You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS实例部署Mastodon:bncert-tool生成证书超时问题求助

解决Bitnami bncert-tool超时无法获取证书的方法
  • 检查AWS安全组规则
    Let's Encrypt的ACME验证需要通过80、443端口访问服务器,务必确保AWS安全组开放这两个端口:
    登录AWS控制台,进入EC2实例详情页,找到关联的安全组,在入站规则中添加:

    • 类型选HTTP(80),源设置为0.0.0.0/0和::/0
    • 类型选HTTPS(443),源设置为0.0.0.0/0和::/0
  • 排查服务器本地防火墙
    先查看系统防火墙状态:

    sudo ufw status
    

    如果启用了ufw,执行以下命令开放端口并重载规则:

    sudo ufw allow 80/tcp
    sudo ufw allow 443/tcp
    sudo ufw reload
    

    若使用firewalld,执行:

    sudo firewall-cmd --add-service=http --permanent
    sudo firewall-cmd --add-service=https --permanent
    sudo firewall-cmd --reload
    
  • 验证端口连通性与域名解析
    在本地终端用curl测试域名80端口的连通性:

    curl -I http://yourdoma.in
    

    若返回HTTP 200或3xx状态码,说明端口正常;如果仍超时,检查域名A/AAAA记录是否正确指向实例公网IP,确认没有CDN、反向代理等中间节点拦截请求。

  • 手动获取证书(备选方案)
    如果bncert-tool持续失败,可改用certbot手动获取证书:

    1. 安装certbot:
      sudo apt update && sudo apt install certbot
      
    2. 通过webroot模式获取证书:
      sudo certbot certonly --webroot -w /opt/bitnami/apache/htdocs -d yourdoma.in
      
    3. 将证书链接到Bitnami的证书目录:
      sudo ln -sf /etc/letsencrypt/live/yourdoma.in/fullchain.pem /opt/bitnami/apache/conf/bitnami/certs/server.crt
      sudo ln -sf /etc/letsencrypt/live/yourdoma.in/privkey.pem /opt/bitnami/apache/conf/bitnami/certs/server.key
      
    4. 重启Apache服务:
      sudo /opt/bitnami/ctlscript.sh restart apache
      

内容的提问来源于stack exchange,提问作者user2420974

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 19:15:00