如何将Certbot的Let’s Encrypt验证从HTTP切换到AWS Route53?
如何将Certbot所有证书从Apache HTTP验证切换到AWS Route53验证
我正在使用Certbot管理多个域名证书,当前采用HTTP验证方式,现需将所有证书切换为AWS Route53验证方式。两种配置均能正常运行,但我想知道是否有对应的Certbot命令可完成该操作。我的配置文件内容如下:
[renewalparams] authenticator = apache installer = apache account = XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX manual_public_ip_logging_ok = None server = https://acme-v02.api.letsencrypt.org/directory
操作步骤
安装Certbot Route53插件
根据操作系统选择对应命令:- Debian/Ubuntu:
sudo apt install certbot-dns-route53 - RHEL/CentOS:
sudo yum install certbot-dns-route53 - 通用pip安装:
sudo pip install certbot-dns-route53
- Debian/Ubuntu:
配置AWS权限与凭证
- 创建IAM用户,赋予以下Route53权限策略:
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "route53:ListHostedZones", "route53:GetChange", "route53:ChangeResourceRecordSets" ], "Resource": "*" } ] } - 在运行Certbot的机器上配置AWS凭证:
创建~/.aws/credentials文件并填入:
也可以通过设置环境变量[default] aws_access_key_id = YOUR_AWS_ACCESS_KEY aws_secret_access_key = YOUR_AWS_SECRET_KEYAWS_ACCESS_KEY_ID和AWS_SECRET_ACCESS_KEY来配置。
- 创建IAM用户,赋予以下Route53权限策略:
批量更新证书验证配置
有两种方式完成配置切换:方式一:通过Certbot命令自动更新
运行以下命令,Certbot会更新所有证书的续期参数,将验证器改为Route53并保存配置:sudo certbot renew --authenticator dns-route53 --installer apache --save-renewal-config该命令会同时完成一次续期测试,确保新配置可用。
方式二:直接批量修改配置文件
证书续期配置默认存放在/etc/letsencrypt/renewal/目录,用sed批量替换验证器参数:sudo sed -i 's/authenticator = apache/authenticator = dns-route53/g' /etc/letsencrypt/renewal/*.conf
验证配置正确性
运行续期测试确保无报错:sudo certbot renew --dry-run
内容的提问来源于stack exchange,提问作者jbrahy
相关产品推荐
相关产品推荐

