HTTPS mit Certbot¶
Ziel¶
Diese Seite erklärt, wie HTTPS für öffentlich erreichbare Webapps und Dokumentationen mit Certbot und Let's Encrypt eingerichtet wird.
Die Anleitung ist allgemein verwendbar. Immohai dient als konkretes Praxisbeispiel.
Warum HTTPS wichtig ist¶
HTTP ist unverschlüsselt.
HTTPS schützt die Verbindung zwischen Browser und Server.
HTTPS ist Standard für moderne Webanwendungen und sollte für alle öffentlich erreichbaren Dienste verwendet werden.
HTTPS ist wichtig für:
- Schutz der übertragenen Daten
- Vertrauen im Browser
- Vermeidung von Sicherheitswarnungen
- moderne Webfunktionen
- saubere produktive Veröffentlichung
Grundprinzip¶
Nginx nimmt öffentliche Anfragen entgegen.
Certbot erstellt ein Zertifikat von Let's Encrypt und passt die Nginx-Konfiguration an.
Browser
↓
https://app.example.com
↓
Nginx mit TLS-Zertifikat
↓
lokaler Docker-Dienst
Voraussetzungen¶
Vor Certbot müssen diese Punkte erledigt sein:
- Domain ist gekauft.
- DNS zeigt auf die öffentliche Server-IP.
- Nginx ist installiert.
- Nginx Reverse Proxy funktioniert über HTTP.
- Port
80ist von außen erreichbar. - Firewall erlaubt HTTP und HTTPS.
- Docker-Dienste laufen lokal.
DNS prüfen:
nslookup app.example.com
HTTP prüfen:
curl -I http://app.example.com
Firewall prüfen:
sudo ufw status verbose
Erwartung:
OpenSSH ALLOW IN
Nginx Full ALLOW IN
Certbot installieren¶
sudo apt update
sudo apt install certbot python3-certbot-nginx -y
Version prüfen:
certbot --version
Zertifikat erstellen¶
Allgemeines Muster für eine Domain:
sudo certbot --nginx -d app.example.com
Allgemeines Muster für App und Dokumentation:
sudo certbot --nginx -d app.example.com -d docs.app.example.com
Mehrere Subdomains können gemeinsam in ein Zertifikat aufgenommen werden.
Empfehlung zur Zertifikatsstruktur¶
Für kleine Setups sind beide Varianten möglich.
Variante 1: gemeinsames Zertifikat¶
sudo certbot --nginx \
-d app.example.com \
-d docs.app.example.com
Vorteil:
- wenige Zertifikate
- einfache Verwaltung
Variante 2: einzelne Zertifikate¶
sudo certbot --nginx -d app.example.com
sudo certbot --nginx -d docs.app.example.com
Vorteil:
- klare Trennung pro Dienst
- einzelne Domains können unabhängig erneuert oder geändert werden
Für kleine Projekte ist ein gemeinsames Zertifikat meist ausreichend.
Certbot-Abfragen¶
Bei der Einrichtung fragt Certbot typischerweise:
| Frage | Empfehlung |
|---|---|
| E-Mail-Adresse | echte E-Mail-Adresse verwenden |
| Terms of Service | akzeptieren |
| Newsletter | optional |
| HTTP auf HTTPS umleiten | ja |
Die Weiterleitung von HTTP auf HTTPS sollte aktiviert werden.
Praxisbeispiel Immohai und Developer Playbook¶
Aktive Domains:
playbook.ohaisoft.com
immohai.ohaisoft.com
docs.immohai.ohaisoft.com
Beispiel für gemeinsames Zertifikat:
sudo certbot --nginx \
-d playbook.ohaisoft.com \
-d immohai.ohaisoft.com \
-d docs.immohai.ohaisoft.com
Alternativ getrennt:
sudo certbot --nginx -d playbook.ohaisoft.com
sudo certbot --nginx -d immohai.ohaisoft.com -d docs.immohai.ohaisoft.com
Im Praxisbeispiel ist HTTPS eingerichtet für:
https://playbook.ohaisoft.com
https://immohai.ohaisoft.com
https://docs.immohai.ohaisoft.com
HTTPS testen¶
curl -I https://playbook.ohaisoft.com
curl -I https://immohai.ohaisoft.com
curl -I https://docs.immohai.ohaisoft.com
Erwartung:
HTTP/2 200
oder:
HTTP/1.1 200 OK
HTTP-zu-HTTPS-Weiterleitung testen¶
curl -I http://playbook.ohaisoft.com
curl -I http://immohai.ohaisoft.com
curl -I http://docs.immohai.ohaisoft.com
Erwartung:
301 Moved Permanently
oder eine andere permanente Weiterleitung auf HTTPS.
Zertifikate anzeigen¶
sudo certbot certificates
Diese Ausgabe zeigt:
- Zertifikatsnamen
- enthaltene Domains
- Ablaufdatum
- Speicherpfade
Wichtig:
Private Keys niemals kopieren, veröffentlichen oder in Git speichern.
Automatische Erneuerung testen¶
Let's-Encrypt-Zertifikate laufen regelmäßig ab und müssen erneuert werden.
Certbot richtet normalerweise eine automatische Erneuerung ein.
Testlauf:
sudo certbot renew --dry-run
Erwartung:
Congratulations, all simulated renewals succeeded
Wenn dieser Test erfolgreich ist, ist die automatische Zertifikatserneuerung grundsätzlich funktionsfähig.
Nginx nach Certbot prüfen¶
Nach Certbot:
sudo nginx -t
sudo systemctl reload nginx
Status prüfen:
sudo systemctl status nginx
Browser-Test¶
Im Browser prüfen:
https://playbook.ohaisoft.com
https://immohai.ohaisoft.com
https://docs.immohai.ohaisoft.com
Erwartung:
- keine Zertifikatswarnung
- Schloss-Symbol im Browser
- richtige Inhalte
- automatische Weiterleitung von HTTP auf HTTPS
Best Practices¶
- HTTPS vor produktiver Nutzung einrichten.
- HTTP immer auf HTTPS weiterleiten.
sudo certbot renew --dry-runnach Einrichtung testen.- Zertifikatsablauf regelmäßig kontrollieren.
- Private Keys niemals dokumentieren.
- Keine Zertifikatsdateien in Git speichern.
- DNS und Nginx vor Certbot sauber prüfen.
- Für einfache Setups Certbot mit Nginx-Plugin verwenden.
Typische Fehler¶
| Fehler | Ursache | Lösung |
|---|---|---|
| Certbot Timeout | Port 80 nicht erreichbar |
Firewall, DNS und Nginx prüfen |
| Domain wird nicht gefunden | DNS zeigt nicht auf Server | nslookup ausführen |
| Nginx-Plugin funktioniert nicht | Paket fehlt | python3-certbot-nginx installieren |
| Browser zeigt Zertifikatswarnung | Zertifikat fehlt oder falsche Domain | Certbot erneut für richtige Domain ausführen |
| HTTP leitet nicht auf HTTPS weiter | Weiterleitung nicht aktiviert | Nginx-Konfiguration prüfen |
| Renewal schlägt fehl | HTTP-Challenge nicht erreichbar | sudo certbot renew --dry-run prüfen |
Checkliste¶
- [ ] DNS zeigt auf Server
- [ ] Nginx läuft
- [ ] HTTP funktioniert
- [ ] Firewall erlaubt
Nginx Full - [ ] Certbot installiert
- [ ] Nginx-Plugin für Certbot installiert
- [ ] Zertifikat erstellt
- [ ] HTTP-zu-HTTPS-Weiterleitung aktiviert
- [ ] HTTPS getestet
- [ ] HTTP-Weiterleitung getestet
- [ ]
sudo certbot renew --dry-runerfolgreich - [ ] Browser-Test durchgeführt