You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Let's Encrypt证书续期失败求助(ce.oclockdt.com)

无法为域名ce.oclockdt.com续期Let's Encrypt SSL证书

环境信息

  • 操作系统:Rocky Linux 8.6
  • Web服务器:Apache 2.4.37
  • Certbot版本:1.22.0
  • 控制面板:Virtualmin

问题描述

通过Virtualmin路径Server Configuration -> SSL Certificate -> Let's Encrypt -> Only Update Renewal执行证书续期时,报错:

Renewal failed due to Web-based validation failed

尝试手动执行Certbot命令:

sudo certbot certonly --manual -d ce.oclockdt.com

执行时出现EOFError,完整输出:

Renewing an existing certificate for ce.oclockdt.com

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Create a file containing just this data:

eUd3ZH9NU76e1rEfHcbmXlXutVP4-O7YnLR-Zidl_XM.hbNn4qOrcJOUJpXJpjW6kKIYWmrSPy_O3rVxzOvqKGE

And make it available on your web server at this URL:

http://ce.oclockdt.com/.well-known/acme-challenge/eUd3ZH9NU76e1rEfHcbmXlXutVP4-O7YnLR-Zidl_XM

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Press Enter to ContinueSaving debug log to /var/log/letsencrypt/letsencrypt.log
An unexpected error occurred:
EOFError
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

日志文件/var/log/letsencrypt/letsencrypt.log相关内容:

And make it available on your web server at this URL:

http://ce.oclockdt.com/.well-known/acme-challenge/eUd3ZH9NU76e1rEfHcbmXlXutVP4-O7YnLR-Zidl_XM

2023-06-14 11:17:46,909:DEBUG:certbot._internal.error_handler:Encountered exception:
Traceback (most recent call last):
  File "/usr/lib/python3.6/site-packages/certbot/_internal/auth_handler.py", line 85, in handle_authorizations
    resps = self.auth.perform(achalls)
  File "/usr/lib/python3.6/site-packages/certbot/_internal/plugins/manual.py", line 186, in perform
    self._perform_achall_manually(achall, i == last_dns_achall)
  File "/usr/lib/python3.6/site-packages/certbot/_internal/plugins/manual.py", line 234, in _perform_achall_manually
    display_util.notification(msg, wrap=False, force_interactive=True)
  File "/usr/lib/python3.6/site-packages/certbot/display/util.py", line 76, in notification
    force_interactive=force_interactive, decorate=decorate)
  File "/usr/lib/python3.6/site-packages/certbot/_internal/display/obj.py", line 95, in notification
    util.input_with_timeout("Press Enter to Continue")
  File "/usr/lib/python3.6/site-packages/certbot/_internal/display/util.py", line 67, in input_with_timeout
    raise EOFError
EOFError

已尝试的操作

  1. 创建/public_html/.well-known/acme-challenge目录,设置权限为0777
  2. 在该目录下添加.htaccess文件,内容如下:
Options +Indexes
Order allow,deny
Allow from all
  1. 检查Apache配置文件/etc/httpd/conf/httpd.conf,相关虚拟主机配置如下:
<VirtualHost 162.19.89.212:80 [2001:41d0:306:2cd4::]:80>
    ServerName ce.oclockdt.com
    ServerAlias www.ce.oclockdt.com
    ServerAlias mail.ce.oclockdt.com
    ServerAlias webmail.ce.oclockdt.com
    ServerAlias admin.ce.oclockdt.com
    DocumentRoot /home/ce/public_html/public
    ErrorLog /var/log/virtualmin/ce.oclockdt.com_error_log
    CustomLog /var/log/virtualmin/ce.oclockdt.com_access_log combined
    ScriptAlias /cgi-bin/ /home/ce/cgi-bin/
    DirectoryIndex index.php index.php4 index.php5 index.htm index.html
    <Directory /home/ce/public_html/public>
        Options -Indexes +IncludesNOEXEC +SymLinksIfOwnerMatch 
        Require all granted
        AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch
    </Directory>
    <Directory /home/ce/cgi-bin>
        Require all granted
        AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch
        SetHandler proxy:unix:/var/fcgiwrap/167161024797448.sock/socket|fcgi://localhost
        ProxyFCGISetEnvIf true SCRIPT_FILENAME "/home/ce%{reqenv:SCRIPT_NAME}"
    </Directory>
    ProxyPass /.well-known !
    RewriteEngine on
    RewriteCond %{HTTP_HOST} =webmail.ce.oclockdt.com
    RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:20000/ [R]
    RewriteCond %{HTTP_HOST} =admin.ce.oclockdt.com
    RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:10000/ [R]
    RemoveHandler .php
    RemoveHandler .php7.2
    RemoveHandler .php8.0
    RemoveHandler .php8.1
    <FilesMatch \.php$>
        SetHandler proxy:unix:/var/php-fpm/167161024797448.sock|fcgi://127.0.0.1
    </FilesMatch>
</VirtualHost>
<VirtualHost 162.19.89.212:443 [2001:41d0:306:2cd4::]:443>
    ServerName ce.oclockdt.com
    ServerAlias www.ce.oclockdt.com
    ServerAlias mail.ce.oclockdt.com
    ServerAlias webmail.ce.oclockdt.com
    ServerAlias admin.ce.oclockdt.com
    DocumentRoot /home/ce/public_html/public
    ErrorLog /var/log/virtualmin/ce.oclockdt.com_error_log
    CustomLog /var/log/virtualmin/ce.oclockdt.com_access_log combined
    ScriptAlias /cgi-bin/ /home/ce/cgi-bin/
    DirectoryIndex index.php index.php4 index.php5 index.htm index.html
    <Directory /home/ce/public_html/public>
        Options -Indexes +IncludesNOEXEC +SymLinksIfOwnerMatch 
        Require all granted
        AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch
    </Directory>
    <Directory /home/ce/cgi-bin>
        Require all granted
        AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch
        SetHandler proxy:unix:/var/fcgiwrap/167161024797448.sock/socket|fcgi://localhost
        ProxyFCGISetEnvIf true SCRIPT_FILENAME "/home/ce%{reqenv:SCRIPT_NAME}"
    </Directory>
    ProxyPass /.well-known !
    RewriteEngine on
    RewriteCond %{HTTP_HOST} =webmail.ce.oclockdt.com
    RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:20000/ [R]
    RewriteCond %{HTTP_HOST} =admin.ce.oclockdt.com
    RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:10000/ [R]
    RemoveHandler .php
    RemoveHandler .php7.2
    RemoveHandler .php8.0
    RemoveHandler .php8.1
    <FilesMatch \.php$>
        SetHandler proxy:unix:/var/php-fpm/167161024797448.sock|fcgi://127.0.0.1
    </FilesMatch>
    SSLEngine on
    SSLCertificateFile /etc/ssl/virtualmin/167161024797448/ssl.cert
    SSLCertificateKeyFile /etc/ssl/virtualmin/167161024797448/ssl.key
    SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1
    SSLCACertificateFile /etc/ssl/virtualmin/167161024797448/ssl.ca
</VirtualHost>
  1. 重启服务器,问题仍未解决

怀疑Let's Encrypt无法在/public_html/.well-known/acme-challenge目录创建测试文件,但该目录已设置0777权限,寻求解决办法。


解决办法

1. 修复手动Certbot命令的EOFError问题

EOFError是因为你在非交互式环境下运行了--manual命令(比如SSH后台会话或脚本),Certbot需要交互式输入但得不到响应。解决方式:

  • 如果在SSH会话中运行,确保会话是交互式的,不要用nohup或后台执行;
  • 添加--manual-public-ip-logging-ok参数,同时在命令提示输入回车时及时响应:
sudo certbot certonly --manual --manual-public-ip-logging-ok -d ce.oclockdt.com

2. 修正验证目录的实际路径

你的Apache虚拟主机DocumentRoot是/home/ce/public_html/public,所以正确的验证目录路径应该是/home/ce/public_html/public/.well-known/acme-challenge,而非你创建的/public_html/.well-known/acme-challenge,这是核心问题:

  1. 创建正确的目录:
mkdir -p /home/ce/public_html/public/.well-known/acme-challenge
  1. 设置合理权限(不需要0777,给Apache运行用户权限即可):
chown apache:apache /home/ce/public_html/public/.well-known/acme-challenge
chmod 755 /home/ce/public_html/public/.well-known/acme-challenge
  1. 测试文件访问:在该目录下创建test.txt文件,内容随意,访问http://ce.oclockdt.com/.well-known/acme-challenge/test.txt,确保能正常打开。

3. 优化Apache配置中的验证路径规则

在80端口的VirtualHost中添加专属目录规则,避免被其他配置干扰:

<Directory /home/ce/public_html/public/.well-known/acme-challenge>
    Options +Indexes
    Require all granted
    AllowOverride None
</Directory>

添加后重启Apache:

sudo systemctl restart httpd

4. 使用Certbot Apache插件自动续期

避免手动操作的麻烦,直接用Certbot的Apache插件自动处理验证和续期:

sudo certbot renew --apache

如果是首次配置或需要重新生成证书,可执行:

sudo certbot --apache -d ce.oclockdt.com

5. 检查防火墙和端口

确保服务器80端口(HTTP)对外开放,Let's Encrypt的HTTP验证必须访问80端口:

  • 查看已开放端口:
sudo firewall-cmd --list-ports
  • 若80端口未开放,添加并重启防火墙:
sudo firewall-cmd --add-port=80/tcp --permanent
sudo firewall-cmd --reload

内容的提问来源于stack exchange,提问作者Telerín

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 23:07:02