Let's Encrypt证书续期失败求助(ce.oclockdt.com)
环境信息
- 操作系统:Rocky Linux 8.6
- Web服务器:Apache 2.4.37
- Certbot版本:1.22.0
- 控制面板:Virtualmin
问题描述
通过Virtualmin路径Server Configuration -> SSL Certificate -> Let's Encrypt -> Only Update Renewal执行证书续期时,报错:
Renewal failed due to Web-based validation failed
尝试手动执行Certbot命令:
sudo certbot certonly --manual -d ce.oclockdt.com
执行时出现EOFError,完整输出:
Renewing an existing certificate for ce.oclockdt.com - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Create a file containing just this data: eUd3ZH9NU76e1rEfHcbmXlXutVP4-O7YnLR-Zidl_XM.hbNn4qOrcJOUJpXJpjW6kKIYWmrSPy_O3rVxzOvqKGE And make it available on your web server at this URL: http://ce.oclockdt.com/.well-known/acme-challenge/eUd3ZH9NU76e1rEfHcbmXlXutVP4-O7YnLR-Zidl_XM - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Press Enter to ContinueSaving debug log to /var/log/letsencrypt/letsencrypt.log An unexpected error occurred: EOFError Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
日志文件/var/log/letsencrypt/letsencrypt.log相关内容:
And make it available on your web server at this URL: http://ce.oclockdt.com/.well-known/acme-challenge/eUd3ZH9NU76e1rEfHcbmXlXutVP4-O7YnLR-Zidl_XM 2023-06-14 11:17:46,909:DEBUG:certbot._internal.error_handler:Encountered exception: Traceback (most recent call last): File "/usr/lib/python3.6/site-packages/certbot/_internal/auth_handler.py", line 85, in handle_authorizations resps = self.auth.perform(achalls) File "/usr/lib/python3.6/site-packages/certbot/_internal/plugins/manual.py", line 186, in perform self._perform_achall_manually(achall, i == last_dns_achall) File "/usr/lib/python3.6/site-packages/certbot/_internal/plugins/manual.py", line 234, in _perform_achall_manually display_util.notification(msg, wrap=False, force_interactive=True) File "/usr/lib/python3.6/site-packages/certbot/display/util.py", line 76, in notification force_interactive=force_interactive, decorate=decorate) File "/usr/lib/python3.6/site-packages/certbot/_internal/display/obj.py", line 95, in notification util.input_with_timeout("Press Enter to Continue") File "/usr/lib/python3.6/site-packages/certbot/_internal/display/util.py", line 67, in input_with_timeout raise EOFError EOFError
已尝试的操作
- 创建
/public_html/.well-known/acme-challenge目录,设置权限为0777 - 在该目录下添加
.htaccess文件,内容如下:
Options +Indexes Order allow,deny Allow from all
- 检查Apache配置文件
/etc/httpd/conf/httpd.conf,相关虚拟主机配置如下:
<VirtualHost 162.19.89.212:80 [2001:41d0:306:2cd4::]:80> ServerName ce.oclockdt.com ServerAlias www.ce.oclockdt.com ServerAlias mail.ce.oclockdt.com ServerAlias webmail.ce.oclockdt.com ServerAlias admin.ce.oclockdt.com DocumentRoot /home/ce/public_html/public ErrorLog /var/log/virtualmin/ce.oclockdt.com_error_log CustomLog /var/log/virtualmin/ce.oclockdt.com_access_log combined ScriptAlias /cgi-bin/ /home/ce/cgi-bin/ DirectoryIndex index.php index.php4 index.php5 index.htm index.html <Directory /home/ce/public_html/public> Options -Indexes +IncludesNOEXEC +SymLinksIfOwnerMatch Require all granted AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch </Directory> <Directory /home/ce/cgi-bin> Require all granted AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch SetHandler proxy:unix:/var/fcgiwrap/167161024797448.sock/socket|fcgi://localhost ProxyFCGISetEnvIf true SCRIPT_FILENAME "/home/ce%{reqenv:SCRIPT_NAME}" </Directory> ProxyPass /.well-known ! RewriteEngine on RewriteCond %{HTTP_HOST} =webmail.ce.oclockdt.com RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:20000/ [R] RewriteCond %{HTTP_HOST} =admin.ce.oclockdt.com RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:10000/ [R] RemoveHandler .php RemoveHandler .php7.2 RemoveHandler .php8.0 RemoveHandler .php8.1 <FilesMatch \.php$> SetHandler proxy:unix:/var/php-fpm/167161024797448.sock|fcgi://127.0.0.1 </FilesMatch> </VirtualHost> <VirtualHost 162.19.89.212:443 [2001:41d0:306:2cd4::]:443> ServerName ce.oclockdt.com ServerAlias www.ce.oclockdt.com ServerAlias mail.ce.oclockdt.com ServerAlias webmail.ce.oclockdt.com ServerAlias admin.ce.oclockdt.com DocumentRoot /home/ce/public_html/public ErrorLog /var/log/virtualmin/ce.oclockdt.com_error_log CustomLog /var/log/virtualmin/ce.oclockdt.com_access_log combined ScriptAlias /cgi-bin/ /home/ce/cgi-bin/ DirectoryIndex index.php index.php4 index.php5 index.htm index.html <Directory /home/ce/public_html/public> Options -Indexes +IncludesNOEXEC +SymLinksIfOwnerMatch Require all granted AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch </Directory> <Directory /home/ce/cgi-bin> Require all granted AllowOverride All Options=ExecCGI,Includes,IncludesNOEXEC,Indexes,MultiViews,SymLinksIfOwnerMatch SetHandler proxy:unix:/var/fcgiwrap/167161024797448.sock/socket|fcgi://localhost ProxyFCGISetEnvIf true SCRIPT_FILENAME "/home/ce%{reqenv:SCRIPT_NAME}" </Directory> ProxyPass /.well-known ! RewriteEngine on RewriteCond %{HTTP_HOST} =webmail.ce.oclockdt.com RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:20000/ [R] RewriteCond %{HTTP_HOST} =admin.ce.oclockdt.com RewriteRule ^(?!/.well-known)(.*) https://ce.oclockdt.com:10000/ [R] RemoveHandler .php RemoveHandler .php7.2 RemoveHandler .php8.0 RemoveHandler .php8.1 <FilesMatch \.php$> SetHandler proxy:unix:/var/php-fpm/167161024797448.sock|fcgi://127.0.0.1 </FilesMatch> SSLEngine on SSLCertificateFile /etc/ssl/virtualmin/167161024797448/ssl.cert SSLCertificateKeyFile /etc/ssl/virtualmin/167161024797448/ssl.key SSLProtocol all -SSLv2 -SSLv3 -TLSv1 -TLSv1.1 SSLCACertificateFile /etc/ssl/virtualmin/167161024797448/ssl.ca </VirtualHost>
- 重启服务器,问题仍未解决
怀疑Let's Encrypt无法在/public_html/.well-known/acme-challenge目录创建测试文件,但该目录已设置0777权限,寻求解决办法。
1. 修复手动Certbot命令的EOFError问题
EOFError是因为你在非交互式环境下运行了--manual命令(比如SSH后台会话或脚本),Certbot需要交互式输入但得不到响应。解决方式:
- 如果在SSH会话中运行,确保会话是交互式的,不要用
nohup或后台执行; - 添加
--manual-public-ip-logging-ok参数,同时在命令提示输入回车时及时响应:
sudo certbot certonly --manual --manual-public-ip-logging-ok -d ce.oclockdt.com
2. 修正验证目录的实际路径
你的Apache虚拟主机DocumentRoot是/home/ce/public_html/public,所以正确的验证目录路径应该是/home/ce/public_html/public/.well-known/acme-challenge,而非你创建的/public_html/.well-known/acme-challenge,这是核心问题:
- 创建正确的目录:
mkdir -p /home/ce/public_html/public/.well-known/acme-challenge
- 设置合理权限(不需要0777,给Apache运行用户权限即可):
chown apache:apache /home/ce/public_html/public/.well-known/acme-challenge chmod 755 /home/ce/public_html/public/.well-known/acme-challenge
- 测试文件访问:在该目录下创建
test.txt文件,内容随意,访问http://ce.oclockdt.com/.well-known/acme-challenge/test.txt,确保能正常打开。
3. 优化Apache配置中的验证路径规则
在80端口的VirtualHost中添加专属目录规则,避免被其他配置干扰:
<Directory /home/ce/public_html/public/.well-known/acme-challenge> Options +Indexes Require all granted AllowOverride None </Directory>
添加后重启Apache:
sudo systemctl restart httpd
4. 使用Certbot Apache插件自动续期
避免手动操作的麻烦,直接用Certbot的Apache插件自动处理验证和续期:
sudo certbot renew --apache
如果是首次配置或需要重新生成证书,可执行:
sudo certbot --apache -d ce.oclockdt.com
5. 检查防火墙和端口
确保服务器80端口(HTTP)对外开放,Let's Encrypt的HTTP验证必须访问80端口:
- 查看已开放端口:
sudo firewall-cmd --list-ports
- 若80端口未开放,添加并重启防火墙:
sudo firewall-cmd --add-port=80/tcp --permanent sudo firewall-cmd --reload
内容的提问来源于stack exchange,提问作者Telerín

