配置Let's Encrypt证书后www域名仍显示不安全的解决请求
配置Let's Encrypt证书后www域名仍显示不安全的解决请求
问题描述
我用Certbot安装了Let's Encrypt证书,但访问www.example.com时会出现“此网站不安全”的错误。目前我有以下两张有效证书:
- 证书1:
- 证书名称: example.com
- 域名: example.com
- 有效期: 2023-05-25 15:01:00+00:00(剩余70天)
- 证书路径:
/etc/letsencrypt/live/example.com/fullchain.pem - 私钥路径:
/etc/letsencrypt/live/example.com/privkey.pem
- 证书2:
- 证书名称: www.example.com
- 域名: www.example.com
- 有效期: 2023-06-13 16:14:03+00:00(剩余89天)
- 证书路径:
/etc/letsencrypt/live/www.example.com/fullchain.pem - 私钥路径:
/etc/letsencrypt/live/www.example.com/privkey.pem
我的Apache SSL配置文件内容如下:
<VirtualHost *:443> ServerName example.com ServerAlias www.example.com DocumentRoot /var/www/example/public_html/public SSLEngine on <Directory /var/www/example/public_html/public> Options +FollowSymLinks DirectoryIndex index.php AllowOverride All Require all granted Order allow,deny Allow from all </Directory> SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf </VirtualHost>
请问怎么让www域名也能正常使用HTTPS呢?
解决方案
问题出在你当前的配置里:www.example.com作为ServerAlias绑定到了example.com的虚拟主机,但你用的example.com证书并不包含www.example.com这个域名,浏览器检测到证书和访问域名不匹配,就会提示“不安全”。
这里有两种简单的解决思路:
方法1:合并域名到同一张证书(推荐)
Let's Encrypt支持在单张证书里包含多个域名(也就是SAN证书),这样不用维护两张独立证书,后续更新也更省心。
- 先删除现有的两张证书(也可以跳过这步,直接重新申请覆盖):
sudo certbot delete --cert-name example.com sudo certbot delete --cert-name www.example.com - 重新申请包含两个域名的证书:
Certbot会自动帮你更新Apache的SSL配置,把两个域名绑定到同一张证书上,最后重启Apache生效:sudo certbot --apache -d example.com -d www.example.comsudo systemctl restart apache2
方法2:为www域名单独配置VirtualHost
如果你想保留两张独立证书,可以给www.example.com单独创建一个SSL虚拟主机配置:
- 在Apache的SSL配置目录(通常是
/etc/apache2/sites-available/)新建一个配置文件,比如www.example.com-ssl.conf,内容如下:<VirtualHost *:443> ServerName www.example.com DocumentRoot /var/www/example/public_html/public SSLEngine on <Directory /var/www/example/public_html/public> Options +FollowSymLinks DirectoryIndex index.php AllowOverride All Require all granted Order allow,deny Allow from all </Directory> SSLCertificateFile /etc/letsencrypt/live/www.example.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/www.example.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf </VirtualHost> - 启用这个配置文件:
sudo a2ensite www.example.com-ssl.conf - 重启Apache服务:
sudo systemctl restart apache2
配置完成后,建议直接用浏览器访问https://www.example.com验证,或者查看证书详情确认域名匹配情况。
备注:内容来源于stack exchange,提问作者Utku Dalmaz
相关产品推荐
相关产品推荐

