Nginx와 Certbot으로 워드프레스 HTTPS 적용하기
워드프레스 사이트를 실제로 운영한다면 HTTPS는 이제 선택이 아닌 필수입니다. 구글 검색 순위에도 영향을 주고, 브라우저는 HTTP 사이트에 “안전하지 않음” 경고를 표시합니다. 다행히 Let’s Encrypt의 무료 인증서와 Certbot 도구를 사용하면 Nginx로 운영 중인 워드프레스에 HTTPS를 무료로, 그리고 자동 갱신까지 손쉽게 적용할 수 있습니다.
이 글에서는 Nginx + 워드프레스 환경에 Certbot으로 SSL 인증서를 발급하고 자동 갱신까지 설정하는 전 과정을 다룹니다.
1. 사전 준비 사항
시작하기 전에 아래 조건이 충족되어야 합니다.
- 도메인이 서버의 공인 IP로 연결되어 있어야 함 (A 레코드 설정 완료)
- Nginx가 이미 설치되어 워드프레스가 정상적으로 서비스되고 있어야 함
- 서버의 80번, 443번 포트가 외부에 열려 있어야 함 (방화벽 확인)
도메인 연결 확인:
dig +short yourdomain.com
출력된 IP가 서버의 공인 IP와 일치하면 정상입니다.
2. Certbot 설치
Ubuntu/Debian 계열:
sudo apt update
sudo apt install certbot python3-certbot-nginx -y
CentOS/RHEL 계열:
sudo dnf install certbot python3-certbot-nginx -y
python3-certbot-nginx 플러그인을 함께 설치하면 Nginx 설정 파일을 Certbot이 자동으로 수정해줍니다.
3. 기존 Nginx 설정 확인
HTTPS를 적용하기 전, 워드프레스용 Nginx 설정 파일이 아래와 같은 기본 구조인지 확인합니다.
# /etc/nginx/sites-available/yourdomain.com
server {
listen 80;
server_name yourdomain.com www.yourdomain.com;
root /var/www/wordpress;
index index.php index.html;
location / {
try_files $uri $uri/ /index.php?$args;
}
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php8.2-fpm.sock;
}
location ~ /\.ht {
deny all;
}
}
설정 파일 문법 검사:
sudo nginx -t
syntax is ok, test is successful 메시지가 나오면 다음 단계로 진행합니다.
4. Certbot으로 인증서 발급 및 자동 적용
Nginx 플러그인을 사용하면 인증서 발급과 Nginx 설정 수정을 한 번에 처리할 수 있습니다.
sudo certbot --nginx -d yourdomain.com -d www.yourdomain.com
실행하면 아래와 같은 절차가 진행됩니다.
- 이메일 주소 입력 (인증서 만료 알림 수신용)
- 서비스 약관 동의
- HTTP 요청을 HTTPS로 자동 리다이렉트할지 여부 선택 (권장: 예)
완료되면 아래처럼 인증서 발급 성공 메시지가 표시됩니다.
Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/yourdomain.com/fullchain.pem
Key is saved at: /etc/letsencrypt/live/yourdomain.com/privkey.pem
Certbot은 자동으로 Nginx 설정 파일을 수정해 아래와 같은 형태로 바꿔줍니다.
server {
listen 443 ssl;
server_name yourdomain.com www.yourdomain.com;
root /var/www/wordpress;
index index.php index.html;
ssl_certificate /etc/letsencrypt/live/yourdomain.com/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/yourdomain.com/privkey.pem;
include /etc/letsencrypt/options-ssl-nginx.conf;
ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
location / {
try_files $uri $uri/ /index.php?$args;
}
location ~ \.php$ {
include snippets/fastcgi-php.conf;
fastcgi_pass unix:/var/run/php/php8.2-fpm.sock;
}
}
server {
listen 80;
server_name yourdomain.com www.yourdomain.com;
return 301 https://$host$request_uri;
}
5. 워드프레스 설정에서도 HTTPS 반영하기
Nginx 설정만으로는 부족합니다. 워드프레스 내부에서도 사이트 주소를 HTTPS로 인식시켜야 콘텐츠, 이미지, 관리자 페이지 전반이 정상 작동합니다.
방법 1: 관리자 대시보드에서 변경
설정 → 일반으로 이동해 아래 두 항목을 https://로 시작하도록 수정합니다.
- 워드프레스 주소(URL)
- 사이트 주소(URL)
방법 2: wp-config.php에서 강제 지정 (관리자 접속이 안 될 때)
define('WP_HOME', 'https://yourdomain.com');
define('WP_SITEURL', 'https://yourdomain.com');
방법 3: 데이터베이스 직접 수정 (URL을 통째로 이전한 경우)
기존에 HTTP로 저장된 게시글 내 이미지 링크 등을 일괄 변경해야 한다면 WP-CLI를 활용하는 것이 안전합니다.
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --skip-columns=guid
6. 인증서 자동 갱신 설정
Let’s Encrypt 인증서의 유효 기간은 90일입니다. Certbot 설치 시 대부분 자동 갱신용 타이머(systemd timer)나 cron이 함께 등록되지만, 정상 동작하는지 반드시 확인해야 합니다.
systemd 타이머 확인:
sudo systemctl status certbot.timer
수동으로 갱신 테스트 (실제 갱신 없이 시뮬레이션):
sudo certbot renew --dry-run
Congratulations, all simulated renewals succeeded 메시지가 나오면 자동 갱신이 정상적으로 설정된 것입니다.
cron으로 별도 등록하고 싶다면:
sudo crontab -e
아래 줄 추가 (매일 새벽 3시에 갱신 시도, 필요할 때만 실제 갱신됨):
0 3 * * * /usr/bin/certbot renew --quiet && systemctl reload nginx
7. Docker 환경에서 Nginx + Certbot 적용하기
Docker Compose로 워드프레스를 운영 중이라면 Nginx와 Certbot도 컨테이너로 함께 구성할 수 있습니다.
services:
nginx:
image: nginx:latest
ports:
- "80:80"
- "443:443"
volumes:
- ./nginx/conf.d:/etc/nginx/conf.d
- certbot_www:/var/www/certbot
- certbot_conf:/etc/letsencrypt
depends_on:
- wordpress
certbot:
image: certbot/certbot
volumes:
- certbot_www:/var/www/certbot
- certbot_conf:/etc/letsencrypt
entrypoint: >
sh -c "trap exit TERM; while :; do
certbot renew --webroot -w /var/www/certbot;
sleep 12h & wait $${!}; done"
volumes:
certbot_www:
certbot_conf:
최초 인증서 발급은 아래처럼 1회성 컨테이너 실행으로 처리합니다.
docker compose run --rm certbot certonly --webroot \
-w /var/www/certbot \
-d yourdomain.com -d www.yourdomain.com \
--email you@example.com --agree-tos --no-eff-email
8. 흔한 문제와 해결법
| 문제 | 원인 및 해결 |
|---|---|
Challenge failed 오류 | 도메인이 서버 IP로 연결되지 않았거나 80번 포트가 막혀있음. DNS 전파 및 방화벽 확인 |
| HTTPS 적용 후 이미지가 깨짐 | 워드프레스 내부 URL이 여전히 HTTP로 저장되어 있음. wp search-replace로 일괄 변경 |
| “혼합 콘텐츠(Mixed Content)” 경고 | 일부 리소스가 HTTP로 강제 로드됨. 플러그인(Really Simple SSL 등) 또는 코드에서 강제 리다이렉트 적용 |
| 인증서 갱신 실패 | Nginx가 80번 포트에서 Certbot의 챌린지 요청을 처리하지 못함. webroot 경로 및 Nginx 설정 재확인 |
9. 요약
Nginx와 Certbot을 이용한 HTTPS 적용 과정을 정리하면 다음과 같습니다.
- 도메인이 서버 IP로 정상 연결되어 있는지 확인
- Certbot과 Nginx 플러그인 설치
certbot --nginx명령 한 줄로 인증서 발급 및 Nginx 설정 자동화- 워드프레스 관리자 설정 또는
wp-config.php에서 사이트 URL을 HTTPS로 변경 certbot renew --dry-run으로 자동 갱신 정상 작동 확인
한 번 설정해두면 90일마다 인증서가 자동으로 갱신되므로, 이후에는 별도의 수동 작업 없이 안전하게 HTTPS 사이트를 운영할 수 있습니다.