Certbot执行失败报错:SSL证书验证失败(证书尚未生效)求助
问题排查:Certbot请求Let's Encrypt API时SSL证书验证失败
执行的命令
certbot certonly --webroot -w /var/www/html/ -d mrcoudreau.fr -d www.mrcoudreau.fr
错误信息
requests.exceptions.SSLError: HTTPSConnectionPool(host='acme-v02.api.letsencrypt.org', port=443): Max retries exceeded with url: /directory (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:1123)')))
错误原因
- 服务器系统时间偏差:Let's Encrypt的API证书有严格的生效时间范围,若本地系统时间早于证书生效时间,会直接触发"certificate is not yet valid"验证失败。
- 本地CA证书库失效:系统用于校验SSL证书的根CA证书未更新或损坏,无法正确识别Let's Encrypt的API证书链。
- 网络代理/防火墙干扰:代理可能篡改SSL证书链,或防火墙拦截了证书验证相关的请求,导致证书校验失败。
解决方法
1. 同步系统时间
- 安装并启用NTP服务(Debian/Ubuntu环境):
apt update && apt install ntp -y systemctl enable --now ntp
- 临时手动同步时间:
timedatectl set-ntp true timedatectl status
确认输出中System clock synchronized显示为yes即可。
2. 更新本地CA证书库
- Debian/Ubuntu系统:
apt update && apt install --reinstall ca-certificates -y update-ca-certificates
- RHEL/CentOS系统:
yum update ca-certificates -y update-ca-trust extract
3. 排查代理与防火墙
- 若服务器使用代理,临时关闭代理后重新执行Certbot命令,验证是否为代理导致的问题。
- 检查防火墙规则,确保允许服务器访问
acme-v02.api.letsencrypt.org的443端口。
内容的提问来源于stack exchange,提问作者ArnaudG
相关产品推荐
相关产品推荐

