【问题标题】:Trying to use certbox to get SSL Certificate, however command sudo certbot --apache failed on ec2 instance尝试使用 certbox 获取 SSL 证书,但是命令 sudo certbot --apache 在 ec2 实例上失败
【发布时间】:2020-01-09 16:50:21
【问题描述】:

Here are the instructions I was following,这是我尝试运行sudo certbot --apache时收到的错误

我通过 ssh 连接到我的 EC2 实例并成功运行了说明的第 2 节和第 3 节中的所有命令,但现在第 4 节中的这个命令失败了。这是输出:

bitnami@ip-172-31-82-209:~/apps/InterSportsGraphs$ sudo certbot --apache
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator apache, Installer apache
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org
No names were found in your configuration files. Please enter in your domain
name(s) (comma and/or space separated)  (Enter 'c' to cancel): bigleaguegraphs.com www.bigleaguegraphs.com
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for bigleaguegraphs.com
http-01 challenge for www.bigleaguegraphs.com
Enabled Apache rewrite module
Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs

Unable to restart apache using ['apache2ctl', 'graceful']
Cleaning up challenges
Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs

Unable to restart apache using ['apache2ctl', 'graceful']
Encountered exception during recovery: 
Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2185, in _reload
    util.run_script(self.option("restart_cmd"))
  File "/usr/lib/python3/dist-packages/certbot/util.py", line 86, in run_script
    raise errors.SubprocessError(msg)
certbot.errors.SubprocessError: Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs


During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/certbot/auth_handler.py", line 75, in handle_authorizations
    resp = self._solve_challenges(aauthzrs)
  File "/usr/lib/python3/dist-packages/certbot/auth_handler.py", line 139, in _solve_challenges
    resp = self.auth.perform(all_achalls)
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2287, in perform
    self.restart()
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2175, in restart
    self._reload()
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2203, in _reload
    raise errors.MisconfigurationError(error)
certbot.errors.MisconfigurationError: Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs


During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2185, in _reload
    util.run_script(self.option("restart_cmd"))
  File "/usr/lib/python3/dist-packages/certbot/util.py", line 86, in run_script
    raise errors.SubprocessError(msg)
certbot.errors.SubprocessError: Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs


During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/certbot/error_handler.py", line 108, in _call_registered
    self.funcs[-1]()
  File "/usr/lib/python3/dist-packages/certbot/auth_handler.py", line 323, in _cleanup_challenges
    self.auth.cleanup(achalls)
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2312, in cleanup
    self.restart()
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2175, in restart
    self._reload()
  File "/usr/lib/python3/dist-packages/certbot_apache/configurator.py", line 2203, in _reload
    raise errors.MisconfigurationError(error)
certbot.errors.MisconfigurationError: Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs

Error while running apache2ctl graceful.
httpd not running, trying to start
Action 'graceful' failed.
The Apache error log may have more information.

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80
no listening sockets available, shutting down
AH00015: Unable to open logs

整个错误中出现的错误信息的内容,我认为如下:

AH00558: apache2: Could not reliably determine the server's fully qualified domain name, using 127.0.0.1. Set the 'ServerName' directive globally to suppress this message
(98)Address already in use: AH00072: make_sock: could not bind to address [::]:80
(98)Address already in use: AH00072: make_sock: could not bind to address 0.0.0.0:80

任何关于如何调试它以便为我的网站获取 SSL 证书的指导都很好,谢谢!我不是网络人,但需要完成这项工作以保护我的网站。请让我知道我是否可以分享任何有助于解决此问题的附加信息,或者我应该如何解决这个问题。谢谢!

编辑:我使用https://www.ssllabs.com/ssltest/ 测试我的域 bigleaguegraphs.com,但也不太了解此处的输出。

Edit2:这里有两个其他帖子的链接:

...看起来他们可能与我的帖子有关?

【问题讨论】:

  • 您正在尝试使用 --apache 标志运行 certbot,但 apache 无法在机器上运行(原因是您已经想到的最后一个日志输出)。这让我想知道,当 apache 无法运行时,您的网站也无法在线? --apache 标志适用于 apache 服务器向外部世界提供您的网站的用例。但是,您的网站似乎是由其他地方提供服务的,这是什么/在哪里?
  • 感谢@JeyDWork - 我使用forever 部署我的网站。几乎我在 ec2 实例上运行的唯一命令(除了cd)是sudo forever stopall 来停止网站,git pull 来获取网站的最新代码,然后如果需要,我会在 ec2 实例上安装新包,然后sudo NODE_ENV=prod forever start index.js 重新部署网站。
  • 好吧,所以它是由 node.js 而不是 apache 提供的。这意味着您与certbot --apache 走错了路。您可能可以让 apache 工作只是为了通过 apache 获取证书,但这会很麻烦,然后您仍然需要将证书集成到 node.js 中(取决于您在这里使用的可能是 express.js)。所以我推荐另一种 certbot 方法。基于 DNS(参见 certbot.eff.org/docs/using.html#dns-plugins)或直接与 node.js/express.js 一起使用的东西(第一次谷歌点击:sitepoint.com/how-to-use-ssltls-with-node-js)。
  • @JeyDWork 将所有这些结合成一个答案而不是评论,我会给你赏金。非常有用的东西。

标签: apache amazon-ec2 ssl-certificate lets-encrypt certbot


【解决方案1】:

根据您发布的日志输出和 cmets,我们知道您的网站是由 node.js 而不是 Apache 提供的。 这意味着您有三个选择:

  1. 让 Apache 工作只是为了获得 Let's Encrypt 证书。我不会推荐这种方法,因为它会很麻烦。 Apache 会在使用的端口方面与 node.js 发生冲突,当您解决了仍需要将检索到的证书集成到 node.js 中时。

  2. 您可以通过 certbot 和任何其他服务器(例如 node.js)直接检索证书,而不是使用 Apache 和 --apache 标志检索证书。通常这将涉及使用带有 certonly --webroot 选项的 certbot,并且您需要修改您的 node.js 服务器(只需一点点)以实际使用检索到的证书并在附加端口上侦听 SSL/TLS 连接。这种方法的一个很好的起点可能是这篇针对 node.js 和 express.js 的文章(并且 express.js 是迄今为止最流行的 node.js 的 HTTP 服务器包,所以它很可能是你的网站也使用它或至少使用非常相似的包):https://www.sitepoint.com/how-to-use-ssltls-with-node-js/
    如果您有一个站点或少数几个站点想要获得证书,我会推荐这种方法。

  3. 不是让 Let's Encrypt 通过 HTTP 验证您的网站,这总是涉及通过现有服务器(如 Apache 并带有 --apache 标志)或任何其他服务器(带有 certonly --webroot选项)您还可以通过 DNS 提供这些响应。这也适用于 certonly 选项(您还需要修改 node.js 以像以前的方法一样实际使用证书),但它有点复杂,需要额外的选项,这可能会因您的 DNS 提供商而异.您可以在https://certbot.eff.org/docs/using.html#dns-plugins 找到流行的 DNS 提供商的文档概述。
    如果您有更多网站并且想要通配符证书(专业提示:每个 DNS 提供商都准备好使用 docker 映像:https://hub.docker.com/r/certbot/certbot/),这是我绝对推荐的方法。

【讨论】:

  • 谢谢。当我尝试实施您的建议时,我将提供更多详细信息。到期前没有分配赏金,所以我创建了一个新的,并在允许时分配!
  • 当您选择特定方法并有其他问题时,请告诉我。目前很难更详细地回答,因为每种方法都有很多可能性,而且还有一些未知的事实。如果您像我建议的那样选择 2 或 3,您可能会遇到如何集成证书的问题。因此,我们需要知道您当前的 node.js 网站是否使用 express.js。寻找require('express')。如果它不存在,您的项目不使用它,在这种情况下查找require('http')。这些可能会指示集成证书的位置。
猜你喜欢
  • 1970-01-01
  • 2023-03-21
  • 1970-01-01
  • 2012-04-24
  • 1970-01-01
  • 2020-09-15
  • 2022-11-22
  • 2014-01-31
  • 2017-02-19
相关资源
最近更新 更多