Dokku配置Let's Encrypt SSL证书失败问题求助
Dokku应用无法获取Let's Encrypt SSL证书
问题现象
为Dokku应用personal-app申请Let's Encrypt SSL证书时持续失败,报错包含:
- nginx.service启动失败
- ACME HTTP-01挑战返回404未授权
已完成验证:
- 域名DNS A记录配置正确
- 服务器80端口开放(telnet验证通过)
- 域名可正常通过SSH和HTTP访问
- 重建服务器并严格遵循Dokku文档操作,问题仍存在
相关日志
证书获取过程日志
=====> Enabling letsencrypt for personal-app -----> Enabling ACME proxy for personal-app... -----> Setting temporary site Job for nginx.service failed. See "systemctl status nginx.service" and "journalctl -xe" for details. -----> Getting letsencrypt certificate for personal-app via HTTP-01 - Domain 'app.[my-domain].ch' 2024/02/11 14:59:15 [INFO] [app.[my-domain].ch] acme: Obtaining bundled SAN certificate 2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] AuthURL: https://acme-v02.api.letsencrypt.org/acme/authz-v3/314082842777 2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] acme: Could not find solver for: tls-alpn-01 2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] acme: use http-01 solver 2024/02/11 14:59:16 [INFO] [app.[my-domain].ch] acme: Trying to solve HTTP-01 2024/02/11 14:59:19 [INFO] Deactivating auth: https://acme-v02.api.letsencrypt.org/acme/authz-v3/314082842777 2024/02/11 14:59:19 Could not obtain certificates: error: one or more domains had a problem: [app.[my-domain].ch] acme: error: 403 :: urn:ietf:params:acme:error:unauthorized :: 142.132.187.148: Invalid response from http://app.[my-domain].ch/.well-known/acme-challenge/VTYxIcvj1BHEXzQKaTF67Sp8GPYemQqQSNubW-VMKnk: 404 -----> Certificate retrieval failed! -----> Disabling ACME proxy for personal-app... ! Failed to setup letsencrypt ! Check log output for further information on failure
systemctl status nginx.service日志
● nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/lib/systemd/system/nginx.service; enabled; vendor preset: enabled) Active: active (running) since Sun 2024-02-11 14:50:16 UTC; 50min ago Docs: man:nginx(8) Process: 39421 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=0/SUCCESS) Process: 39442 ExecStart=/usr/sbin/nginx -g daemon on; master_process on; (code=exited, status=0/SUCCESS) Process: 47531 ExecReload=/usr/sbin/nginx -g daemon on; master_process on; -s reload (code=exited, status=0/SUCCESS) Main PID: 39451 (nginx) Tasks: 2 (limit: 2261) Memory: 4.6M CGroup: /system.slice/nginx.service ├─39451 nginx: master process /usr/sbin/nginx -g daemon on; master_process on; └─47532 nginx: worker process Feb 11 15:16:06 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server. Feb 11 15:16:06 personal1-1core1gb systemd[1]: Reloaded A high performance web server and a reverse proxy server. Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server. Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reloaded A high performance web server and a reverse proxy server. Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server. Feb 11 15:18:58 personal1-1core1gb nginx[47100]: nginx: [emerg] invalid number of arguments in "access_log" directive in /home/dokku/personal-app/nginx.con> Feb 11 15:18:58 personal1-1core1gb systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE Feb 11 15:18:58 personal1-1core1gb systemd[1]: Reload failed for A high performance web server and a reverse proxy server. Feb 11 15:19:00 personal1-1core1gb systemd[1]: Reloading A high performance web server and a reverse proxy server. Feb 11 15:19:00 personal1-1core1gb systemd[1]: Reloaded A high performance web server and a reverse proxy server.
journalctl -xe日志
-- A start job for unit dokku-retire.service has begun execution. -- -- The job identifier is 3677. Feb 11 15:35:40 personal1-1core1gb dokku[48365]: -----> Retiring old containers and images Feb 11 15:35:40 personal1-1core1gb systemd[1]: dokku-retire.service: Succeeded. -- Subject: Unit succeeded -- Defined-By: systemd -- Support: http://www.ubuntu.com/support -- -- The unit dokku-retire.service has successfully entered the 'dead' state. Feb 11 15:35:40 personal1-1core1gb systemd[1]: Finished Dokku retire service. -- Subject: A start job for unit dokku-retire.service has finished successfully -- Defined-By: systemd -- Support: http://www.ubuntu.com/support -- -- A start job for unit dokku-retire.service has finished successfully. -- -- The job identifier is 3677. Feb 11 15:37:52 personal1-1core1gb sshd[48598]: Invalid user public_django_project from 68.183.148.142 port 33464 Feb 11 15:37:52 personal1-1core1gb sshd[48598]: pam_unix(sshd:auth): check pass; user unknown Feb 11 15:37:52 personal1-1core1gb sshd[48598]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=68.183.148.142 Feb 11 15:37:54 personal1-1core1gb sshd[48598]: Failed password for invalid user public_django_project from 68.183.148.142 port 33464 ssh2 Feb 11 15:37:55 personal1-1core1gb sshd[48598]: Connection closed by invalid user public_django_project 68.183.148.142 port 33464 [preauth] Feb 11 15:40:49 personal1-1core1gb systemd[1]: Starting Dokku retire service... -- Subject: A start job for unit dokku-retire.service has begun execution -- Defined-By: systemd -- Support: http://www.ubuntu.com/support -- -- A start job for unit dokku-retire.service has begun execution. -- -- The job identifier is 3765. Feb 11 15:40:49 personal1-1core1gb dokku[48629]: -----> Retiring old containers and images Feb 11 15:40:49 personal1-1core1gb systemd[1]: dokku-retire.service: Succeeded. -- Subject: Unit succeeded -- Defined-By: systemd -- Support: http://www.ubuntu.com/support -- -- The unit dokku-retire.service has successfully entered the 'dead' state. Feb 11 15:40:49 personal1-1core1gb systemd[1]: Finished Dokku retire service. -- Subject: A start job for unit dokku-retire.service has finished successfully -- Defined-By: systemd -- Support: http://www.ubuntu.com/support -- -- A start job for unit dokku-retire.service has finished successfully. -- -- The job identifier is 3765.
已完成排查
- 防火墙配置:确认80端口允许外部连接(telnet验证通过)
分析与解决步骤
核心问题定位:从nginx状态日志可明确,
/home/dokku/personal-app/nginx.conf中的access_log指令参数格式错误,导致nginx重载失败。这直接破坏了ACME代理的临时站点配置,使得HTTP-01挑战请求无法被正确路由,返回404错误。修复操作:
- 查看并修正应用的nginx配置文件:
找到cat /home/dokku/personal-app/nginx.confaccess_log行,确保格式符合nginx标准:access_log /path/to/log/file [日志格式]; - 验证nginx配置有效性:
确认无语法错误后,重载nginx服务:nginx -tsystemctl reload nginx - 重新尝试获取SSL证书:
dokku letsencrypt:enable personal-app
- 查看并修正应用的nginx配置文件:
额外检查项:
- 更新Dokku letsencrypt插件到最新版本,避免版本bug:
dokku plugin:install https://github.com/dokku/dokku-letsencrypt.git letsencrypt - 若应用使用自定义nginx配置模板,检查模板中的
access_log指令是否存在格式问题,防止重新部署时覆盖正确配置。
- 更新Dokku letsencrypt插件到最新版本,避免版本bug:
内容的提问来源于stack exchange,提问作者GiftChees
相关产品推荐
相关产品推荐

