Zum Inhalt

HTTPS mit Certbot

Ziel

Diese Seite erklärt, wie HTTPS für öffentlich erreichbare Webapps und Dokumentationen mit Certbot und Let's Encrypt eingerichtet wird.

Die Anleitung ist allgemein verwendbar. Immohai dient als konkretes Praxisbeispiel.

Warum HTTPS wichtig ist

HTTP ist unverschlüsselt.

HTTPS schützt die Verbindung zwischen Browser und Server.

HTTPS ist Standard für moderne Webanwendungen und sollte für alle öffentlich erreichbaren Dienste verwendet werden.

HTTPS ist wichtig für:

  • Schutz der übertragenen Daten
  • Vertrauen im Browser
  • Vermeidung von Sicherheitswarnungen
  • moderne Webfunktionen
  • saubere produktive Veröffentlichung

Grundprinzip

Nginx nimmt öffentliche Anfragen entgegen.

Certbot erstellt ein Zertifikat von Let's Encrypt und passt die Nginx-Konfiguration an.

Browser
↓
https://app.example.com
↓
Nginx mit TLS-Zertifikat
↓
lokaler Docker-Dienst

Voraussetzungen

Vor Certbot müssen diese Punkte erledigt sein:

  • Domain ist gekauft.
  • DNS zeigt auf die öffentliche Server-IP.
  • Nginx ist installiert.
  • Nginx Reverse Proxy funktioniert über HTTP.
  • Port 80 ist von außen erreichbar.
  • Firewall erlaubt HTTP und HTTPS.
  • Docker-Dienste laufen lokal.

DNS prüfen:

nslookup app.example.com

HTTP prüfen:

curl -I http://app.example.com

Firewall prüfen:

sudo ufw status verbose

Erwartung:

OpenSSH         ALLOW IN
Nginx Full      ALLOW IN

Certbot installieren

sudo apt update
sudo apt install certbot python3-certbot-nginx -y

Version prüfen:

certbot --version

Zertifikat erstellen

Allgemeines Muster für eine Domain:

sudo certbot --nginx -d app.example.com

Allgemeines Muster für App und Dokumentation:

sudo certbot --nginx -d app.example.com -d docs.app.example.com

Mehrere Subdomains können gemeinsam in ein Zertifikat aufgenommen werden.

Empfehlung zur Zertifikatsstruktur

Für kleine Setups sind beide Varianten möglich.

Variante 1: gemeinsames Zertifikat

sudo certbot --nginx \
  -d app.example.com \
  -d docs.app.example.com

Vorteil:

  • wenige Zertifikate
  • einfache Verwaltung

Variante 2: einzelne Zertifikate

sudo certbot --nginx -d app.example.com
sudo certbot --nginx -d docs.app.example.com

Vorteil:

  • klare Trennung pro Dienst
  • einzelne Domains können unabhängig erneuert oder geändert werden

Für kleine Projekte ist ein gemeinsames Zertifikat meist ausreichend.

Certbot-Abfragen

Bei der Einrichtung fragt Certbot typischerweise:

Frage Empfehlung
E-Mail-Adresse echte E-Mail-Adresse verwenden
Terms of Service akzeptieren
Newsletter optional
HTTP auf HTTPS umleiten ja

Die Weiterleitung von HTTP auf HTTPS sollte aktiviert werden.

Praxisbeispiel Immohai und Developer Playbook

Aktive Domains:

playbook.ohaisoft.com
immohai.ohaisoft.com
docs.immohai.ohaisoft.com

Beispiel für gemeinsames Zertifikat:

sudo certbot --nginx \
  -d playbook.ohaisoft.com \
  -d immohai.ohaisoft.com \
  -d docs.immohai.ohaisoft.com

Alternativ getrennt:

sudo certbot --nginx -d playbook.ohaisoft.com
sudo certbot --nginx -d immohai.ohaisoft.com -d docs.immohai.ohaisoft.com

Im Praxisbeispiel ist HTTPS eingerichtet für:

https://playbook.ohaisoft.com
https://immohai.ohaisoft.com
https://docs.immohai.ohaisoft.com

HTTPS testen

curl -I https://playbook.ohaisoft.com
curl -I https://immohai.ohaisoft.com
curl -I https://docs.immohai.ohaisoft.com

Erwartung:

HTTP/2 200

oder:

HTTP/1.1 200 OK

HTTP-zu-HTTPS-Weiterleitung testen

curl -I http://playbook.ohaisoft.com
curl -I http://immohai.ohaisoft.com
curl -I http://docs.immohai.ohaisoft.com

Erwartung:

301 Moved Permanently

oder eine andere permanente Weiterleitung auf HTTPS.

Zertifikate anzeigen

sudo certbot certificates

Diese Ausgabe zeigt:

  • Zertifikatsnamen
  • enthaltene Domains
  • Ablaufdatum
  • Speicherpfade

Wichtig:

Private Keys niemals kopieren, veröffentlichen oder in Git speichern.

Automatische Erneuerung testen

Let's-Encrypt-Zertifikate laufen regelmäßig ab und müssen erneuert werden.

Certbot richtet normalerweise eine automatische Erneuerung ein.

Testlauf:

sudo certbot renew --dry-run

Erwartung:

Congratulations, all simulated renewals succeeded

Wenn dieser Test erfolgreich ist, ist die automatische Zertifikatserneuerung grundsätzlich funktionsfähig.

Nginx nach Certbot prüfen

Nach Certbot:

sudo nginx -t
sudo systemctl reload nginx

Status prüfen:

sudo systemctl status nginx

Browser-Test

Im Browser prüfen:

https://playbook.ohaisoft.com
https://immohai.ohaisoft.com
https://docs.immohai.ohaisoft.com

Erwartung:

  • keine Zertifikatswarnung
  • Schloss-Symbol im Browser
  • richtige Inhalte
  • automatische Weiterleitung von HTTP auf HTTPS

Best Practices

  • HTTPS vor produktiver Nutzung einrichten.
  • HTTP immer auf HTTPS weiterleiten.
  • sudo certbot renew --dry-run nach Einrichtung testen.
  • Zertifikatsablauf regelmäßig kontrollieren.
  • Private Keys niemals dokumentieren.
  • Keine Zertifikatsdateien in Git speichern.
  • DNS und Nginx vor Certbot sauber prüfen.
  • Für einfache Setups Certbot mit Nginx-Plugin verwenden.

Typische Fehler

Fehler Ursache Lösung
Certbot Timeout Port 80 nicht erreichbar Firewall, DNS und Nginx prüfen
Domain wird nicht gefunden DNS zeigt nicht auf Server nslookup ausführen
Nginx-Plugin funktioniert nicht Paket fehlt python3-certbot-nginx installieren
Browser zeigt Zertifikatswarnung Zertifikat fehlt oder falsche Domain Certbot erneut für richtige Domain ausführen
HTTP leitet nicht auf HTTPS weiter Weiterleitung nicht aktiviert Nginx-Konfiguration prüfen
Renewal schlägt fehl HTTP-Challenge nicht erreichbar sudo certbot renew --dry-run prüfen

Checkliste

  • [ ] DNS zeigt auf Server
  • [ ] Nginx läuft
  • [ ] HTTP funktioniert
  • [ ] Firewall erlaubt Nginx Full
  • [ ] Certbot installiert
  • [ ] Nginx-Plugin für Certbot installiert
  • [ ] Zertifikat erstellt
  • [ ] HTTP-zu-HTTPS-Weiterleitung aktiviert
  • [ ] HTTPS getestet
  • [ ] HTTP-Weiterleitung getestet
  • [ ] sudo certbot renew --dry-run erfolgreich
  • [ ] Browser-Test durchgeführt