You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

certbot-auto扩展SSL证书至新域名失败(403 Forbidden错误)

Hey there, let's tackle this 403 Forbidden issue you're hitting when expanding your Let's Encrypt certificate with Certbot. This is almost always tied to the HTTP-01 validation challenge that Certbot uses to verify domain ownership—so let's break down the fixes step by step:

1. Fix Your New Subdomain's Virtual Host Configuration

Certbot needs unobstructed access to the /.well-known/acme-challenge/ path over HTTP to validate your new subdomain. If your Virtual Host is blocking this path (or missing the necessary permissions), you'll get a 403.

What to check:

  • Open your new subdomain's config file in /etc/apache2/sites-available/ (e.g., sub3.domain.com.conf)
  • Ensure the port 80 (HTTP) block includes explicit access permissions for the challenge path. Add this if it's missing:
    <VirtualHost *:80>
        ServerName sub3.domain.com
        DocumentRoot /var/www/sub3  # Adjust this to match your subdomain's actual root
    
        # Allow Certbot to access the challenge directory
        Alias /.well-known/acme-challenge/ /var/www/sub3/.well-known/acme-challenge/
        <Directory /var/www/sub3/.well-known/acme-challenge/>
            Options FollowSymLinks
            AllowOverride None
            Require all granted
        </Directory>
    
        # Fix HTTPS redirect to exclude challenge requests
        RewriteEngine On
        RewriteCond %{REQUEST_URI} !^/.well-known/acme-challenge/
        RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301,L]
    </VirtualHost>
    
  • Save the file, then enable the site (if you haven't already) and reload Apache:
    sudo a2ensite sub3.domain.com.conf
    sudo systemctl reload apache2
    

2. Verify File System Permissions

Even if your Apache config is correct, incorrect file ownership or permissions on the challenge directory will cause a 403.

Run these commands to set the right permissions (adjust the path to match your subdomain's DocumentRoot):

# Create the challenge directory if it doesn't exist
sudo mkdir -p /var/www/sub3/.well-known/acme-challenge/
# Set ownership to Apache's user (www-data)
sudo chown -R www-data:www-data /var/www/sub3/.well-known/
# Set read/write/execute permissions for the owner, read/execute for others
sudo chmod -R 755 /var/www/sub3/.well-known/

3. Test the Challenge Path Manually

Before re-running Certbot, confirm the path is accessible. Create a test file and curl it:

# Create a test file
sudo echo "certbot-test" > /var/www/sub3/.well-known/acme-challenge/test-file
# Test access over HTTP
curl http://sub3.domain.com/.well-known/acme-challenge/test-file

If you see certbot-test returned, the path is working. If you still get a 403, double-check your Apache config and permissions.

4. Re-Run Certbot to Expand the Certificate

Now run the Certbot command to expand your existing certificate to include the new subdomain. Use the --expand flag to avoid creating a new certificate:

sudo ./certbot-auto certonly --apache --expand -d domain.com -d sub1.domain.com -d sub2.domain.com -d sub3.domain.com

Make sure to list all existing domains plus the new one to keep them all on the same certificate.

5. Debug with Apache Error Logs

If you still hit a 403, check Apache's error logs for specific details (this will tell you exactly why access is being denied):

sudo tail -f /var/log/apache2/error.log

Look for lines mentioning /.well-known/acme-challenge/—common issues include client denied by server configuration (config issue) or permission denied (file system issue).


内容的提问来源于stack exchange,提问作者CGriffin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:39:56