ติดตั้ง SSL ฟรีจาก Let's Encrypt ด้วย Certbot บน Nginx
Let's Encrypt เป็นหน่วยงานออกใบรับรอง SSL/TLS ที่ให้บริการฟรี ใบรับรองแต่ละใบมีอายุ 90 วัน จึงต้องต่ออายุอัตโนมัติ ซึ่งเครื่องมือ Certbot จัดการให้ได้ทั้งการขอใบรับรอง การแก้ไขไฟล์ตั้งค่า Nginx ให้ใช้ HTTPS และการต่ออายุตามกำหนด
คู่มือนี้เหมาะกับเซิร์ฟเวอร์ที่ติดตั้ง Nginx และมีเว็บไซต์ตอบสนองผ่าน HTTP ได้แล้ว หากยังไม่ได้ติดตั้ง ดูได้ที่ ติดตั้ง Nginx, PHP-FPM และ MariaDB (LEMP) บน Ubuntu สำหรับผู้ใช้ Plesk มีคู่มือแยกที่ วิธีการติดตั้ง SSL by Let's Encryption บน Plesk ฟรี
สิ่งที่ต้องเตรียม
- เซิร์ฟเวอร์ Ubuntu 22.04/24.04 หรือ AlmaLinux/Rocky Linux 8-9 ที่ติดตั้ง Nginx แล้ว
- ผู้ใช้ที่มีสิทธิ์
sudo - โดเมนที่ A Record (และ AAAA Record ถ้ามี) ชี้มายัง IP ของเซิร์ฟเวอร์นี้แล้ว ทั้ง
example.comและwww.example.com - พอร์ต 80 และ 443 เปิดจากอินเทอร์เน็ต เพราะ Let's Encrypt ต้องเข้ามาตรวจสอบผ่านพอร์ต 80
- ไฟล์ตั้งค่า Nginx ที่มีบรรทัด
server_name example.com www.example.com;ตรงกับโดเมนที่จะขอใบรับรอง
ขั้นตอนที่ 1: ตรวจสอบ DNS และ Firewall
ตรวจว่าโดเมนชี้มาถูก IP แล้ว (วิธีใช้คำสั่งเพิ่มเติมดูที่ ตรวจสอบ DNS ด้วย nslookup และ dig)
dig +short example.com
dig +short www.example.comผลลัพธ์ต้องเป็น IP ของเซิร์ฟเวอร์นี้ จากนั้นเปิดพอร์ตใน Firewall ของเครื่อง
สำหรับ Ubuntu ที่ใช้ UFW
sudo ufw allow 'Nginx Full'สำหรับ AlmaLinux หรือ Rocky Linux ที่ใช้ firewalld
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --reloadหากเซิร์ฟเวอร์มี Security Group หรือ Firewall ภายนอกจากฝั่งผู้ให้บริการ ให้เปิดพอร์ตนั้นเพิ่มด้วย
ขั้นตอนที่ 2: ติดตั้ง Certbot
Ubuntu
วิธีที่โครงการ Certbot แนะนำคือติดตั้งผ่าน snap ซึ่งจะได้เวอร์ชันล่าสุดเสมอ
sudo snap install --classic certbot
sudo ln -s /snap/bin/certbot /usr/bin/certbotหากไม่ต้องการใช้ snap สามารถติดตั้งจาก apt ได้ด้วย sudo apt install certbot python3-certbot-nginx อย่าติดตั้งทั้งสองแบบพร้อมกัน
AlmaLinux และ Rocky Linux
Certbot อยู่ใน EPEL Repository
sudo dnf install -y epel-release
sudo dnf install -y certbot python3-certbot-nginxตรวจสอบการติดตั้งด้วย certbot --version
ขั้นตอนที่ 3: ขอใบรับรองและตั้งค่า Nginx อัตโนมัติ
sudo certbot --nginx -d example.com -d www.example.comครั้งแรก Certbot จะถาม
- อีเมลสำหรับติดต่อเรื่องสำคัญของบัญชี
- การยอมรับ Terms of Service (ตอบ
Y) - การรับข่าวสารจาก EFF (ตอบตามต้องการ)
เมื่อสำเร็จจะเห็นข้อความประมาณนี้
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/example.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/example.com/privkey.pem
...
Successfully deployed certificate for example.com to /etc/nginx/sites-enabled/example.com
Successfully deployed certificate for www.example.com to /etc/nginx/sites-enabled/example.com
Congratulations! You have successfully enabled HTTPS on https://example.com and https://www.example.comCertbot จะเพิ่ม listen 443 ssl และตำแหน่งไฟล์ใบรับรองลงในไฟล์ตั้งค่าของ Nginx ให้ รวมถึงเพิ่มการ Redirect จาก HTTP ไป HTTPS Certbot เวอร์ชันปัจจุบันตั้งค่า Redirect ให้เป็นค่าเริ่มต้น ส่วนเวอร์ชันเก่าบางรุ่นจะถามก่อน หากต้องการระบุให้ชัดเจนให้เติม --redirect ต่อท้ายคำสั่ง
หมายเหตุ: ถ้าต้องการเพียงใบรับรองโดยไม่ให้ Certbot แก้ไฟล์ Nginx ให้ใช้
sudo certbot certonly --nginx -d example.comแล้วเพิ่มบรรทัดssl_certificateและssl_certificate_keyเอง
ขั้นตอนที่ 4: ตรวจสอบการต่ออายุอัตโนมัติ
Certbot ติดตั้งตัวตั้งเวลาของ systemd ไว้ให้แล้ว และจะต่ออายุใบรับรองเมื่อเหลืออายุน้อยกว่า 30 วัน ตรวจสอบตัวตั้งเวลาได้ด้วย
systemctl list-timers | grep -i certbotหากติดตั้งผ่าน snap จะเห็นชื่อ snap.certbot.renew.timer ส่วนการติดตั้งผ่าน apt จะเป็น certbot.timer บน AlmaLinux และ Rocky Linux ที่ติดตั้งจาก EPEL ให้ตรวจและเปิดใช้งานด้วย
sudo systemctl enable --now certbot-renew.timerจากนั้นทดสอบการต่ออายุแบบจำลอง ซึ่งไม่กระทบใบรับรองจริง
sudo certbot renew --dry-runผลลัพธ์ที่ถูกต้องจะลงท้ายด้วย Congratulations, all simulated renewals succeeded
หมายเหตุ: Let's Encrypt ยกเลิกการส่งอีเมลเตือนใบรับรองใกล้หมดอายุไปแล้วตั้งแต่ปี 2025 จึงควรทดสอบ
renew --dry-runให้ผ่าน และตรวจวันหมดอายุเป็นระยะ แทนการรออีเมลแจ้งเตือน
ตรวจสอบผลลัพธ์
- เปิด
https://example.comในเบราว์เซอร์ ต้องเห็นไอคอนแม่กุญแจและไม่มีคำเตือน - เปิด
http://example.comต้องถูกส่งต่อไปhttps://อัตโนมัติ - ดูรายการใบรับรองและวันหมดอายุด้วย
sudo certbot certificates - ตรวจจากฝั่ง Command Line ด้วย
curl -I https://example.comต้องได้สถานะ 200 หรือ 301 โดยไม่มี Error เรื่องใบรับรอง
ปัญหาที่พบบ่อย
Could not automatically find a matching server block
Certbot หาไฟล์ Nginx ที่มี server_name ตรงกับโดเมนไม่พบ ให้แก้ไฟล์ Server Block ใส่ server_name example.com www.example.com; รัน sudo nginx -t และ sudo systemctl reload nginx แล้วขอใหม่
Timeout during connect หรือ unauthorized
Let's Encrypt เข้ามาตรวจที่พอร์ต 80 ไม่ได้ หรือเข้าไปเจอเซิร์ฟเวอร์อื่น ตรวจว่า DNS ชี้ถูก IP (รวมถึง AAAA Record ที่อาจชี้ไป IP อื่น) และพอร์ต 80 เปิดทั้งที่ Firewall ในเครื่องและที่ Firewall ภายนอก หากใช้ Cloudflare แบบ Proxy (เมฆสีส้ม) ให้ปิด Proxy ชั่วคราวระหว่างขอใบรับรอง
too many certificates already issued
ติด Rate Limit ของ Let's Encrypt จากการขอใบรับรองชุดโดเมนเดิมซ้ำหลายครั้งในช่วงเวลาสั้น ๆ ให้รอตามเวลาที่ข้อความระบุ และระหว่างทดลองให้ใช้ --dry-run หรือ --staging ซึ่งไม่นับรวมใน Rate Limit ของระบบจริง
ต่ออายุแล้ว แต่เว็บยังใช้ใบรับรองเก่า
Nginx ยังไม่ได้โหลดใบรับรองใหม่ เมื่อใช้ปลั๊กอิน --nginx Certbot จะ reload ให้เอง แต่ถ้าใช้ certonly แบบอื่น ให้สร้าง Deploy Hook ด้วยคำสั่ง sudo sh -c 'printf "#!/bin/sh\nsystemctl reload nginx\n" > /etc/letsencrypt/renewal-hooks/deploy/reload-nginx.sh' แล้ว sudo chmod +x /etc/letsencrypt/renewal-hooks/deploy/reload-nginx.sh
หากทำตามขั้นตอนแล้วยังติดปัญหา สามารถติดต่อทีมงาน Support ของ THAI DATA CLOUD ได้ที่ https://thaidata.cloud/contact/ โดยแจ้งชื่อเซิร์ฟเวอร์ ระบบปฏิบัติการ ขั้นตอนที่ทำไปแล้ว และข้อความ Error ที่พบ เพื่อให้ตรวจสอบได้รวดเร็วขึ้น
- Categories:
- Cloud
- Tags:
- Cloud
- Cloud Server
Related Posts
หมวดหมู่ที่น่าสนใจ
- Account Settings
- AD Server
- AI
- Alibaba Cloud
- Anti-Spam Gateway
- AWS Amazon Web Services
- Campaign
- CentOS/AlmaLinux
- Cloud
- Cloud Backup
- Cloud Communication
- Cloud Migration
- Cloud Security
- Cloud Server Management
- Cloud Solution
- Cloud Solution for Government
- Cloud Solutions by Industry
- Cloud Storage
- Cloud VPS App Plus +
- Cloud VPS DirectAdmin
- Cloud VPS Plesk
- CSR
- Cyber Security
- Cybersecurity
- Data Sovereignty
- Database Server
- DDoS
- Digital Tranformation
- Digital Transformation
- Direct Mail
- Directadmin
- Domainname
- Ecommerce
- ERP
- Generative AI
- Getting Started
- Google Cloud
- Google G Suite
- Huawei Cloud
- IT News
- Linux Server
- Managed Cloud Services
- Managed Service Provider
- Manual
- Microsoft
- Microsoft 365
- Microsoft Azure
- News
- On-premise
- Private Mail Server
- Promotion
- Recommend Solution (Enterprise)
- Server
- Sovereign Cloud
- THAI DATA CLOUD Platform
- Ubuntu
- Ubuntu
- Uncategorized
- VMware
- VPS Server
- Web Design
- Web Hosting
- Web Hosting (DirectAdmin)
- Web Hosting (Plesk)
- Web Technologies
- Windows Server
- Wordpress
- Zimbra
- เรื่องราวความประทับใจ
- โซลูชันสำหรับธุรกิจการผลิตและยานยนต์
- โซลูชันสำหรับธุรกิจการศึกษา
- โซลูชันสำหรับธุรกิจการเงิน
- โซลูชันสำหรับธุรกิจขนส่งและกระจายสินค้า
- โซลูชันสำหรับธุรกิจค้าปลีก
- โซลูชันสำหรับธุรกิจท่องเที่ยว
- โซลูชันสำหรับธุรกิจบริการสุขภาพและโรงพยาบาล
- โซลูชันสำหรับธุรกิจประกันภัย
- โซลูชันสำหรับธุรกิจพลังงานและสาธารณูปโภค
- โซลูชันสำหรับธุรกิจสื่อสารมวลชนและเอ็นเตอร์เทนเมนท์
- โซลูชันสำหรับธุรกิจอสังหาริมทรัพย์
- โซลูชันสำหรับธุรกิจเทคโนโลยี


