如何为Linux上的.NET Core 6 Systemd服务配置SSL
为Systemd托管的.NET Core 6 API配置SSL的两种方案
方案一:让.NET Core直接加载SSL证书(Kestrel自带SSL)
步骤1:修改Systemd服务配置文件
编辑你的服务文件(通常位于/etc/systemd/system/VanJugando.service),调整环境变量指定HTTPS端口和证书路径:
[Unit] Description=Van Jugando NETCore API [Service] WorkingDirectory=/var/www/vanjugando ExecStart=/usr/bin/dotnet /var/www/vanjugando/VanJugando.dll Restart=always Environment=ASPNETCORE_ENVIRONMENT=Production # 替换为HTTPS端口(例如5001) Environment=ASPNETCORE_URLS=https://0.0.0.0:5001 # 替换为你的域名对应的Certbot证书路径 Environment=ASPNETCORE_Kestrel__Certificates__Default__Path=/etc/letsencrypt/live/your-domain.com/fullchain.pem Environment=ASPNETCORE_Kestrel__Certificates__Default__KeyPath=/etc/letsencrypt/live/your-domain.com/privkey.pem SyslogIdentifier=VanJugando # 指定运行用户,确保该用户能访问证书文件(推荐使用www-data) User=www-data [Install] WantedBy=multi-user.target
步骤2:确保证书文件的访问权限
Certbot生成的证书默认是root权限,需要给运行.NET Core的用户授权访问:
# 复制证书到API目录,避免Certbot更新时权限变化 sudo cp /etc/letsencrypt/live/your-domain.com/fullchain.pem /var/www/vanjugando/ sudo cp /etc/letsencrypt/live/your-domain.com/privkey.pem /var/www/vanjugando/ # 修改文件权限,仅运行用户可读 sudo chown www-data:www-data /var/www/vanjugando/fullchain.pem /var/www/vanjugando/privkey.pem sudo chmod 600 /var/www/vanjugando/fullchain.pem /var/www/vanjugando/privkey.pem
步骤3:重启服务
sudo systemctl daemon-reload sudo systemctl restart VanJugando.service
方案二:通过Apache反向代理实现SSL(推荐)
利用已有的Apache SSL配置,将HTTPS请求反向代理到API的3000端口,无需修改.NET Core的Systemd配置。
步骤1:启用Apache代理模块
sudo a2enmod proxy proxy_http
步骤2:配置Apache虚拟主机
编辑你的Web应用虚拟主机配置文件(例如/etc/apache2/sites-available/your-domain.conf),添加反向代理规则:
场景1:API通过主域名的子路径访问(如your-domain.com/api)
<VirtualHost *:443> ServerName your-domain.com # 保留原Web应用的配置... # 添加API反向代理规则 ProxyPass /api http://localhost:3000 ProxyPassReverse /api http://localhost:3000 # Certbot自动生成的SSL配置(无需修改) SSLCertificateFile /etc/letsencrypt/live/your-domain.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/your-domain.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf </VirtualHost>
场景2:API通过独立子域名访问(如api.your-domain.com)
先给子域名申请Certbot证书:
sudo certbot --apache -d api.your-domain.com
然后新建虚拟主机配置:
<VirtualHost *:443> ServerName api.your-domain.com # 反向代理到API的3000端口 ProxyPass / http://localhost:3000/ ProxyPassReverse / http://localhost:3000/ SSLCertificateFile /etc/letsencrypt/live/api.your-domain.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/api.your-domain.com/privkey.pem Include /etc/letsencrypt/options-ssl-apache.conf </VirtualHost>
步骤3:重启Apache服务
sudo systemctl restart apache2
方案对比
- 方案一:API直接处理SSL,无需依赖Apache,但需要手动维护证书权限,Certbot续期后可能需要重新同步证书文件。
- 方案二:通过Apache统一管理SSL,Certbot自动续期生效,无需修改API配置,更适合已有Apache环境的场景,推荐使用。
内容的提问来源于stack exchange,提问作者Valentin Garcia
相关产品推荐
相关产品推荐

