You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Amazon Linux上使用LetsEncrypt Certbot创建SSL证书失败求助

Fixing Certbot LetsEncrypt SSL Setup on Amazon Linux 2017.09 (Apache)

I’ve run into this exact frustration with older Amazon Linux releases—Certbot’s repo support is spotty here, but we can get it working with manual setup tweaks. Here’s what you need to do:

Step 1: Install Required System Dependencies

First, make sure all the base packages needed for Certbot to build and run are installed. Amazon Linux 2017.09 is missing some of these by default:

sudo yum install -y gcc augeas-libs dialog python27-devel python27-virtualenv libffi-devel openssl-devel

These packages handle compilation, virtual environment management, and SSL-related utilities that Certbot relies on.

Step 2: Fix Permissions for certbot-auto

After downloading certbot-auto, ensure it has execute permissions:

chmod +x ./certbot-auto

You’ll need to run this tool with root privileges, so prepend sudo to all commands below.

Step 3: Run Certbot with Python 2.7 Specification

Older Amazon Linux versions have Python 2.7 as the stable default, but Certbot might try to use an incompatible version. Force it to use Python 2.7 with debug mode to catch any remaining issues:

sudo ./certbot-auto --apache --debug --python /usr/bin/python2.7

The --apache flag tells Certbot to automatically configure your Apache virtual hosts for SSL, and --debug will show detailed logs if something fails.

Step 4: Fallback Manual Installation (If certbot-auto Still Fails)

If the automated tool keeps breaking, set up a dedicated Python virtual environment and install Certbot manually:

  • Create a virtual environment for Certbot:
    sudo virtualenv -p python2.7 /opt/certbot
    
  • Activate the virtual environment:
    sudo source /opt/certbot/bin/activate
    
  • Install Certbot and its Apache plugin:
    pip install certbot certbot-apache
    
  • Run the Certbot setup wizard:
    certbot --apache
    

Step 5: Set Up Auto-Renewal

Once your certificate is installed, ensure it renews automatically. Add a cron job to check for renewals daily:

echo "0 12 * * * root /opt/certbot/bin/certbot renew --quiet" | sudo tee -a /etc/crontab

(If you used certbot-auto, replace the path with ./certbot-auto or the full path where you saved it.)

A quick note: Amazon Linux 2017.09 is end-of-life, so consider upgrading to a newer Amazon Linux 2 or 2023 release long-term—Certbot support is much better there.

内容的提问来源于stack exchange,提问作者RTF

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:19:16