2026-09-30 11:29AM
certkit 是一个快速申请 Let's Encrypt 免费 SSL 证书,http-01域名验证;适合临时、快速签发证书,不需要在服务器安装 certbot
原理:让域名的 /.well-known/acme-challenge/xxx 请求跳转到 certkit 的验证地址,Let's Encrypt 外部访问该路径完成域名所有权校验
注意:Certkit无自动续期,证书 90 天到期,需要重新走一遍 http-01 流程重新申请、替换证书
具体实现流程:
1. 进入网站 https://www.certkit.io/tools/free-ssl-certificate-generator
2. 输入域名,点击生成

3. 配置你的nginx,我这里使用的是 nginx 方法

eg:
server {
listen 80;
listen [::]:80;
server_name test.mysite.com;
location /.well-known/acme-challenge/ {
return 302 https://app.certkit.io/http-challenge/free/你的密钥/$request_uri;
}
# 其余http请求,直接跳转https
location / {
return 301 https://$host$request_uri;
}
}
4. 在命令行进行测试
$ curl -I http://test.mysite.com/.well-known/acme-challenge/test123
HTTP/1.1 302 Moved Temporarily
Server: nginx/1.24.0 (Ubuntu)
Date: Wed, 30 Sep 2026 02:31:01 GMT
Content-Type: text/html
Content-Length: 154
Connection: keep-alive
Location: https://app.certkit.io/http-challenge/free/xxxxxxx/test123
返回302,Location指向 certkit 的 challenge 地址,就表示成功了。
5. 在页面点击验证域名(I've Setup The Redirect)
Certkit 会调用 Let’s Encrypt 服务,访问你域名的 acme 路径;Nginx 把请求 302 转发到 certkit,校验通过后,需要你提供邮箱发送签发证书,但是邮箱里面只有1个pem文件

你需要再回到网站,在网站上面有2个证书,一个是key,另一个是pem

下载这两个证书
6. 如果你需要crt证书,就使用命令,把pem证书转换为crt证书
$ openssl x509 -in test.pem -out test.crt
然后配置你nginx的ssl,最后打开网站进行测试
这样就可以了~
登录
请登录后再发表评论。
评论列表:
目前还没有人发表评论