80端口被占用时,如何修改Certbot自动续期Timer实现无需手动启停服务?
解决Certbot自动续期端口80占用问题
方案一:改用Webroot插件(推荐,无需停止Web服务)
这是最稳妥的方式,Certbot会通过Web服务器的根目录完成验证,不用抢占80端口:
- 编辑域名的续期配置文件:
sudo nano /etc/letsencrypt/renewal/springwood.me.conf - 找到
[renewalparams]区块,把authenticator = standalone替换成:
比如Nginx默认根目录是authenticator = webroot webroot_path = /你的网站根目录路径/var/www/html,Apache是/var/www/html或对应虚拟主机的根目录,确保这个路径是Web服务器可访问、且Certbot有写入权限的目录。 - 测试配置有效性:
certbot renew --dry-run,确认不再出现端口占用报错。 - 原有的
snap.certbot.renew.timer无需修改,后续自动续期会自动使用Webroot方式完成验证。
方案二:修改Systemd服务,自动启停Web服务器
如果无法使用Webroot插件,可以让Certbot续期前后自动启停Web服务:
- 创建Systemd服务的覆盖配置目录:
sudo mkdir -p /etc/systemd/system/snap.certbot.renew.service.d - 创建覆盖配置文件:
sudo nano /etc/systemd/system/snap.certbot.renew.service.d/override.conf - 写入以下内容(把
nginx.service换成你的Web服务器服务名,比如apache2.service):[Service] ExecStartPre=/usr/bin/systemctl stop nginx.service ExecStartPost=/usr/bin/systemctl start nginx.service - 重新加载Systemd配置:
sudo systemctl daemon-reload - 测试服务:
sudo systemctl start snap.certbot.renew.service,检查Web服务是否自动启停,且Certbot完成续期。
内容的提问来源于stack exchange,提问作者billzt
相关产品推荐
相关产品推荐

