You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon Lightsail移除过期Let's Encrypt SSL证书并安装亚马逊自有证书求助

Hey there! Let's tackle your two SSL certificate issues step by step—removing that expired Let's Encrypt cert and setting up Amazon's own SSL certificate. I've messed around with similar setups before, so here's what works:

1. Removing the Expired Let's Encrypt SSL Certificate

The exact steps depend on which web server you're using (Apache or Nginx), so I'll cover both:

For Apache

  • First, locate where your Let's Encrypt cert is referenced in Apache's config. Run apache2ctl -S (or httpd -S on RHEL/CentOS) to list your virtual hosts—look for lines like SSLCertificateFile and SSLCertificateKeyFile pointing to /etc/letsencrypt/live/your-domain/.
  • Always back up your config first: cp /etc/apache2/sites-available/your-domain.conf /etc/apache2/sites-available/your-domain.conf.bak
  • Edit the virtual host config file, and either comment out or delete the lines referencing the Let's Encrypt cert. For example:
    # SSLCertificateFile /etc/letsencrypt/live/your-domain/fullchain.pem
    # SSLCertificateKeyFile /etc/letsencrypt/live/your-domain/privkey.pem
    
  • Verify the config is valid: apache2ctl configtest (or httpd configtest)
  • Restart Apache to apply changes: systemctl restart apache2 (or service httpd restart)
  • (Optional) If you're sure you'll never use Let's Encrypt again for this domain, delete the cert files:
    rm -rf /etc/letsencrypt/live/your-domain/
    rm -rf /etc/letsencrypt/archive/your-domain/
    rm /etc/letsencrypt/renewal/your-domain.conf
    

For Nginx

  • Find your Nginx virtual host config (usually in /etc/nginx/sites-available/ or /etc/nginx/conf.d/). Look for ssl_certificate and ssl_certificate_key lines pointing to Let's Encrypt files.
  • Back up your config: cp /etc/nginx/sites-available/your-domain.conf /etc/nginx/sites-available/your-domain.conf.bak
  • Edit the config to comment out or remove the Let's Encrypt cert references:
    # ssl_certificate /etc/letsencrypt/live/your-domain/fullchain.pem;
    # ssl_certificate_key /etc/letsencrypt/live/your-domain/privkey.pem;
    
  • Check for config errors: nginx -t
  • Restart Nginx: systemctl restart nginx
  • (Optional) Delete the old cert files same as the Apache section above.
2. Installing Amazon's Own SSL Certificate

This depends on whether you're using AWS services like a Load Balancer/CloudFront, or installing directly on your EC2 server:

Option A: Using AWS Certificate Manager (ACM) with ALB/CloudFront

ACM's free certificates are super convenient, and you don't have to manage them on your server directly:

  • First, go to the AWS Certificate Manager console and either request a free certificate for your domain, or import an existing Amazon-provided certificate if you have one. Make sure the certificate covers your target domain(s).
  • For Application Load Balancer (ALB):
    1. Go to the EC2 Console > Load Balancers > Select your ALB.
    2. Go to the "Listeners" tab, edit the HTTPS listener.
    3. Under "SSL certificate", select "From ACM" and pick your newly created/imported certificate.
    4. Save the changes—your ALB will now handle SSL termination, so you can remove the cert config from your backend EC2 server entirely.
  • For CloudFront:
    1. Go to the CloudFront Console > Select your distribution.
    2. Edit the "General" settings, then under "SSL Certificate", choose "Custom SSL Certificate" and select your ACM certificate (note: ACM certs for CloudFront must be in the us-east-1 region).
    3. Save and wait for CloudFront to deploy the changes (this can take a few minutes).

Option B: Installing Directly on EC2 (Apache/Nginx)

If you have a standalone Amazon SSL certificate (like a purchased one) to install on your server:

  • First, upload your certificate files to your server—you'll need:
    • The main certificate file (e.g., your-domain.crt)
    • Your private key file (e.g., your-domain.key)
    • The intermediate CA bundle (e.g., ca-bundle.crt)
  • Move them to a secure directory, like /etc/ssl/amazon/, and set proper permissions:
    mkdir -p /etc/ssl/amazon/
    chmod 600 /etc/ssl/amazon/your-domain.key  # Keep private key secure
    chmod 644 /etc/ssl/amazon/your-domain.crt /etc/ssl/amazon/ca-bundle.crt
    
  • For Apache: Edit your HTTPS virtual host config and add these lines:
    SSLCertificateFile /etc/ssl/amazon/your-domain.crt
    SSLCertificateKeyFile /etc/ssl/amazon/your-domain.key
    SSLCertificateChainFile /etc/ssl/amazon/ca-bundle.crt
    
    Validate config with apache2ctl configtest, then restart Apache.
  • For Nginx: Edit your HTTPS server block and add these lines:
    ssl_certificate /etc/ssl/amazon/your-domain.crt;
    ssl_certificate_key /etc/ssl/amazon/your-domain.key;
    ssl_trusted_certificate /etc/ssl/amazon/ca-bundle.crt;
    
    Check config with nginx -t, then restart Nginx.

Once everything is set up, test your HTTPS connection to make sure the new certificate is working—you can use your browser's dev tools or an online checker to confirm no expired cert warnings show up.

内容的提问来源于stack exchange,提问作者Sachin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 06:37:08