain.pem 和 privkey.pem
五、手动申请证书并独立部署
当Web服务器未运行、或使用非标准端口、或需自定义Nginx/Apache配置时,可采用“standalone”模式申请证书,Certbot临时启动内置HTTP服务完成验证。
1、停止Nginx或Apache服务:
sudo systemctl stop nginx 或 sudo systemctl stop httpd
2、执行独立验证命令:
sudo certbot certonly --standalone -d example.com -d www.example.com
3、按提示输入邮箱并接受条款
4、证书生成后,手动编辑Web服务器配置文件,指定证书路径:
ssl_certificate /etc/letsencrypt/live/example.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/example.com/privkey.pem;
5、重新加载配置:
sudo nginx -t && sudo systemctl reload nginx 或 sudo apachectl configtest && sudo systemctl reload httpd










