Qhov yuav ua tiav: Lub vev xaib ntawm VPS Vultr uas siv Ubuntu thiab Nginx yuav muaj daim ntawv pov thawj Let’s Encrypt raug rau lub npe sau, nkag tau los ntawm HTTPS thiab nws txoj kev rov txuas hnub nyoog yuav tau kuaj nrog sudo certbot renew --dry-run. Kab lus no haum rau tus neeg uas muaj cai SSH thiab sudo. Cov lus txib uas muaj tiền tố sudo yuav tsum khiav hauv SSH session ntawm VPS; cov lus txib dig tuaj yeem khiav ntawm lub computer ntiag tug lossis VPS.
Txheej txheem no siv HTTP-01 authentication. Yog li, lub npe sau yuav tsum taw rau VPS thiab lub server yuav tsum txais tau kev txuas hauv Internet ntawm TCP 80. HTTPS yuav tsum ntxiv TCP 443. Let’s Encrypt muab daim ntawv pov thawj uas siv tau 90 hnub; kev nruab tau daim ntawv pov thawj tsis txhais tias txoj kev rov txuas hnub nyoog twb ua haujlwm lawm.
Thaj tsam, cov xwm txheej thiab cov nqi yuav tsum hloov
- VPS Vultr uas siv Ubuntu 22.04 lossis Ubuntu 24.04.
- Nginx twb tau nruab lawm lossis yuav nruab hauv kab lus no.
- SSH account uas muaj cai
sudo. - Koj muaj cai kho DNS ntawm lub npe sau thiab Vultr Firewall Group yog tias VPS tab tom siv pawg firewall ntawd.
- Hauv cov lus txib hauv qab no, hloov
example.comua lub npe sau tiag. Yog tsis sivwww, tshem qhov parameter-d www.example.comthiab cov DNS records uas cuam tshuam.
TLS daim ntawv pov thawj tsis vam khom PHP. Yog lub vev xaib yog PHP application lossis WordPress, PHP-FPM thiab PHP extensions yuav tsum ua haujlwm sib cais; tsis tas hloov upload_max_filesize, memory_limit lossis max_execution_time tsuas yog kom tau daim ntawv pov thawj. Koj tuaj yeem kuaj PHP tom qab HTTPS ua haujlwm lawm.
1. Taw DNS thiab kuaj Nginx ua ntej thov daim ntawv pov thawj
Teeb DNS records
Ntawm tus sau npe lub chaw lossis DNS service uas tswj lub npe sau, tsim yam tsawg kawg cov records hauv qab no:
| Hom | Npe | Tus nqi | Hom phiaj |
|---|---|---|---|
| A | @ | IPv4 ntawm VPS Vultr | Lub npe sau tseem ceeb |
| A | www | IPv4 ntawm VPS Vultr | Lub npe sau www |
Yog muaj record AAAA, tsuas khaws record ntawd yog VPS yeej muaj IPv6 thiab Nginx/firewall tuaj yeem pab IPv6 tau. Ib qho AAAA uas taw yuam kev yuav ua rau authentication server nkag mus rau qhov chaw tsis yog, txawm tias record A twb raug lawm.
Khiav los ntawm lub computer ntiag tug lossis VPS:
dig +short A example.com
dig +short A www.example.com
dig +short AAAA example.com
dig +short AAAA www.example.com
DNS record qhov tshwm sim A yuav tsum yog VPS li IPv4. Yog muaj AAAA, qhov chaw nyob ntawd yuav tsum yog VPS li IPv6 tiag. DNS uas nyuam qhuav hloov yuav tseem tsis tau hloov tshiab thoob plaws txhua qhov chaw vim TTL thiab DNS cache; tsis txhob khiav Certbot kom txog thaum qhov kev resolve tshwm sim raug.
Tshawb xyuas Nginx thiab server block
Ntawm VPS, khiav:
sudo systemctl status nginx --no-pager
sudo nginx -t
curl -I http://example.com
Qhov tshwm sim uas xav tau yog Nginx tseem tab tom khiav, nginx -t qhia tias configuration raug thiab curl tau txais HTTP response. Server block yuav tsum muaj lub domain raug, piv txwv li:
server {
listen 80;
listen [::]:80;
server_name example.com www.example.com;
root /var/www/example;
index index.html index.php;
location / {
try_files $uri $uri/ =404;
}
}
Nqe lus saum toj no tsuas yog ib qho piv txwv rau lub website static xwb. Yog koj siv PHP-FPM, reverse proxy lossis WordPress, cia cov directives location uas tab tom pab lub application nyob twj ywm; tsis txhob hloov tag nrho server block ua piv txwv no.
Rau PHP website, koj kuj yuav tshuaj xyuas ntxiv ntawm VPS:
php -v
php -m
systemctl list-units --type=service --all 'php*-fpm.service' --no-pager
Yog application siv PHP-FPM, lub npe service feem ntau muaj hom php8.1-fpm lossis php8.3-fpm, nyob ntawm version uas twb tau nruab. PHP-FPM qhov yuam kev tsis yog qhov yuam kev ntawm kev muab certificate, tabsis nws yuav ua rau website xa rov qab 502 tom qab qhib HTTPS.
2. Qhib TCP 80 thiab 443 ntawm ob txheej firewall
HTTP-01 xav tau TCP 80; HTTPS website xav tau TCP 443. Tshawb xyuas Vultr Firewall Group thiab firewall hauv Ubuntu tib si. Vultr cov ntaub ntawv ntsig txog muaj nyob ntawm How Do I Install an SSL Certificate on a Vultr Compute Instance?.
Hauv Vultr control panel, qhib Firewall Group uas txuas nrog VPS thiab tso cai rau:
- TCP 22 los ntawm koj tus IP tswj hwm, lossis SSH port tiag yog koj twb hloov port lawm.
- TCP 80 los ntawm Internet.
- TCP 443 los ntawm Internet.
Ntawm VPS, hloov 22 ua SSH port tiag yog koj tsis siv lub port mặc định. Khiav txhua command nyias:
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose
Yog UFW yeej tsis tau qhib dua, command sudo ufw enable yuav nug kom koj lees paub. Tsuas txuas ntxiv tom qab tso cai rau SSH port raug lawm; yog tsis li, koj yuav kaw koj tus kheej tawm ntawm management session. Qhov kev tshuaj xyuas yuav tsum qhia cov cai rau SSH, HTTP thiab HTTPS.
Yog xav tshuaj xyuas los ntawm network sab nraud VPS, siv koj lub computer lossis lwm lub server:
curl -I http://example.com
Yog command timeout, tshuaj xyuas DNS, Vultr Firewall, UFW thiab lwm lub firewall ua ntej khiav Certbot.
3. Backup configuration thiab nruab Certbot
Backup ua ntej Certbot hloov Nginx
Ntawm VPS, tsim ib daim backup uas muaj timestamp:
BACKUP_DIR="/root/nginx-backup-$(date +%F-%H%M%S)"
sudo cp -a /etc/nginx "$BACKUP_DIR"
printf '%sn' "$BACKUP_DIR"
Command kawg yuav luam tawm backup qhov chaw nyob. Sau cia qhov chaw nyob no; yuav siv thaum xav rollback. Tshawb xyuas tias directory twb muaj lawm:
sudo test -d "$BACKUP_DIR" && echo "Da tao backup: $BACKUP_DIR"
Nruab Nginx yog VPS tseem tsis tau muaj
Yog Nginx twb khiav lawm thiab sudo nginx -t ua tiav zoo, hla qhov nruab Nginx. Rau VPS tshiab, khiav ntawm VPS:
sudo apt update
sudo apt install -y nginx snapd
sudo systemctl enable --now nginx
sudo nginx -t
Qhov tshwm sim kawg yuav tsum qhia tias configuration raug. Yog Nginx tseem tsis muaj server block rau lub domain, rov qab mus rau DNS theem thiab teeb server block kom tiav ua ntej thov certificate.
Nruab Certbot ntawm Snap
Ntawm VPS, khiav raws ib qho zuj zus:
sudo snap install core
sudo snap refresh core
sudo snap install --classic certbot
sudo ln -sfn /snap/bin/certbot /usr/local/bin/certbot
certbot --version
Command kawg yuav tsum luam tawm Certbot version. Tsis tsim nyog nruab Certbot ntau daim tib lub sijhawm los ntawm Snap, APT thiab pip yog tsis xav tau, vim koj yuav tshuaj xyuas yuam kev rau lwm qhov program lossis lwm txoj haujlwm renew.
4. Muab certificate thiab qhib HTTPS rau Nginx
Ntawm VPS, khiav command hauv qab no thiab hloov lub domain piv txwv ua koj lub domain tiag:
sudo certbot --nginx -d example.com -d www.example.com
Certbot yuav nug email, cov nqe lus siv thiab qhov kev xaiv redirect HTTP mus rau HTTPS. Rau website pej xeem, koj yuav xaiv redirect yog application tsis vam khom HTTP ntshiab. Tsis txhob thov certificate rau domain uas tseem tsis tau resolve mus rau VPS.
Nginx plugin yuav nrhiav server block uas phim, ntxiv TLS configuration thiab tej zaum yuav reload Nginx. Yog command ua tsis tiav, tsis txhob rho certificate lossis configuration qub; sau tseg cov lus yuam kev thiab tshuaj xyuas DNS, port 80 thiab server block.
Certbot siv cov path tswj hwm cais nyob hauv /etc/letsencrypt. Tsis txhob rho cov file hauv ntawd ntawm koj tus kheej. Tom qab command ua tiav, tshuaj xyuas:
sudo nginx -t
sudo systemctl reload nginx
sudo certbot certificates
certbot certificates yuav tsum qhia lub domain raug, hnub tas sij hawm thiab certificate path. Yog nginx -t ua tsis tiav, tsis txhob reload Nginx kom txog thaum kho syntax yuam kev tiav.
5. Tshawb xyuas HTTPS, HTTP redirect thiab application
Ntawm VPS lossis koj lub computer, khiav:
curl -I http://example.com
curl -I https://example.com
curl -sS -o /dev/null -w '%{http_code}n' https://example.com
Qhov tshwm sim uas xav tau:
- HTTP yuav xa rov qab
301lossis308mus rau HTTPS yog twb xaiv redirect lawm. - HTTPS yuav xa rov qab website response thiab yuav tsis qhia certificate yuam kev.
- Certificate hauv domain yuav tsum suav nrog txhua domain uas koj nkag mus, piv txwv li ob qho tib si
example.comthiabwww.example.com.
Code 200, 301 lossis tus lej uas daim ntawv thov xa rov qab los yeej siv tau, nyob ntawm qhov kev teeb tsa. Yog HTTPS xa rov qab 502, tshuaj xyuas PHP-FPM lossis upstream:
sudo systemctl status nginx --no-pager
sudo journalctl -u nginx -n 50 --no-pager
systemctl list-units --type=service --all 'php*-fpm.service' --no-pager
Yog lub vev xaib siv PHP, tshuaj xyuas kom yog PHP-FPM version thiab cov extensions uas daim ntawv thov yuav tsum muaj. Tsis txhob suav tias kev kho php.ini yog ib kauj ruam uas SSL yuav tsum muaj; tsuas hloov cov kev txwv upload, memory thiab runtime thaum daim ntawv thov xav tau xwb.
6. Tshuaj xyuas txoj kev rov txuas hnub nyoog tsis siv neeg
Tshuaj xyuas timer lossis cron
Certbot feem ntau nruab ib systemd timer lossis cron job los tshuaj xyuas cov certificate uas yuav tas sij hawm raws caij nyoog. Hauv VPS, nrhiav timer:
systemctl list-timers --all | grep -i certbot || true
systemctl list-unit-files | grep -i certbot || true
systemctl status snap.certbot.renew.timer --no-pager
Lub npe timer yuav txawv raws version thiab txoj kev nruab. Yog tias snap.certbot.renew.timer tsis muaj, siv cov txiaj ntsig ntawm ob lo lus txib saum toj los nrhiav unit kom raug; tsis txhob tsim cron job ntxiv yog twb muaj timer lawm.
Yog nrhiav tsis tau timer, tshuaj xyuas cron:
sudo grep -R "certbot renew" /etc/cron.d /etc/cron.daily /var/spool/cron 2>/dev/null || true
Yuav tsum cais ob yam no: timer/cron tsuas yog pib lo lus txib xwb; DNS, firewall, Nginx thiab kev teeb tsa domain tseem yuav tsum raug, thiaj rov txuas hnub nyoog tau tiav.
Simulating kev rov txuas hnub nyoog ib zaug
Nov yog qhov kev tshuaj xyuas tseem ceeb tshaj tom qab tau txais certificate. Hauv VPS, khiav:
sudo certbot renew --dry-run
--dry-run siv qhov chaw sim thiab yuav tsis hloov certificate uas tab tom muab kev pab. Qhov ua tiav yuav tsum qhia tias txoj kev sim rov txuas hnub nyoog tiav yam tsis muaj authentication lossis deployment yuam kev. Yog ua tsis tiav, nyeem tag nrho cov output kom nrhiav seb puas yog DNS, HTTP-01, firewall, Nginx lossis deployment hook ua rau muaj teeb meem.
Tom qab sim tiav, tshuaj xyuas Nginx thiab lub vev xaib dua:
sudo nginx -t
sudo systemctl reload nginx
curl -sS -o /dev/null -w '%{http_code}n' https://example.com
Tsis tas yuav khiav certbot renew sawv daws txhua hli. Tsuas siv lo lus txib ntawd thaum muaj laj thawj khiav hauj lwm meej; timer yuav tshuaj xyuas nws tus kheej raws lub sijhawm.
7. Tshawb nrhiav teeb meem raws li cov tsos mob
| Tsos mob | Teeb meem uas nquag ua rau | Yam yuav tshuaj xyuas thiab kho |
|---|---|---|
| Timeout thaum authentication | TCP 80 raug thaiv hauv Vultr Firewall, UFW lossis lwm lub firewall. | Tshuaj xyuas sudo ufw status verbose, Firewall Group thiab khiav curl -I http://example.com los ntawm ib lub network sab nraud. |
| IP rau authentication tsis raug | A lossis AAAA record taw mus rau lwm lub server. | Khiav dig +short A example.com thiab dig +short AAAA example.com; kho DNS lossis tshem AAAA uas tsis raug. |
| 404 ntawm ACME path | Rewrite, reverse proxy lossis daim ntawv thov ua haujlwm tsis raug /.well-known/acme-challenge/. | Tshuaj xyuas server block thiab rewrite rules; xyuas kom domain hla TCP 80 mus txog Nginx kom raug. |
| Nginx reload tsis tiav | TLS configuration muaj syntax yuam kev lossis sib tsoo nrog configuration qub. | Khiav sudo nginx -t, kho cov ntaub ntawv uas tau qhia tias muaj teeb meem kom raug, mam li khiav sudo systemctl reload nginx. |
--dry-run ua tsis tiav | DNS, firewall, domain lossis web configuration tau hloov. | Nyeem Certbot output thiab log, kho lub hauv paus teeb meem mam li khiav dua; tsis txhob rho daim certificate qub thaum tseem tab tom tshawb xyuas. |
| Certificate tsis phim domain | Certificate tsis suav nrog variant uas tab tom siv, xws li www. | Khiav sudo certbot certificates; yog tsim nyog, thov certificate dua nrog tag nrho cov -dtsis. |
| HTTPS xa rov qab 502 | PHP-FPM lossis upstream nyob tom qab Nginx tsis ua haujlwm. | Tshuaj xyuas PHP-FPM/upstream service status thiab Nginx log; qhov no tsis tas yuav yog certificate teeb meem. |
Let’s Encrypt siv HTTP-01 los ntawm kev tso token rau hauv /.well-known/acme-challenge/ thiab nkag mus rau token ntawd hauv Internet. Yog li, qhib TCP 443 xwb tseem tsis txaus rau txoj kev no. Saib ntxiv Challenge Types — Let’s Encrypt.
8. Rollback kom nyab xeeb thaum Nginx configuration muaj teeb meem
Yog tom qab Certbot hloov kho lawm Nginx kuaj tsis tau lossis lub vev xaib muaj teeb meem, ua ntej tshaj tsis txhob khiav lwm lo lus txib rau kev thov lossis rov txuas hnub nyoog certificate. Nrhiav qhov yuam kev:
sudo nginx -t
sudo certbot certificates
sudo ls -la /etc/letsencrypt/live/example.com/
Hloov example.com nrog lub domain tiag. Yog xav rov qab siv backup uas tsim hauv kauj ruam 3, teeb txoj kev mus kom raug ua ntej khiav:
BACKUP_DIR="/root/nginx-backup-YYYY-MM-DD-HHMMSS"
if sudo test -d "$BACKUP_DIR"; then
sudo mv /etc/nginx "/etc/nginx.failed-$(date +%F-%H%M%S)"
sudo cp -a "$BACKUP_DIR" /etc/nginx
sudo nginx -t
sudo systemctl reload nginx
else
echo "Khong tim thay thu muc sao luu: $BACKUP_DIR" >&2
exit 1
fi
Hloov YYYY-MM-DD-HHMMSS nrog lub npe tiag ntawm daim nplaub tshev thaub qab. Nqe lus txib no kuaj daim nplaub tshev ua ntej rov qab kho, kom tsis txhob siv txoj kev tsis yog. Tsis txhob rho tawm /etc/letsencrypt thaum tseem tab tom tshawb xyuas; daim nplaub tshev ntawd muaj cov ntawv pov thawj, cov yuam sij thiab cov ntaub ntawv uas Certbot xav tau. Tsuas rov siv daim ntawv pov thawj tom qab kho qhov teeb meem tiav thiab sudo nginx -t ua tiav.
Daim ntawv txheeb xyuas thaum txais ua tiav
- A record ntawm txhua lub npe sau npe uas yuav siv yuav tsum taw rau VPS tus IPv4 kom raug.
- AAAA record yuav tsum tsis muaj, lossis taw rau IPv6 uas VPS yeej siv los muab kev pabcuam.
- Vultr Firewall thiab UFW yuav tsum tso cai rau TCP 80 thiab TCP 443; SSH tseem yuav tsum txuas tau.
sudo nginx -tua tiav ua ntej thiab tom qab khiav Certbot.sudo certbot certificatesqhia lub npe sau npe kom raug thiab hnub tas sijhawm.- HTTPS qhib tau, thiab daim ntawv pov thawj phim txhua lub npe sau npe uas yuav siv.
- HTTP yuav tsum redirect kom raug yog tias tau xaiv qhov kev xaiv redirect.
- Systemd timer lossis Certbot cron yuav tsum muaj nyob thiab tsis raug lov tes taw.
sudo certbot renew --dry-runua tiav yam tsis muaj kev yuam kev.- Muaj txoj kev mus rau daim qauv thaub qab ntawm Nginx configuration thiab paub yuav rov qab kho li cas.
Yog koj tswj ntau lub vev xaib lossis ntau lub VPS, tsim nyog sau tseg cov npe sau npe, qhov chaw TLS xaus, authentication method, timer/cron mechanism thiab hnub uas tau khiav --dry-run. Koj kuj tuaj yeem nyeem ntxiv hauv tsab xov xwm hais txog kev qhib HTTPS thiab kho CAA yuam kev rau Blogger, hauv pab pawg kev ruaj ntseg blog thiab cov lus qhia txog Hosting thiab servers thaum xav siv lwm yam HTTPS configurations los ua qauv.
Xaus lus
Yog xav nruab Let’s Encrypt rau VPS Vultr kom ntseeg tau, yuav tsum ua kom tiav tag nrho cov theem: DNS raug, TCP 80 thiab 443 qhib ntawm ob txheej firewall, Nginx muaj server block uas siv lub npe sau npe raug, Certbot muab daim ntawv pov thawj tau thiab sudo certbot renew --dry-run khiav tau tiav. Tom qab txhua qhov kev hloov pauv hauv DNS, firewall lossis Nginx, tsim nyog rov kuaj tag nrho cov txheej txheem uas tau npaj tseg, tsis yog saib lub cim xauv ntawm browser xwb.
Cov ntaub ntawv siv
- How Do I Install an SSL Certificate on a Vultr Compute Instance? — Vultr Docs.
- Obtain TLS certificates — Ubuntu Server documentation.
- Certbot Instructions — Certbot.
- Challenge Types — Let’s Encrypt.
- Firewall — Ubuntu Server documentation.

