You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Certbot执行失败报错:SSL证书验证失败(证书尚未生效)求助

问题排查:Certbot请求Let's Encrypt API时SSL证书验证失败

执行的命令

certbot certonly --webroot -w /var/www/html/ -d mrcoudreau.fr -d www.mrcoudreau.fr

错误信息

requests.exceptions.SSLError: HTTPSConnectionPool(host='acme-v02.api.letsencrypt.org', port=443): Max retries exceeded with url: /directory (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:1123)')))

错误原因

  • 服务器系统时间偏差:Let's Encrypt的API证书有严格的生效时间范围,若本地系统时间早于证书生效时间,会直接触发"certificate is not yet valid"验证失败。
  • 本地CA证书库失效:系统用于校验SSL证书的根CA证书未更新或损坏,无法正确识别Let's Encrypt的API证书链。
  • 网络代理/防火墙干扰:代理可能篡改SSL证书链,或防火墙拦截了证书验证相关的请求,导致证书校验失败。

解决方法

1. 同步系统时间

  • 安装并启用NTP服务(Debian/Ubuntu环境):
apt update && apt install ntp -y
systemctl enable --now ntp
  • 临时手动同步时间:
timedatectl set-ntp true
timedatectl status

确认输出中System clock synchronized显示为yes即可。

2. 更新本地CA证书库

  • Debian/Ubuntu系统:
apt update && apt install --reinstall ca-certificates -y
update-ca-certificates
  • RHEL/CentOS系统:
yum update ca-certificates -y
update-ca-trust extract

3. 排查代理与防火墙

  • 若服务器使用代理,临时关闭代理后重新执行Certbot命令,验证是否为代理导致的问题。
  • 检查防火墙规则,确保允许服务器访问acme-v02.api.letsencrypt.org的443端口。

内容的提问来源于stack exchange,提问作者ArnaudG

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 19:42:06