You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Linux上的.NET Core 6 Systemd服务配置SSL

为Systemd托管的.NET Core 6 API配置SSL的两种方案

方案一:让.NET Core直接加载SSL证书(Kestrel自带SSL)

步骤1:修改Systemd服务配置文件

编辑你的服务文件(通常位于/etc/systemd/system/VanJugando.service),调整环境变量指定HTTPS端口和证书路径:

[Unit]
Description=Van Jugando NETCore API

[Service]
WorkingDirectory=/var/www/vanjugando
ExecStart=/usr/bin/dotnet /var/www/vanjugando/VanJugando.dll
Restart=always
Environment=ASPNETCORE_ENVIRONMENT=Production
# 替换为HTTPS端口(例如5001)
Environment=ASPNETCORE_URLS=https://0.0.0.0:5001
# 替换为你的域名对应的Certbot证书路径
Environment=ASPNETCORE_Kestrel__Certificates__Default__Path=/etc/letsencrypt/live/your-domain.com/fullchain.pem
Environment=ASPNETCORE_Kestrel__Certificates__Default__KeyPath=/etc/letsencrypt/live/your-domain.com/privkey.pem
SyslogIdentifier=VanJugando
# 指定运行用户,确保该用户能访问证书文件(推荐使用www-data)
User=www-data

[Install]
WantedBy=multi-user.target

步骤2:确保证书文件的访问权限

Certbot生成的证书默认是root权限,需要给运行.NET Core的用户授权访问:

# 复制证书到API目录,避免Certbot更新时权限变化
sudo cp /etc/letsencrypt/live/your-domain.com/fullchain.pem /var/www/vanjugando/
sudo cp /etc/letsencrypt/live/your-domain.com/privkey.pem /var/www/vanjugando/
# 修改文件权限,仅运行用户可读
sudo chown www-data:www-data /var/www/vanjugando/fullchain.pem /var/www/vanjugando/privkey.pem
sudo chmod 600 /var/www/vanjugando/fullchain.pem /var/www/vanjugando/privkey.pem

步骤3:重启服务

sudo systemctl daemon-reload
sudo systemctl restart VanJugando.service

方案二:通过Apache反向代理实现SSL(推荐)

利用已有的Apache SSL配置,将HTTPS请求反向代理到API的3000端口,无需修改.NET Core的Systemd配置。

步骤1:启用Apache代理模块

sudo a2enmod proxy proxy_http

步骤2:配置Apache虚拟主机

编辑你的Web应用虚拟主机配置文件(例如/etc/apache2/sites-available/your-domain.conf),添加反向代理规则:

场景1:API通过主域名的子路径访问(如your-domain.com/api)

<VirtualHost *:443>
    ServerName your-domain.com

    # 保留原Web应用的配置...

    # 添加API反向代理规则
    ProxyPass /api http://localhost:3000
    ProxyPassReverse /api http://localhost:3000

    # Certbot自动生成的SSL配置(无需修改)
    SSLCertificateFile /etc/letsencrypt/live/your-domain.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/your-domain.com/privkey.pem
    Include /etc/letsencrypt/options-ssl-apache.conf
</VirtualHost>

场景2:API通过独立子域名访问(如api.your-domain.com)

先给子域名申请Certbot证书:

sudo certbot --apache -d api.your-domain.com

然后新建虚拟主机配置:

<VirtualHost *:443>
    ServerName api.your-domain.com

    # 反向代理到API的3000端口
    ProxyPass / http://localhost:3000/
    ProxyPassReverse / http://localhost:3000/

    SSLCertificateFile /etc/letsencrypt/live/api.your-domain.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/api.your-domain.com/privkey.pem
    Include /etc/letsencrypt/options-ssl-apache.conf
</VirtualHost>

步骤3:重启Apache服务

sudo systemctl restart apache2

方案对比

  • 方案一:API直接处理SSL,无需依赖Apache,但需要手动维护证书权限,Certbot续期后可能需要重新同步证书文件。
  • 方案二:通过Apache统一管理SSL,Certbot自动续期生效,无需修改API配置,更适合已有Apache环境的场景,推荐使用。

内容的提问来源于stack exchange,提问作者Valentin Garcia

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.12 11:32:51