无主域名权限时如何为子域名申请Let's Encrypt SSL证书
Hey there, let's break down how to resolve your issues and get a valid SSL certificate for subdomain.example.com—you absolutely don't need access to the main example.com domain to make this work. Let's tackle each problem one by one:
1. Fix the ACME HTTP-01 Challenge Access Error
The first error (where Let's Encrypt can't reach http://subdomain.example.com/.well-known/acme-challenge/) is about proving you control the subdomain via a simple file check. Here's how to fix it:
- First, confirm your web server (Nginx, Apache, etc.) is properly configured to serve content for
subdomain.example.comover HTTP. Visithttp://subdomain.example.comdirectly to make sure it loads your app or a default page without issues. - Next, ensure the
/.well-known/acme-challenge/path isn't blocked or rewritten by your server config:- For Nginx, add this block to your
subdomain.example.comserver configuration:location ^~ /.well-known/acme-challenge/ { root /var/www/acme-challenges; # Use any directory your server can read/write to default_type text/plain; } - For Apache, add this to your virtual host config to allow unfiltered access:
<Directory "/var/www/acme-challenges/.well-known/acme-challenge"> AllowOverride None Require all granted </Directory>
- For Nginx, add this block to your
- Test manually: Create a test file (e.g.,
test-file.txt) with random content in the directory you specified, then visithttp://subdomain.example.com/.well-known/acme-challenge/test-file.txt. You should see the file's content immediately.
2. Resolve the "Must Include Main Domain" Error
This error happens because your existing tool/script is probably trying to request a wildcard certificate (*.example.com) instead of a single subdomain certificate. Let's Encrypt fully supports certificates for individual subdomains—you just need to use the right command with a standard ACME client:
Option 1: Use Certbot (Recommended)
If you don't have Certbot installed, grab it via your system's package manager first. Then run this command, replacing the path with the directory you set up earlier:
certbot certonly --webroot -w /var/www/acme-challenges -d subdomain.example.com
--webroottells Certbot to use the file-based validation method-wspecifies the directory where validation files will be placed-donly lists your subdomain—do not includeexample.comhere
Certbot will handle the rest: it creates the validation file, Let's Encrypt checks it, and you'll get a certificate only for subdomain.example.com.
Option 2: Use acme.sh
If you prefer acme.sh, install it then run:
acme.sh --issue -d subdomain.example.com --webroot /var/www/acme-challenges
Again, only specify the subdomain—no need to reference the main domain at all.
3. Deploy the Certificate
Once the certificate is generated:
- For Certbot, your files will be in
/etc/letsencrypt/live/subdomain.example.com/ - For acme.sh, they'll be in
~/.acme.sh/subdomain.example.com/
Update your web server's HTTPS configuration to use these certificate files, then restart the server. Your subdomain should now load over HTTPS without issues.
Why Did the "Main Domain" Error Happen?
Chances are your initial tool (like a hosting panel's automated SSL feature) was defaulting to a wildcard certificate request. Wildcard certificates require verifying control over the main domain, but you don't need that for a single subdomain. Using a standard ACME client and explicitly targeting only subdomain.example.com avoids this problem entirely.
内容的提问来源于stack exchange,提问作者Sjoerd de Wit

