You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Nginx反向代理Certbot认证失败(unauthorized)问题求助

Nginx配置修复:Certbot验证失败问题

问题背景

我是Nginx新手,最初配置里缺少SSL证书相关配置:

ssl_certificate /etc/ssl/certs/crt.crt; // 由openssl生成
ssl_certificate_key /etc/ssl/private/crt.key; // 由openssl生成

尝试获取安装证书出错后,我用OpenSSL生成证书并添加到配置中,当前完整配置如下:

server {
    listen 80;
    server_tokens off;
    resolver 127.0.0.11 ipv6=off;
    server_name GENERIC-SUB-DOMAIN;
}

server {
    listen 443 ssl http2;
    server_name GENERIC-SUB-DOMAIN;
    server_tokens off;
    resolver 127.0.0.11 ipv6=off;
    proxy_pass_header Server;
    ssl_certificate /etc/ssl/certs/crt.crt; // 由openssl生成
    ssl_certificate_key /etc/ssl/private/crt.key; // 由openssl生成
    location / {
        set $do_not_cache 1;
        if ($request_uri ~* "\.(css|json|js|text|png|jpg|map|ico|svg|mp3|mp4|txt|jfproj|etx|pfa|fnt|vlw|woff|fot|ttf|sfd|pfb|vfb|otf|gxf|odttf|woff2|pf2|bf|ttc|chr|bdf|fon)") {
           set $do_not_cache 0;
        }
        proxy_http_version 1.1;
        proxy_pass http://localhost:9500;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "Upgrade";
        proxy_cache seocromom_cache;
        proxy_cache_valid 24h;
        proxy_cache_bypass $do_not_cache;
        proxy_no_cache $do_not_cache;
        proxy_cache_key "$host$uri$is_args$args";
        proxy_cache_lock on;
    }

}

错误信息

运行Certbot时出现以下错误:

Enter PEM pass phrase:
Certbot failed to authenticate some domains (authenticator: nginx). The Certificate Authority reported these problems:
Domain: domain
Type: unauthorized
Detail: ip: Invalid response from http://domain/.well-known/acme-challenge/60NcdFtxVU3D8au-VAYtqbkg8meWXTqgorOxOqT-n9E: 404

Hint: The Certificate Authority failed to verify the temporary nginx configuration changes made by Certbot. Ensure the listed domains point to this nginx server and that it is accessible from the internet.

Enter PEM pass phrase:
Some challenges have failed.
See the logfile /var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.

修复方案

1. 完善80端口配置

当前80端口的server块没有处理ACME验证请求的规则,导致验证文件无法被访问。修改80端口配置:

server {
    listen 80;
    server_tokens off;
    resolver 127.0.0.11 ipv6=off;
    server_name GENERIC-SUB-DOMAIN;

    # 专门处理ACME验证请求,避免被代理到后端
    location /.well-known/acme-challenge/ {
        root /var/www/html; # 先确保该目录存在,权限设为www-data可读
        try_files $uri =404;
    }

    # 其余请求重定向到HTTPS
    location / {
        return 301 https://$host$request_uri;
    }
}

2. 移除SSL密钥的密码保护

你的SSL密钥设置了PEM密码,Certbot无法自动处理带密码的密钥,这会导致验证失败。执行命令生成无密码密钥:

openssl rsa -in /etc/ssl/private/crt.key -out /etc/ssl/private/crt_nopass.key

然后修改443端口server块中的密钥路径:

ssl_certificate_key /etc/ssl/private/crt_nopass.key;

3. 验证基础条件

  • 确认域名GENERIC-SUB-DOMAIN已正确解析到服务器公网IP
  • 确保服务器防火墙/安全组开放了80、443端口

4. 重新执行Certbot

先测试Nginx配置合法性:

nginx -t

测试通过后重启Nginx:

systemctl restart nginx

最后重新运行Certbot:

certbot --nginx -d GENERIC-SUB-DOMAIN

内容的提问来源于stack exchange,提问作者Silent Sea

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.20 05:27:25