新建证书
wget https://dl.eff.org/certbot-auto
sudo mv certbot-auto /usr/local/bin/certbot-auto
sudo chown root /usr/local/bin/certbot-auto
sudo chmod 0755 /usr/local/bin/certbot-auto
certbot-auto --server https://acme-v02.api.letsencrypt.org/directory -d "example.com" -d "*.example.com" --manual --preferred-challenges dns-01 certonly
然后根据提示,域名里添加一个 TXT 字段
之后会生成证书和 key 到
/etc/letsencrypt/live/example.com/fullchain.pem
/etc/letsencrypt/live/example.com/privkey.pem
更新证书
certbot-auto --force-renewal