Ubuntu 22.04下配置Nginx与Certbot安装SSL证书后网站无法访问,Nginx启动失败求助
Ubuntu 22.04下配置Nginx与Certbot安装SSL证书后网站无法访问,Nginx启动失败求助
各位大佬好,我是Ubuntu新手,最近在一台公有虚拟机上搭环境,刚装了Ubuntu 22.04、Nginx和Certbot。之前网站已经能指向我的域名正常访问了,但装完Certbot配置SSL之后彻底崩了——现在不管用HTTP还是HTTPS都打不开网站,Nginx还启动失败了!
我用notmydomain.com作为示例域名,给大家详细说下情况:
按照Certbot官网指引操作后,我执行启动Nginx的命令:
systemctl start nginx.service
结果直接报错:
Job for nginx.service failed because the control process exited with error code.
See "systemctl status nginx.service" and "journalctl -xeu nginx.service" for details.
于是我查了Nginx的状态:
systemctl status nginx.service
输出如下:
× nginx.service - A high performance web server and a reverse proxy server Loaded: loaded (/lib/systemd/system/nginx.service; enabled; vendor preset: enabled) Active: failed (Result: exit-code) since Mon 2023-10-30 09:17:39 CDT; 5s ago Docs: man:nginx(8) Process: 535771 ExecStartPre=/usr/sbin/nginx -t -q -g daemon on; master_process on; (code=exited, status=1/FAILURE) CPU: 12ms systemd[1]: Starting A high performance web server and a reverse proxy server... nginx[535771]: nginx: [emerg] cannot load certificate key "/etc/letsencrypt/live/notmydomain.com/privkey.pem": PEM_read> systemd[1]: nginx: configuration file /etc/nginx/nginx.conf test failed systemd[1]: nginx.service: Control process exited, code=exited, status=1/FAILURE systemd[1]: nginx.service: Failed with result 'exit-code'. systemd[1]: Failed to start A high performance web server and a reverse proxy server.
我去检查了证书文件所在目录的权限:
ls -l /etc/letsencrypt/live/notmydomain.com/
输出是:
total 4 lrwxrwxrwx 1 root root 44 Oct 28 03:00 cert.pem -> ../../archive/notmydomain.com/cert1.pem lrwxrwxrwx 1 root root 45 Oct 28 03:00 chain.pem -> ../../archive/notmydomain.com/chain1.pem lrwxrwxrwx 1 root root 49 Oct 28 03:00 fullchain.pem -> ../../notmydomain.com/fullchain1.pem lrwxrwxrwx 1 root root 47 Oct 28 03:00 privkey.pem -> ../../archive/notmydomain.com/privkey1.pem -rw-r--r-- 1 root root 692 Oct 28 03:00 README
我注意到这些文件都是root用户所有,会不会是Nginx没有权限访问这些证书?这会不会是问题所在?这些证书文件应该改成哪个用户所有才能让Nginx正常访问呢?
另外我也检查了防火墙设置,确保没把自己拦在外面:
ufw status numbered
输出是:
Status: active To Action From -- ------ ---- [ 1] Anywhere ALLOW IN xxx.xxx.xxx.xxx [ 2] 443/tcp ALLOW IN Anywhere [ 3] 80/tcp ALLOW IN Anywhere [ 4] Nginx HTTP ALLOW IN Anywhere [ 5] Nginx HTTPS ALLOW IN Anywhere [ 6] 443/tcp (v6) ALLOW IN Anywhere (v6) [ 7] 80/tcp (v6) ALLOW IN Anywhere (v6) [ 8] Nginx HTTP (v6) ALLOW IN Anywhere (v6) [ 9] Nginx HTTPS (v6) ALLOW IN Anywhere (v6)
我还尝试重新签发了证书,执行过程中没有报错:
certbot certonly --standalone --domain notmydomain.com
输出如下:
Saving debug log to /var/log/letsencrypt/letsencrypt.log Requesting a certificate for notmydomain.com Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/notmydomain.com-0001/fullchain.pem Key is saved at: /etc/letsencrypt/live/notmydomain.com-0001/privkey.pem This certificate expires on 2024-01-28. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background.
现在实在不知道该查哪里了,有没有大佬能给点指导?需要更多信息的话我随时提供!
备注:内容来源于stack exchange,提问作者ErocM
相关产品推荐
相关产品推荐

