centos7 certbot nginx

想在阿里云 centos7 nginx 下使用https直接使用的 Certbot:
1.安裝 certbot nginx 版

$ sudo yum install python2-certbot-nginx

  1. 停nginx服務(wù)

$ ps -ef | grep nginx

root     12373     1  0 09:58 ?        00:00:00 nginx: master process nginx -c /etc/nginx/nginx.conf
www      12390 12373  0 09:59 ?        00:00:00 nginx: worker process
root     12637 11828  0 10:16 pts/0    00:00:00 grep --color=auto nginx

$ kill -9 12373

  1. 設(shè)置Certbot需要的默認(rèn)的 nginx 路徑

$ ln -s /usr/local/nginx/sbin/nginx /usr/bin/nginx

$ ln -s /usr/local/nginx/conf/ /etc/nginx

4.開始配置

$ sudo certbot --nginx

[root@iz2zece0fhvx3at7vwt7wzz nginx]# sudo certbot --nginx
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator nginx, Installer nginx
Enter email address (used for urgent renewal and security notices) (Enter 'c' to
cancel): liangyongtong@foxmail.com
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Please read the Terms of Service at
https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must
agree in order to register with the ACME server at
https://acme-v02.api.letsencrypt.org/directory
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(A)gree/(C)ancel: A

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Would you be willing to share your email address with the Electronic Frontier
Foundation, a founding partner of the Let's Encrypt project and the non-profit
organization that develops Certbot? We'd like to send you email about our work
encrypting the web, EFF news, campaigns, and ways to support digital freedom.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: Y
Starting new HTTPS connection (1): supporters.eff.org

Which names would you like to activate HTTPS for?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: aaa.liangyongtong.cn
2: bbb.liangyongtong.cn
3: ccc.liangyongtong.cn
4: ddd.liangyongtong.cn
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): 4
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for www.liangyongtong.cn
nginx: [alert] kill(12271, 1) failed (3: No such process)
Waiting for verification...
Cleaning up challenges
Resetting dropped connection: acme-v02.api.letsencrypt.org
Deploying Certificate to VirtualHost /etc/nginx/nginx.conf

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: No redirect - Make no further changes to the webserver configuration.
2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you're confident your site works on HTTPS. You can undo this
change by editing your web server's configuration.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2
Redirecting all traffic on port 80 to ssl in /etc/nginx/nginx.conf

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations! You have successfully enabled https://ddd.liangyongtong.cn

You should test your configuration at:
https://www.ssllabs.com/ssltest/analyze.html?d=ddd.liangyongtong.cn
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/ddd.liangyongtong.cn/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/ddd.liangyongtong.cn/privkey.pem
   Your cert will expire on 2019-04-15. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot again
   with the "certonly" option. To non-interactively renew *all* of
   your certificates, run "certbot renew"
 - Your account credentials have been saved in your Certbot
   configuration directory at /etc/letsencrypt. You should make a
   secure backup of this folder now. This configuration directory will
   also contain certificates and private keys obtained by Certbot so
   making regular backups of this folder is ideal.
 - If you like Certbot, please consider supporting our work by:

   Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
   Donating to EFF:                    https://eff.org/donate-le

 - We were unable to subscribe you the EFF mailing list because your
   e-mail address appears to be invalid. You can try again later by
   visiting https://act.eff.org.
遇到的問題

1.ImportError: No module named 'requests.packages.urllib3
執(zhí)行:

$ pip install --upgrade --force-reinstall 'requests==2.6.0' urllib3

查看已安裝的證書

$ certbot certificates

Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Found the following certs:
  Certificate Name: ddd.liangyongtong.cn
    Domains: ddd.liangyongtong.cn
    Expiry Date: 2019-04-15 00:58:21+00:00 (VALID: 89 days)
    Certificate Path: /etc/letsencrypt/live/ddd.liangyongtong.cn/fullchain.pem
    Private Key Path: /etc/letsencrypt/live/ddd.liangyongtong.cn/privkey.pem
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末楷兽,一起剝皮案震驚了整個(gè)濱河市刮吧,隨后出現(xiàn)的幾起案子,更是在濱河造成了極大的恐慌经备,老刑警劉巖玄货,帶你破解...
    沈念sama閱讀 211,194評(píng)論 6 490
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件考榨,死亡現(xiàn)場離奇詭異双霍,居然都是意外死亡蛇数,警方通過查閱死者的電腦和手機(jī)挪钓,發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 90,058評(píng)論 2 385
  • 文/潘曉璐 我一進(jìn)店門,熙熙樓的掌柜王于貴愁眉苦臉地迎上來耳舅,“玉大人碌上,你說我怎么就攤上這事∑只玻” “怎么了馏予?”我有些...
    開封第一講書人閱讀 156,780評(píng)論 0 346
  • 文/不壞的土叔 我叫張陵,是天一觀的道長盔性。 經(jīng)常有香客問我霞丧,道長,這世上最難降的妖魔是什么冕香? 我笑而不...
    開封第一講書人閱讀 56,388評(píng)論 1 283
  • 正文 為了忘掉前任蛹尝,我火速辦了婚禮,結(jié)果婚禮上悉尾,老公的妹妹穿的比我還像新娘突那。我一直安慰自己,他們只是感情好构眯,可當(dāng)我...
    茶點(diǎn)故事閱讀 65,430評(píng)論 5 384
  • 文/花漫 我一把揭開白布愕难。 她就那樣靜靜地躺著,像睡著了一般。 火紅的嫁衣襯著肌膚如雪务漩。 梳的紋絲不亂的頭發(fā)上拄衰,一...
    開封第一講書人閱讀 49,764評(píng)論 1 290
  • 那天,我揣著相機(jī)與錄音饵骨,去河邊找鬼翘悉。 笑死,一個(gè)胖子當(dāng)著我的面吹牛居触,可吹牛的內(nèi)容都是我干的妖混。 我是一名探鬼主播,決...
    沈念sama閱讀 38,907評(píng)論 3 406
  • 文/蒼蘭香墨 我猛地睜開眼轮洋,長吁一口氣:“原來是場噩夢啊……” “哼制市!你這毒婦竟也來了?” 一聲冷哼從身側(cè)響起弊予,我...
    開封第一講書人閱讀 37,679評(píng)論 0 266
  • 序言:老撾萬榮一對(duì)情侶失蹤祥楣,失蹤者是張志新(化名)和其女友劉穎,沒想到半個(gè)月后汉柒,有當(dāng)?shù)厝嗽跇淞掷锇l(fā)現(xiàn)了一具尸體误褪,經(jīng)...
    沈念sama閱讀 44,122評(píng)論 1 303
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡,尸身上長有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 36,459評(píng)論 2 325
  • 正文 我和宋清朗相戀三年碾褂,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了兽间。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片。...
    茶點(diǎn)故事閱讀 38,605評(píng)論 1 340
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡正塌,死狀恐怖嘀略,靈堂內(nèi)的尸體忽然破棺而出,到底是詐尸還是另有隱情乓诽,我是刑警寧澤帜羊,帶...
    沈念sama閱讀 34,270評(píng)論 4 329
  • 正文 年R本政府宣布,位于F島的核電站问裕,受9級(jí)特大地震影響逮壁,放射性物質(zhì)發(fā)生泄漏。R本人自食惡果不足惜粮宛,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 39,867評(píng)論 3 312
  • 文/蒙蒙 一、第九天 我趴在偏房一處隱蔽的房頂上張望卖宠。 院中可真熱鬧巍杈,春花似錦、人聲如沸扛伍。這莊子的主人今日做“春日...
    開封第一講書人閱讀 30,734評(píng)論 0 21
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽。三九已至鳖宾,卻和暖如春吼砂,著一層夾襖步出監(jiān)牢的瞬間,已是汗流浹背鼎文。 一陣腳步聲響...
    開封第一講書人閱讀 31,961評(píng)論 1 265
  • 我被黑心中介騙來泰國打工渔肩, 沒想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留,地道東北人拇惋。 一個(gè)月前我還...
    沈念sama閱讀 46,297評(píng)論 2 360
  • 正文 我出身青樓周偎,卻偏偏與公主長得像,于是被迫代替她去往敵國和親撑帖。 傳聞我的和親對(duì)象是個(gè)殘疾皇子蓉坎,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 43,472評(píng)論 2 348

推薦閱讀更多精彩內(nèi)容