Let’s Encrypt ssl证书到期后,无法自动续签,请问怎么办?

问答中心分类: OneinStackLet’s Encrypt ssl证书到期后,无法自动续签,请问怎么办?
kkwn asked 5年 ago
如题,Let’s Encrypt 3个月的证书到期后,crontab 中也有自动添加了续签命令,但是无法续签。
手动运行后,提示如下。

[root@bogon ~]# /usr/local/python/bin/certbot renew --renew-hook
usage:
certbot [SUBCOMMAND] [options] [-d domain] [-d domain] ...

Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,
it will attempt to use a webserver both for obtaining and installing the
cert. Major SUBCOMMANDS are:

(default) run Obtain & install a cert in your current webserver
certonly Obtain cert, but do not install it (aka "auth")
install Install a previously obtained cert in a server
renew Renew previously obtained certs that are near expiry
revoke Revoke a previously obtained certificate
register Perform tasks related to registering with the CA
rollback Rollback server configuration changes made during install
config_changes Show changes made to server config during installation
plugins Display information about installed plugins
certbot: error: argument --renew-hook: expected one argument
crontab 中如下:
*/20 * * * * /usr/sbin/ntpdate pool.ntp.org > /dev/null 2>&1
0 0 1 * * /usr/local/python/bin/certbot renew --renew-hook "/etc/init.d/nginx reload"
0 4 * * * cd ~/oneinstack;./backup.sh > /dev/null 2>&1 &


Question Tags:

7 Answers
andy.zhang answered 5年 ago
/data/oneinstack/letsencrypt/letsencrypt-auto certonly --renew-by-default --webroot -w             /data/wwwroot/www.blog-andy.com/ -d blog-andy.com -d http://www.blog-andy.com  >/dev/null
/etc/init.d/nginx reload
我把上面这两个写成脚本,放在crontab里,每两月执行一次,是可以的。你把对应的路径改一下,域名换成你自己的就可以了。
 
 

kkwn answered 5年 ago
#1 你是自己配置的Let’s Encrypt  ssl证书,我使用的是oneinstack的自动配置Let’s Encrypt  ssl的脚本,不知道如何续签。

kkwn answered 5年 ago
烦请 管理员查看下,提供下解决方法,貌似其他人也遇到这样问题。

oneinstack answered 5年 ago
执行如下命令,强制更新试试:

/usr/local/python/bin/certbot renew --force-renewal --renew-hook "/etc/init.d/nginx reload"

kkwn answered 5年 ago
感谢!以上方法可以!强制更新可以!

king answered 5年 ago
我也遇到了,,,ONS签发的域名证书到期后,,域名不能自动续期~~~~~~ 希望能完善这个BUG~~

nougat answered 5年 ago
目前靠手动