You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无主域名权限时如何为子域名申请Let's Encrypt SSL证书

Fixing Let's Encrypt SSL Certificate for Subdomains Without Main Domain Access

Hey there, let's break down how to resolve your issues and get a valid SSL certificate for subdomain.example.com—you absolutely don't need access to the main example.com domain to make this work. Let's tackle each problem one by one:

1. Fix the ACME HTTP-01 Challenge Access Error

The first error (where Let's Encrypt can't reach http://subdomain.example.com/.well-known/acme-challenge/) is about proving you control the subdomain via a simple file check. Here's how to fix it:

  • First, confirm your web server (Nginx, Apache, etc.) is properly configured to serve content for subdomain.example.com over HTTP. Visit http://subdomain.example.com directly to make sure it loads your app or a default page without issues.
  • Next, ensure the /.well-known/acme-challenge/ path isn't blocked or rewritten by your server config:
    • For Nginx, add this block to your subdomain.example.com server configuration:
      location ^~ /.well-known/acme-challenge/ {
          root /var/www/acme-challenges; # Use any directory your server can read/write to
          default_type text/plain;
      }
      
    • For Apache, add this to your virtual host config to allow unfiltered access:
      <Directory "/var/www/acme-challenges/.well-known/acme-challenge">
          AllowOverride None
          Require all granted
      </Directory>
      
  • Test manually: Create a test file (e.g., test-file.txt) with random content in the directory you specified, then visit http://subdomain.example.com/.well-known/acme-challenge/test-file.txt. You should see the file's content immediately.

2. Resolve the "Must Include Main Domain" Error

This error happens because your existing tool/script is probably trying to request a wildcard certificate (*.example.com) instead of a single subdomain certificate. Let's Encrypt fully supports certificates for individual subdomains—you just need to use the right command with a standard ACME client:

If you don't have Certbot installed, grab it via your system's package manager first. Then run this command, replacing the path with the directory you set up earlier:

certbot certonly --webroot -w /var/www/acme-challenges -d subdomain.example.com
  • --webroot tells Certbot to use the file-based validation method
  • -w specifies the directory where validation files will be placed
  • -d only lists your subdomain—do not include example.com here

Certbot will handle the rest: it creates the validation file, Let's Encrypt checks it, and you'll get a certificate only for subdomain.example.com.

Option 2: Use acme.sh

If you prefer acme.sh, install it then run:

acme.sh --issue -d subdomain.example.com --webroot /var/www/acme-challenges

Again, only specify the subdomain—no need to reference the main domain at all.

3. Deploy the Certificate

Once the certificate is generated:

  • For Certbot, your files will be in /etc/letsencrypt/live/subdomain.example.com/
  • For acme.sh, they'll be in ~/.acme.sh/subdomain.example.com/

Update your web server's HTTPS configuration to use these certificate files, then restart the server. Your subdomain should now load over HTTPS without issues.

Why Did the "Main Domain" Error Happen?

Chances are your initial tool (like a hosting panel's automated SSL feature) was defaulting to a wildcard certificate request. Wildcard certificates require verifying control over the main domain, but you don't need that for a single subdomain. Using a standard ACME client and explicitly targeting only subdomain.example.com avoids this problem entirely.

内容的提问来源于stack exchange,提问作者Sjoerd de Wit

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 04:01:12