重新颁发的SSL证书替换文件在Apache VirtualHost配置中的指定方法
Got it, let's get your Apache setup sorted for both your root domain and www subdomain with their respective SSL certificates. Here's a step-by-step guide tailored to your Ubuntu 16.04/Apache 2.4.18 environment:
Step 1: Securely Store Your New WWW Certificates
First, make sure your new www-specific SSL files are placed in Apache's standard SSL directories on Ubuntu:
- Drop your certificate file (e.g.,
www-domain-cert.pem) into/etc/ssl/certs/ - Place the corresponding private key (e.g.,
www-domain-key.pem) into/etc/ssl/private/
Critical security note: Private keys need tight permissions to prevent unauthorized access. Run these commands to lock them down:
sudo chmod 600 /etc/ssl/private/www-domain-key.pem sudo chown root:root /etc/ssl/private/www-domain-key.pem
Step 2: Update Apache VirtualHost Configurations
You'll need separate HTTPS VirtualHost blocks for your root domain (using the original cert) and www subdomain (using the new cert). You can edit your existing SSL config file (usually at /etc/apache2/sites-available/your-site-ssl.conf) or create new blocks as needed.
First: Redirect HTTP to HTTPS for Both Domains
Add this to your HTTP config file (e.g., /etc/apache2/sites-available/your-site.conf) to ensure all traffic uses HTTPS:
<VirtualHost *:80> ServerName domain-name.com ServerAlias www.domain-name.com Redirect permanent / https://%{HTTP_HOST}%{REQUEST_URI} </VirtualHost>
Second: Configure HTTPS for Root Domain (Original Cert)
Add this block to your SSL config to handle the non-www domain with your existing certificate:
<VirtualHost *:443> ServerName domain-name.com # Enable SSL SSLEngine on # Paths to your original SSL files SSLCertificateFile /etc/ssl/certs/original-domain-cert.pem SSLCertificateKeyFile /etc/ssl/private/original-domain-key.pem # Uncomment if your CA provided an intermediate/chain certificate # SSLCertificateChainFile /etc/ssl/certs/original-chain.pem # Standard site settings DocumentRoot /var/www/html/your-site-directory ErrorLog ${APACHE_LOG_DIR}/domain-name.com-error.log CustomLog ${APACHE_LOG_DIR}/domain-name.com-access.log combined # Optional (but recommended) security headers Header always set X-Content-Type-Options nosniff Header always set X-Frame-Options DENY </VirtualHost>
Third: Configure HTTPS for WWW Subdomain (New Cert)
Add this separate block to handle the www subdomain with your new certificate:
<VirtualHost *:443> ServerName www.domain-name.com SSLEngine on # Paths to your NEW www SSL files SSLCertificateFile /etc/ssl/certs/www-domain-cert.pem SSLCertificateKeyFile /etc/ssl/private/www-domain-key.pem # Uncomment if your CA provided an intermediate/chain certificate for the www cert # SSLCertificateChainFile /etc/ssl/certs/www-chain.pem # Match your root domain's document root unless you need separate content DocumentRoot /var/www/html/your-site-directory ErrorLog ${APACHE_LOG_DIR}/www.domain-name.com-error.log CustomLog ${APACHE_LOG_DIR}/www.domain-name.com-access.log combined # Same security headers as above (if using) Header always set X-Content-Type-Options nosniff Header always set X-Frame-Options DENY </VirtualHost>
Step 3: Validate Config & Restart Apache
Before applying changes, check for syntax errors to avoid breaking your server:
sudo apache2ctl configtest
You should see Syntax OK if everything is set correctly.
Then restart Apache to activate the new config:
sudo systemctl restart apache2
Step 4: Verify the Setup
- Visit
https://domain-name.comandhttps://www.domain-name.comin your browser, then check the certificate details to confirm each uses the correct SSL file. - For a command-line check, run this to inspect the www cert:
Look for theopenssl s_client -connect www.domain-name.com:443Subjectline in the output to confirm it matcheswww.domain-name.com.
A quick future tip: If you want to avoid managing separate certs, you could get a SAN (Subject Alternative Name) certificate (covers both domain-name.com and www.domain-name.com) or a wildcard certificate (covers all subdomains like *.domain-name.com) next time.
内容的提问来源于stack exchange,提问作者mlclm

