SSD Nodes Learn Hosting plans →
మార్గదర్శకాలు Matt Connorద్వారా Matt Connor · అప్‌డేట్ చేయబడింది 2026-08-07

Ubuntu 24.04లో Apache కోసం Certbot ఇన్‌స్టాల్ చేయడం

Ubuntu 24.04లో apt ద్వారా వచ్చే Certbot 2.9.0తో ఒక్క commandలో Let's Encrypt certificate పొందండి. snap అవసరం లేదు; ServerName లోపం issuanceను ఎలా ఆపుతుందో చూడండి.

మీరు నిర్మించేది

Ubuntu 24.04 పై నడిచే Apache site ను HTTPS ద్వారా అందుబాటులో ఉంచుతారు. దీనికి ఉచితంగా, browserలు విశ్వసించే Let's Encrypt certificate ఉంటుంది. ఈ certificate ను Certbot జారీ చేస్తుంది. మీరు మళ్లీ ఆలోచించాల్సిన అవసరం లేకుండా systemd timer దీన్ని స్వయంచాలకంగా renew చేస్తుంది. పని చేసే command ఒక్క line మాత్రమే. విఫలమయ్యే ప్రతిదీ ఆ line కు ముందే విఫలమవుతుంది: ServerName లేని vhost, provider firewall వద్ద మూసి ఉన్న port 80, ఇంకా పాత server కు చూపిస్తున్న DNS. అందువల్ల ఈ guide లో ఎక్కువ భాగం ముందస్తు అవసరాలపైనే ఉంటుంది. ప్రతి తప్పు చూపించే ఖచ్చితమైన error string ను కూడా ఇది పేర్కొంటుంది.

పరిధికి సంబంధించిన రెండు గమనికలు. మీ web server nginx అయితే, విధానం దాదాపు ఇదే విధంగా ఉంటుంది. అయితే plugin మరియు configs వేర్వేరుగా ఉంటాయి. అందువల్ల nginx version of this guide ను ఉపయోగించండి. మీరు భద్రపరచేది internal-only సేవ అయితే—private address పై ఉన్న admin panel లేదా మరెవరూ సందర్శించని staging box వంటిది—మీకు certificate authority అవసరం లేదు. self-signed certificate కు తక్కువ configuration అవసరం. ఇది offline లో కూడా పనిచేస్తుంది.

ముందస్తు అవసరాలు, Certbot అమలు కాకముందే ఇది విఫలమయ్యే మూడు పరిస్థితులు

  • Apache ఇప్పటికే మీ site ను సాధారణ HTTPపై అందిస్తూ ఉండాలి. Certbot యొక్క Apache plugin ఇప్పటికే ఉన్న site configuration ను సవరిస్తుంది; కొత్త site ను సృష్టించదు. మీరు ఖాళీ VPS నుంచి ప్రారంభిస్తే ముందుగా Ubuntu 24.04లో LAMP stack ను సిద్ధం చేసి తిరిగి రండి. ఈ guide దానికి అవసరమైన TLS అధ్యాయం.
  • మీ VPS address కు A record ఉన్న public domain ఉండాలి. Let's Encrypt యొక్క HTTP-01 challenge కోసం validation servers internet నుంచి మీ server కు connect అవుతాయి. అందువల్ల port forward లేకుండా NAT వెనుక ఉన్న homelab, .local పేర్లు, bare IPలు పనిచేయవు. dig +short example.com మీ VPS address ను return చేయాలి. గత గంటలో DNS మార్చి ఉంటే, certificate issue చేయడానికి ముందు పాత record యొక్క TTL ముగిసే వరకు వేచి ఉండండి.
  • AAAA record ఉంటే అది సరైనదై ఉండాలి. AAAA record ప్రచురించబడితే Let's Encrypt IPv6కు ప్రాధాన్యం ఇస్తుంది. అందువల్ల మీ laptop నుంచి, సాధారణంగా IPv4పై, curl సరిగ్గా పనిచేసినా stale AAAA validation ను విఫలపరచవచ్చు. సరైన AAAA record ను publish చేయండి లేదా అసలు publish చేయకండి.

Port 80 మరియు 443 రెండూ ufwలో అలాగే మీ provider network firewallలో open అయి ఉండాలి. చాలా hosting panelsలో OS చూడలేని రెండవ firewall ఉంటుంది. HTTP-01 validation ప్రత్యేకంగా port 80పై జరుగుతుంది; దీన్ని 443-onlyగా అమలు చేయలేరు.

sudo ufw allow "Apache Full"
sudo ufw status

ఈ అవసరాలన్నీ సిద్ధంగా ఉంటే మొత్తం పని పదిహేను నిమిషాల్లో పూర్తవుతుంది. అందులో పది నిమిషాలు చదవడానికే పడతాయి.

Snap లేదా apt Certbot? 24.04లో apt చివరకు సరైన ఎంపిక

distro packages స్థిరంగా పాతబడిపోవడంతో Certbot ను snap ద్వారా పంపిణీ చేయడం సంవత్సరాల క్రితమే ప్రారంభమైంది. Ubuntu 20.04లో Certbot 0.40 విడుదలై, ఆ తర్వాత ఎప్పుడూ నవీకరించబడలేదు. ఐదు సంవత్సరాల పాత bugs ను debug చేయడం project కు విసుగు తెప్పించింది. 24.04లో ఆ కారణం ఇక లేదు. archive లో ప్రస్తుత తరం release అయిన Certbot 2.9.0 ఉంది, మరియు unattended-upgrades దానికి patches అందిస్తుంది. ఈ OS కోసం నా సిఫార్సు: apt ఉపయోగించండి. snapd daemon అవసరం ఉండదు. Apache plugin అదే transactionలో install అవుతుంది. Renewal timer కూడా సాధారణ Debian పద్ధతిలో systemdతో ఏకీకృతమవుతుంది.

sudo apt update
sudo apt install -y certbot python3-certbot-apache
certbot --version

సరైన ఫలితం: certbot 2.9.0. python3-certbot-apache package మీ Apache configs ను చదివి సవరించే plugin. అది లేకపోతే certbot --apache, The requested apache plugin does not appear to be installedతో విఫలమవుతుంది.

ఈ రెండు సందర్భాల్లో snap ఇప్పటికీ సరైన ఎంపిక: Certbot విడుదలైన రోజే దాని తాజా version కావాలనుకుంటే, లేదా snapగా మాత్రమే పంపిణీ చేసే DNS plugin అవసరమైతే. certbot-dns-* provider pluginsలో కొన్ని ఈ విధంగానే పంపిణీ అవుతాయి. ఆ మార్గాన్ని ఎంచుకుంటే:

sudo apt remove -y certbot python3-certbot-apache
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbot

మీరు ఏది ఎంచుకున్నా, రెండింటినీ ఎప్పుడూ run చేయవద్దు. రెండు installations ఉంటే /etc/letsencryptపై రెండు renewal schedulers పరస్పరం జోక్యం చేసుకుంటాయి. మీ shell కనుగొనే certbot, PATHలో ఉన్నది, మీ certificatesను నిర్వహించే installationకు చెందినది కాకపోవచ్చు. పై apt remove line ఐచ్ఛికం కాదు.

vhost Certbot సవరించే ముందు నుంచే ఉండాలి; ServerName అత్యంత ముఖ్యమైనది

certbot --apache మీరు ఇచ్చిన ప్రతి -d domain కు సరిపడే ServerName లేదా ServerAlias ఉన్న port-80 virtual host ను కనుగొని, దాని ద్వారా domain నియంత్రణను నిర్ధారించి, ఆ vhost కు SSL జతను రాయడం ద్వారా పనిచేస్తుంది. సరిపడే ServerName లేకపోతే match జరగదు. Ubuntu యొక్క default 000-default.conf లో ServerName comment చేయబడి ఉంటుంది. ఈ ఒక్క comment చేసిన line వల్లనే ఈ guide లోని ఒకే పెద్ద command సాధారణంగా విఫలమవుతుంది.

కాబట్టి Certbot ను ఉపయోగించే ముందు site కు సరైన name-based vhost ఇవ్వండి. /etc/apache2/sites-available/example.com.conf ను సృష్టించండి:

<VirtualHost *:80>
    ServerName example.com
    ServerAlias www.example.com
    DocumentRoot /var/www/example.com
    ErrorLog ${APACHE_LOG_DIR}/example.com-error.log
    CustomLog ${APACHE_LOG_DIR}/example.com-access.log combined
</VirtualHost>

దాన్ని enable చేసి, Apache దాన్ని సరిగ్గా parse చేసి ఆ name ను దానికి route చేస్తుందో నిర్ధారించండి:

sudo a2ensite example.com.conf
sudo apache2ctl configtest
sudo systemctl reload apache2
sudo apache2ctl -S

configtest తప్పనిసరిగా Syntax OK ను చూపాలి. అది AH00558: apache2: Could not reliably determine the server's fully qualified domain name ను కూడా చూపితే, అది మీ vhost గురించి కాదు; global ServerName గురించి ఇచ్చే హెచ్చరిక మాత్రమే. ఇక్కడ దాని ప్రభావం ఉండదు. echo "ServerName $(hostname -f)" | sudo tee /etc/apache2/conf-available/servername.conf && sudo a2enconf servername && sudo systemctl reload apache2 తో ఆ హెచ్చరికను తొలగించవచ్చు.

-S output మాత్రమే ముఖ్యమైన తనిఖీ. alias www.example.com దాని కింద ఉండే port 80 namevhost example.com (/etc/apache2/sites-enabled/example.com.conf:1) వంటి line కనిపించాలి. Apache మీరు sites-available లో edit చేసిన file ను కాదు, తాను వాస్తవంగా చదివిన sites-enabled symlink ను చూపిస్తుంది. port 80 కు సంబంధించిన జాబితాలో example.com లేకపోతే, Certbot కూడా దాన్ని కనుగొనదు.

Certificate జారీ చేయండి: certbot --apache

sudo certbot --apache -d example.com -d www.example.com

మొదటి సారి అమలు చేసినప్పుడు మూడు విషయాలు అడుగుతుంది: ఒక email address (ఇది మీ ACME account మరియు అత్యవసర CA notices కోసం ఉపయోగించబడుతుంది; Let's Encrypt ఇకపై expiry warnings పంపదు, కాబట్టి renewals ను monitor చేయడం మీ బాధ్యత), Let's Encrypt terms కు అంగీకారం, మరియు మీ email ను EFF తో share చేయాలా అనే ప్రశ్న. Redirect కు సంబంధించిన ప్రశ్న ఇప్పుడు ఉండదు: Certbot 2.0 నుంచి Apache installer డిఫాల్ట్‌గా HTTP ను HTTPS కు redirect చేస్తుంది. ఇదే మీకు కావలసిన ప్రవర్తన. Plain HTTP ద్వారా content అందించడం తప్పనిసరిగా కొనసాగించాల్సి ఉంటే మాత్రమే --no-redirect ను pass చేయండి.

విజయం సాధించినప్పుడు ఇలా కనిపిస్తుంది. దీన్ని త్వరగా చదవకుండా జాగ్రత్తగా పరిశీలించండి:

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/example.com/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/example.com/privkey.pem
This certificate expires on 2026-10-14.

Deploying certificate
Successfully deployed certificate for example.com to /etc/apache2/sites-available/example.com-le-ssl.conf
Successfully deployed certificate for www.example.com to /etc/apache2/sites-available/example.com-le-ssl.conf
Congratulations! You have successfully enabled HTTPS on https://example.com and https://www.example.com

ఆ message వెనుక Certbot నాలుగు పనులు చేసింది: ఇప్పటికే enable చేయకపోతే Apache యొక్క ssl module ను enable చేసింది; example.com-le-ssl.conf ను రాసింది; మీ vhost కు సంబంధించిన ఒక copy ని *:443 పై SSLEngine on మరియు certificate paths తో రూపొందించింది; దాన్ని enable చేసింది; అలాగే అసలు port-80 vhost కు RewriteRule block ను జోడించింది. ఆ block ప్రతిదానినీ 301 ద్వారా HTTPS కు redirect చేస్తుంది. మీ అసలు vhost file ను replace చేయలేదు, edit చేసింది. SSL twin దాని పక్కనే ఉంటుంది, కాబట్టి అది జోడించిన ప్రతి line ను మీరు చదవవచ్చు.

సర్టిఫికేట్ వాస్తవంగా ఎక్కడ ఉంటుంది, దాన్ని ఎందుకు ఎప్పుడూ కాపీ చేయకూడదు

అన్నీ /etc/letsencrypt/live/example.com/ కింద నిల్వ అవుతాయి: fullchain.pem (సర్టిఫికేట్ మరియు intermediate chain; సర్వర్లు దీనినే సూచించాలి), privkey.pem (private key; దీనిని root మాత్రమే చదవగలగాలి), అలాగే భాగాలను విడిగా కోరుకునే సాఫ్ట్‌వేర్ కోసం cert.pem మరియు chain.pem. ఇవి /etc/letsencrypt/archive/ లోని ఫైళ్లకు symlinkలు. ఈ పరోక్ష సూచన విధానమే renewal mechanism. Renewal కొత్త ఫైళ్లను archive/ లో రాసి, symlinkలను వాటివైపు మళ్లిస్తుంది. ఇతర సాఫ్ట్‌వేర్‌ను live/ paths వైపు సూచిస్తే renewalలు అదనపు మార్పులు లేకుండానే అందుతాయి. ఫైళ్లను వేరే చోట కాపీ చేస్తే, 90 రోజులకు మీరే outage కు కారణం ఏర్పరచినట్టవుతుంది.

తెలుసుకోవాల్సిన మరో ముఖ్యమైన ఫైల్ /etc/letsencrypt/renewal/example.com.conf. ఈ సర్టిఫికేట్ ఎలా issue అయిందో అది నమోదు చేస్తుంది: authenticator = apache, installer = apache, మరియు domains. అందువల్ల renewal ప్రక్రియను unattended గా మళ్లీ అమలు చేయవచ్చు. ఇందులో తర్వాత Apache ను reload చేయడం కూడా ఉంటుంది.

Renewal ఇప్పటికే షెడ్యూల్ చేయబడింది, దాన్ని ధృవీకరించండి; మళ్లీ నిర్మించవద్దు

Let's Encrypt certificates రూపకల్పన ప్రకారం 90 days వరకు చెల్లుబాటు అవుతాయి. apt package ఇప్పటికే అవసరమైన వ్యవస్థను install చేసింది: రోజుకు రెండుసార్లు Certbot ను నడిపే systemd timer. ఇది randomized సమయాల్లో అమలై, expiry కి 30 days లోపు ఉన్న ఏ certificate అయినా renew చేస్తుంది. దీనిపై మరో cron job ను జోడించవద్దు. రెండవ scheduler వల్ల log noise మరియు rate-limit కు గురయ్యే అవకాశం మాత్రమే పెరుగుతాయి.

systemctl list-timers certbot.timer
sudo certbot renew --dry-run

మొదటి command timer active గా ఉందని చూపిస్తుంది. రాబోయే 24 hours లో ఎప్పుడో ఒక NEXT సమయం కనిపిస్తుంది. Schedule రోజుకు రెండుసార్లు ఉంటుంది మరియు randomized delay ను ఉపయోగిస్తుంది. అందువల్ల ఖచ్చితమైన సమయం ఉద్దేశపూర్వకంగా ముందుగా తెలియదు. snap install లో timer బదులుగా snap.certbot.renew.timer ఉంటుంది. Dry run, Let's Encrypt staging environment కు వ్యతిరేకంగా పూర్తి renewal rehearsal ను నిర్వహిస్తుంది. ఇందులో నిజమైన challenge ఉంటుంది, కానీ certificate issue చేయబడదు మరియు rate-limit పై ఎలాంటి ఖర్చు ఉండదు. సరైన ఫలితం ఈ విధంగా ముగుస్తుంది:

Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/example.com/fullchain.pem (success)

Dry run విఫలమైతే, సుమారు 60 days తర్వాత జరిగే నిజమైన renewal కూడా అదే విధంగా విఫలమవుతుంది. ప్రస్తుత certificate కు ఇంకా దాని పూర్తి validity period మిగిలి ఉన్నప్పుడే సమస్యను పరిష్కరించండి. సాధారణ కారణం, certificate issue చేసిన తర్వాత జోడించిన firewall rule వల్ల port 80 మళ్లీ మూసుకుపోవడం.

curl తో నిర్ధారించండి; padlock ఏమి చూపించాలి

curl -sI http://example.com | head -n 3
curl -I https://example.com
echo | openssl s_client -connect example.com:443 -servername example.com 2>/dev/null | openssl x509 -noout -issuer -dates

మొదటి ఆదేశం HTTP/1.1 301 Moved Permanently ను, అలాగే Location: https://example.com/ header ను చూపించాలి. ఇది Certbot ఇన్‌స్టాల్ చేసిన redirect. రెండవ ఆదేశం HTTP/1.1 200 OK ను చూపించాలి. curl నుంచి ఎలాంటి TLS ఫిర్యాదు ఉండకూడదు. మూడవ ఆదేశం issuer ను చూపిస్తుంది. అందులో O = Let's Encrypt line ఉంటుంది. దాని CN సాధారణంగా R12 లేదా E7 వంటి చిన్న విలువగా ఉంటుంది. అలాగే notAfter గడువు సుమారు 90 రోజుల తర్వాత ఉండాలి. Browserలో padlock కనిపిస్తుంది. దానిపై click చేస్తే అదే issuer కనిపిస్తుంది. curl పనిచేసి, browser హెచ్చరిక చూపిస్తే, మీరు దాదాపు ఖచ్చితంగా cached page ను లేదా తప్పు hostname ను చూస్తున్నారు; ఇది certificate సమస్య కాదు.

బహుళ సైట్‌లు: ఒక SAN certificate లేదా ఒక్కో సైట్‌కు ఒక certificate

రెండు విధానాలూ పనిచేస్తాయి. రెండింటికీ renewal విధానం ఒకటే. ఒకే serverలో పరస్పర సంబంధం లేని సైట్‌ల కోసం ప్రతి సైట్‌కు ఒకసారి issue command అమలు చేయండి. ప్రతి సైట్‌కు live/ కింద ప్రత్యేక directory మరియు ప్రత్యేక renewal config లభిస్తాయి. ఒక domainలో సమస్య వచ్చినా, ఇతర domainల renewal ఎప్పుడూ ఆగదు. ఇది నా default విధానం.

ఒకే సైట్‌కు అనేక పేర్లు ఉంటే, వాటిని ఒకే SAN certificateలో ఉంచండి. ఒక certificateలో గరిష్ఠంగా 100 పేర్లు ఉండవచ్చు. పైన example.com మరియు www.example.com తో ఇదే చేశారు. తరువాత ఇప్పటికే ఉన్న certificateకు పేరు జోడించాలంటే, certificate పేరు మరియు కొత్తగా ఉండాల్సిన పూర్తి జాబితాను ఇచ్చి మళ్లీ issue చేయండి:

sudo certbot --apache --cert-name example.com -d example.com -d www.example.com -d blog.example.com

Domainల సమితి మారిందని Certbot గుర్తిస్తుంది. జాబితాను విస్తరించడాన్ని నిర్ధారించమని అడుగుతుంది. తరువాత అదే live/ pathలో certificateను స్థానంలోనే భర్తీ చేస్తుంది. అందువల్ల మరేదీ మార్చాల్సిన అవసరం ఉండదు. ఈ జాబితా append కాదు, replacement. ఆ commandలో www ను చేర్చకపోతే, కొత్త certificateలో అది మౌనంగా తొలగిపోతుంది.

Wildcards కోసం DNS-01 అవసరం; సాధారణంగా wildcard అవసరం ఉండదు

HTTP-01 ద్వారా *.example.com జారీ చేయలేరు. Web serverపై ఒక file ఉంచడం ద్వారా ఒక hostnameపై నియంత్రణ ఉందని మాత్రమే నిరూపించవచ్చు, మొత్తం namespaceపై కాదు. Wildcards కోసం DNS-01 challenge అవసరం. Certbot _acme-challenge.example.com వద్ద TXT recordను సెట్ చేస్తుంది. ఆచరణలో దీనికి DNS provider కోసం API credentials కలిగిన certbot-dns-* plugin అవసరం. మరో మార్గం ప్రతి renewal సమయంలో --manual తో TXT recordsను చేతితో సవరించడం. ఇది చాలా అసౌకర్యంగా ఉంటుంది; దీనిపై ఆధారపడి ప్రణాళిక చేయవద్దు. TXT record పనిచేసే విధానం నుంచి unattended renewal చేసే plugin వరకు పూర్తి వివరణ DNS-01 ద్వారా Certbotతో wildcard certificates లో ఉంది. స్పష్టమైన సలహా: మీకు తెలిసిన నాలుగు subdomains ఉంటే, వాటినన్నింటినీ జాబితా చేసే SAN certificate wildcard కంటే సరళంగా ఉంటుంది. Serverపై DNS API keys ఉంచాల్సిన అవసరం కూడా ఉండదు.

లోపాల రకాలు: మీరు చూడబోయే సందేశాలతో

Apache configuration లోపభూయిష్టంగా ఉండటంతో Certbot ప్రారంభం కావడం లేదు.

The apache plugin is not working; there may be problems with your existing configuration.
The error was: MisconfigurationError('Error while running apache2ctl configtest.\n\nAction \'configtest\' failed.\nThe Apache error log may have more information.\n\nAH00526: Syntax error on line 12 of /etc/apache2/sites-enabled/example.com.conf')

ఏ పని ప్రారంభించే ముందు plugin configtest ను అమలు చేస్తుంది. Apache సరిగ్గా పనిచేయకపోతే అది వెంటనే ఆగిపోతుంది. Certbot exception యొక్క repr ను చూపిస్తుంది కాబట్టి \ns అక్షరాలా కనిపిస్తాయి. sudo apache2ctl configtest ను మీరే అమలు చేయండి. అది సాధారణంగా చేతితో configuration మార్చేటప్పుడు జరిగిన typo వల్ల ఏర్పడిన file మరియు line ను చూపిస్తుంది. అలాగే ఉనికిలో లేని path ను సూచించే SSLCertificateFile లేదా enable చేయని module ను సూచించే configuration కూడా కారణం కావచ్చు. అది Syntax OK ను చూపించే వరకు లోపాన్ని సరిచేయండి. తరువాత Certbot ను మళ్లీ అమలు చేయండి.

ఏ vhost కూడా domain కు సరిపోలడం లేదు.

Unable to find a virtual host listening on port 80 which is currently the only challenge port.

ఇది ముందుగా వివరించిన missing-ServerName లోపం. Certificate issue సమయంలో ఇది గుర్తించబడుతుంది. Enable చేసిన ప్రతి port-80 vhost లో మీ -d కు సరిపోలే ServerName/ServerAlias కోసం Certbot శోధించింది. కానీ ఏదీ కనుగొనలేదు. Apache వాస్తవంగా ఏ route ఉపయోగిస్తుందో sudo apache2ctl -S చూపిస్తుంది. సరైన vhost లో ServerName line జోడించి, reload చేసి, మళ్లీ ప్రయత్నించండి. దీనికి సమీపమైన మరో సమస్య validation తప్పు vhost కు చేరడం. మరొక site request ను స్వీకరించినందున challenge response Invalid response ... 404 గా తిరిగి రావచ్చు. నిర్ధారణ విధానం అదే. ఉపయోగించాల్సిన tool కూడా అదే: apache2ctl -S.

Validation timeout అవుతోంది.

Certbot failed to authenticate some domains (authenticator: apache).
...
Detail: ...: Timeout during connect (likely firewall problem)

మీ DNS చూపిస్తున్న address వద్ద port 80 కు TCP connection తెరవడం Let's Encrypt కు సాధ్యపడలేదు. సాధారణంగా సంభవించే కారణాలు ఇవి: provider యొక్క network firewall (ఇది ufw కు వేరు; hosting panel లో configure చేస్తారు), 443 లేదా SSH కు మాత్రమే అనుమతించే ufw ruleset, ఇంకా మునుపటి server కు చూపిస్తున్న DNS, లేదా stale-AAAA సమస్య. ఈ సందర్భంలో వారి servers IPv6 ద్వారా ప్రయత్నించాయి, కానీ మీ server IPv4 పై మాత్రమే సమాధానం ఇస్తుంది. VPS వెలుపల నుంచి పరీక్షించండి: మీ laptop లో curl -I http://example.com అమలు చేస్తే validator కు కనిపించే పరిస్థితినే పునరుత్పత్తి చేస్తుంది.

మళ్లీ మళ్లీ ప్రయత్నించడంతో rate limit ను చేరుకున్నారు.

Error creating new order :: too many failed authorizations recently: see https://letsencrypt.org/docs/rate-limits/

Let's Encrypt ప్రతి hostname కు, ప్రతి account కు, ప్రతి గంటలో 5 విఫలమైన validations ను అనుమతిస్తుంది. 2025 rate-limit మార్పుల తరువాత ఇది తిరిగి నింపబడే bucket గా పనిచేస్తుంది. సుమారు ప్రతి 12 minutes కు ఒక retry మళ్లీ లభిస్తుంది. firewall లోపం ఉన్నప్పుడు నిరంతరం retry చేయడం వల్ల ఈ పరిమితి త్వరగా ముగుస్తుంది. వేచి ఉండటం పనిచేస్తుంది. కానీ సరైన పరిష్కారం విధానాన్ని మార్చడం: ఏదైనా failure వచ్చిన తరువాత అది విజయవంతం అయ్యే వరకు staging environment తో debug చేయండి.

sudo certbot certonly --apache --dry-run -d example.com -d www.example.com

certonly ను గమనించండి: --dry-run ను certonly మరియు renew subcommands మాత్రమే అంగీకరిస్తాయి. ఒంటరిగా ఉన్న certbot --apache --dry-run రూపం అసలు run అవదు. అది --dry-run currently only works with the 'certonly' or 'renew' subcommands అని తెలియజేస్తుంది. Dry run staging కు వ్యతిరేకంగా validation చేస్తుంది. Staging కు సొంతంగా ఎక్కువ limits ఉంటాయి, అలాగే అది నిజమైన certificates జారీ చేయదు. అందువల్ల అక్కడ రోజంతా failures వచ్చినా సమస్య ఉండదు. Staging విజయవంతమైన తరువాత మాత్రమే అసలు command ను మళ్లీ అమలు చేయండి. మిగతా limits — ప్రతి registered domain కు వారానికి 50 certificates, అదే name set కు వారానికి 5 duplicates — ఒక script loop లో certificates ను మళ్లీ జారీ చేస్తుంటే మాత్రమే సాధారణంగా ఎదురవుతాయి.

HTTPS ప్రారంభమైన తరువాత కూడా certificate transport ను మాత్రమే సురక్షితం చేస్తుందని గుర్తుంచుకోండి. Server సురక్షితం అయిందని దాని అర్థం కాదు. Port 22 పై రోజంతా password guesses ఇంకా వస్తూనే ఉంటాయి. దీనితో Ubuntu 24.04లో Fail2ban ను కలిపి అమలు చేయడం తరువాతి సహజమైన 30 minutes పని.

FAQ

Ubuntu 24.04లో Apache కోసం Certbot ను snapతో ఇన్‌స్టాల్ చేయాలా లేదా aptతోనా?

aptను ఉపయోగించండి. Ubuntu 24.04లో Certbot 2.9.0 విడుదల ఉంది. ఈ గైడ్‌లోని అన్ని పనులకు ఇది సరిపడే తాజా version. ఇది unattended-upgrades ద్వారా security patches పొందుతుంది మరియు snapd అవసరం లేదు. వెంటనే అత్యంత తాజా release కావాలంటే లేదా snapగా మాత్రమే పంపిణీ చేసే DNS plugin అవసరమైతే snapను ఎంచుకోండి. మారితే, apt remove certbot python3-certbot-apache ముందుగా అమలు చేయండి. అప్పుడు రెండు renewal schedulers ఒకేసారి ఉండవు.

"Unable to find a virtual host listening on port 80" అని Certbot చెప్పినప్పుడు ఎలా పరిష్కరించాలి?

మీరు -dతో ఇచ్చిన domainకు సరిపోయే ServerName లేదా ServerAlias ఏదీ enabled port-80 vhostలో లేకపోవడం దీనికి కారణం. Ubuntu యొక్క default vhostలో ServerName వ్యాఖ్యగా ఉంచబడి ఉంటుంది. sudo apache2ctl -S అమలు చేయండి. ఆ hostnameకు బాధ్యత వహించాల్సిన vhostను కనుగొనండి లేదా సృష్టించండి. ServerName example.com జోడించి Apacheను reload చేయండి. తరువాత Certbotను మళ్లీ అమలు చేయండి.

"Timeout during connect (likely firewall problem)" ను ఎలా పరిష్కరించాలి?

మీ DNSలో ప్రచురించిన addressకు Let's Encrypt port 80 ద్వారా చేరుకోలేకపోయింది. ufwతో పాటు మీ provider panelలోని network firewallను కూడా పరిశీలించండి. dig +short example.com ఈ VPSకు resolve అవుతుందో నిర్ధారించండి. పాత లేదా తప్పుగా ఉన్న AAAA record ఉంటే తొలగించండి లేదా సరిచేయండి. IPv6 అందుబాటులో ఉంటే validation దానికే ప్రాధాన్యం ఇస్తుంది. Server బయట నుంచి curl -I http://example.comతో సరిచేసిన విషయం నిర్ధారించండి. నిజమైన issuanceకు ముందు sudo certbot certonly --apache --dry-run -d example.comతో పరీక్షించండి.

Ubuntu 24.04లో Certbot certificatesను స్వయంచాలకంగా renew చేస్తుందా?

అవును. apt package certbot.timerను ఇన్‌స్టాల్ చేస్తుంది. ఇది systemd timer. రోజుకు రెండుసార్లు నడిచి, expiryకి 30 రోజుల్లోపు ఉన్న ప్రతి certificateను renew చేస్తుంది. తరువాత Apacheను reload చేస్తుంది. ఇదే పని కోసం snap snap.certbot.renew.timerను ఉపయోగిస్తుంది. systemctl list-timers certbot.timerతో నిర్ధారించండి మరియు sudo certbot renew --dry-runతో పరీక్షించండి. దీనికి అదనంగా మీ స్వంత cron jobను జోడించవద్దు.

Certbot మరియు Apacheతో wildcard certificateను ఎలా పొందాలి?

Wildcard certificatesకు DNS-01 challenge అవసరం. Certbot _acme-challenge.example.com వద్ద TXT recordను ఉంచాలి. అందుకోసం మీ DNS provider API credentialsతో కూడిన certbot-dns-* plugin అవసరం. --manual ప్రత్యామ్నాయంలో ప్రతి renewal సమయంలో TXT recordsను చేతితో సవరించాలి. మీకు తెలిసిన subdomains కొద్దిమాత్రమే ఉంటే, వాటిని స్పష్టంగా జాబితా చేసే SAN certificate సరళమైనది. ఇది DNS API keysను server బయట ఉంచుతుంది.