Ubuntu EC2实例Certbot独立验证失败问题求助
问题背景
在Ubuntu EC2实例执行以下命令申请Let's Encrypt证书:
sudo certbot certonly --standalone -d cimetrics.io --staple-ocsp -m jonathanwoollettlight@gmail.com --agree-tos
返回验证失败错误:
Certbot failed to authenticate some domains (authenticator: standalone). The Certificate Authority reported these problems:
Domain: cimetrics.io
Type: unauthorized
Detail: 15.197.142.173: Invalid response from http://cimetrics.io/.well-known/acme-challenge/HAOi6Kom9At9ywZ8UAUykre5WqkAg8dfYvl6tEIA388: 404Hint: The Certificate Authority failed to download the challenge files from the temporary standalone webserver started by Certbot on port 80. Ensure that the listed domains point to this machine and that it can accept inbound connections from the internet.
当前环境与异常点
- 主机信息:
ubuntu@ip-172-31-11-236:~$ uname --a Linux ip-172-31-11-236 6.2.0-1017-aws #17~22.04.1-Ubuntu SMP Fri Nov 17 21:07:13 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux - 域名
cimetrics.io托管于GoDaddy,预期指向EC2实例公网IP3.10.39.149,但实际DNS解析结果为3.33.152.147,错误中还出现未配置的IP15.197.142.173 - 当前DNS记录包含两条错误A记录:
; A Record @ 600 IN A 15.197.142.173 @ 600 IN A 3.33.152.147 - 可通过
http://cimetrics.io/和http://3.10.39.149/正常访问EC2上的HTTP服务器
解决步骤
1. 修正DNS解析记录
- 登录GoDaddy域名管理后台,删除现有的两条A记录(
15.197.142.173和3.33.152.147) - 添加新的A记录,将
@指向EC2实例的公网IP3.10.39.149,TTL设置为600秒(缩短TTL可加速DNS生效) - 验证解析结果:通过
nslookup cimetrics.io或dig cimetrics.io命令确认域名已正确指向3.10.39.149
2. 确认EC2网络权限
- 检查EC2安全组规则,确保允许入站TCP 80端口的流量(来源可设置为0.0.0.0/0)
- 检查实例内部防火墙(如ufw),确认80端口未被拦截:
sudo ufw status # 若未允许80端口,执行: sudo ufw allow 80/tcp
3. 重新执行证书申请命令
待DNS生效且网络权限确认后,重新运行Certbot命令:
sudo certbot certonly --standalone -d cimetrics.io --staple-ocsp -m jonathanwoollettlight@gmail.com --agree-tos
注意:执行命令前需停止占用80端口的其他服务(如已运行的HTTP服务器),避免端口冲突
内容的提问来源于stack exchange,提问作者Jonathan Woollett-light

