使用--work-dir生成证书后,certbot renew无法识别证书目录的求助
解决Certbot续期时无法识别自定义目录证书的问题
我之前也踩过这个坑!当你用--work-dir等自定义目录参数生成证书后,续期时必须同步指定所有当时用到的自定义目录参数,不然Certbot会默认去系统默认的/etc/letsencrypt目录找续期配置,自然找不到你的证书,就会提示“No renewals were attempted”。
具体解决步骤:
首先回忆你生成证书时的完整命令,比如当时可能是这样的:
certbot certonly --work-dir /your/custom/work-dir --config-dir /your/custom/config-dir --logs-dir /your/custom/logs-dir -d yourdomain.com这里要注意:
--work-dir只是临时工作目录,真正存储续期配置文件的是--config-dir(里面的renewal文件夹会保存每个域名的续期配置),所以续期时这个参数是必须的。续期时,把所有自定义目录参数都加到命令里:
certbot renew --work-dir /your/custom/work-dir --config-dir /your/custom/config-dir --logs-dir /your/custom/logs-dir运行这个命令后,Certbot就能找到你的证书配置并尝试续期了。
如果想一劳永逸,不用每次都输这些参数,可以创建一个Certbot的配置文件:
比如在自定义目录下创建cli.ini,内容如下:work-dir = /your/custom/work-dir config-dir = /your/custom/config-dir logs-dir = /your/custom/logs-dir之后续期时只需运行:
certbot renew --config-file /path/to/your/cli.ini要是把
cli.ini放在默认位置/etc/letsencrypt/cli.ini,直接运行certbot renew就会自动读取配置。
补充说明:
出现“No renewals were attempted”的核心原因是:Certbot默认会去/etc/letsencrypt/config-dir查找renewal子目录下的配置文件,当你的证书配置存在自定义目录时,它找不到对应的配置,就会判定没有需要续期的证书,所以不会执行续期操作。
内容的提问来源于stack exchange,提问作者Muttface
相关产品推荐
相关产品推荐

