Nginx CertBot 인증서 발급 및 갱신 자동화

서재·2025년 4월 12일

Certbot

1. Certbot 설치

sudo apt update
sudo apt install certbot python3-certbot-nginx

2. Nginx 도메인 설정

certbot은 nginx.conf를 읽어 SSL 인증서를 설치할 수 있음
server_name에 설정된 도메인 주소에 해당하는 인증서를 발급함

nginx.conf

server {
    listen 80;
    server_name example.com www.example.com;

    location / {
        root /var/www/html;
        index index.html;
    }
}

3. SSL 인증서 발급

sudo certbot --nginx

4. SSL 인증서 갱신 자동화

Certbot이 발급한 인증서는 90일 간 유효하다.
Certbot은 기본적으로 자동 갱신을 하도록 설정되어 있다.
아래 명령어를 통해 Certbot 타이머 상태를 확인할 수 있다.

root@XXXXX:/# sudo systemctl status certbot.timer

● certbot.timer - Run certbot twice daily
     Loaded: loaded (/lib/systemd/system/certbot.timer; enabled; vendor preset: enabled)
     Active: active (waiting) since Thu 2025-04-10 14:53:45 KST; 7min ago
    Trigger: Fri 2025-04-11 09:09:07 KST; 18h left
   Triggers: ● certbot.service
profile
입니다.

0개의 댓글