Let窶冱 Encrypt 菴ソ逕ィ譁ケ豕
逶ョ谺。
Let窶冱 Encrypt縺ィ縺ッ
縲後う繝ウ繧ソ繝シ繝阪ャ繝医r莉九@縺溷ョ牙ィ縺ェ騾壻ソ。繧定。後≧髫帙ョ縲∫オ梧ク磯擇繝サ謚陦馴擇繝サ謨呵ご髱「縺ァ縺ョ髫懷」√r貂帙i縺吶阪r菴ソ蜻ス縺ィ縺励※縺繧九髱槫霧蛻ゥ蝗」菴的SRG縺碁幕逋コ縺励◆繧オ繝シ繝薙せ
辟。譁吶∫ー。蜊倥↓WEB繧オ繧、繝医rSSL蛹悶〒縺阪k
繧、繝ウ繧ケ繝医シ繝ォ
Python繧、繝ウ繧ケ繝医シ繝ォ
# scl enable python27 bash
certbot繧、繝ウ繧ケ繝医シ繝ォ
certbotシ扠et窶冱 Encrypt縺梧署萓帙☆繧玖ィシ譏取嶌逋コ陦後サ譖エ譁ー繝繝シ繝ォ
# cd /usr/local
# git clone https://github.com/letsencrypt/letsencrypt
certbot-auto繧、繝ウ繧ケ繝医シ繝ォ
certbot-autoシ扠et窶冱 Encrypt縺梧署萓帙☆繧玖ィシ譏取嶌逋コ陦後サ譖エ譁ー繝繝シ繝ォ
Let窶冱 Encrypt縺九i險シ譏取嶌繧貞叙蠕励@縲√し繝シ繝舌ョHTTPS繧呈怏蜉ケ蛹悶☆繧
# curl https://dl.eff.org/certbot-auto -o /usr/bin/certbot-auto
# chmod 700 /usr/bin/certbot-auto
險シ譏取嶌逕滓
apache繧貞●豁「縺励※縺翫¥莠
騾壼クク
# letsencrypt/letsencrypt-auto certonly -a standalone -d 繝峨Γ繧、繝ウ蜷
# letsencrypt/letsencrypt-auto certonly -a standalone -d office-yone.com
DNS菴ソ逕ィ
certbot certonly
–manual
繧オ繝悶ラ繝。繧、繝ウ逕ィ
–domain *.office-yone.com
繝。繧、繝ウ繝峨Γ繧、繝ウ逕ィ
–domain office-yone.com
–email yone@office-yone.com
–agree-tos
–manual-public-ip-logging-ok
–preferred-challenges dns-01
–server https://acme-v02.api.letsencrypt.org/directory
螳溯。悟セ後Γ繝繧サ繝シ繧ク
Please deploy a DNS TXT record under the name
_acme-challenge.office-yone.com with the following value:
竊薙rDNS逋サ骭イ(TXT繝ャ繧ウ繝シ繝)
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
繝峨Γ繧、繝ウ繧定、謨ー謖螳壹@縺溷エ蜷医∬、謨ーDNS逋サ骭イ縺吶k
Before continuing, verify the record is deployed.
邨先棡
竊 縺ォ險シ譏取嶌縲∫ァ伜ッ骰オ縺檎函謌舌&繧後k
/etc/letsencrypt/live/office-yone.com/
笏把ert.pem
笏廃rivkey.pem
笏把hain.pem
險ュ螳
險シ譏取嶌險ュ螳
窶サ /etc/httpd/conf.d/ssl.conf
SSLCertificateFile /etc/letsencrypt/live/office-yone.com/cert.pem
SSLCertificateKeyFile /etc/letsencrypt/live/office-yone.com/privkey.pem
SSLCertificateChainFile /etc/letsencrypt/live/office-yone.com/chain.pem
險ュ螳壼セ後‖pache繧定オキ蜍輔@縺ヲ縺翫¥莠
Let窶冱 Encrypt縺ョ險シ譏取悄髯舌ッ3繧ォ譛
WEB繧オ繧、繝医ョ繝ェ繝ウ繧ッ菫ョ豁」
荳願ィ倩ィュ螳壹↓繧医jSSL蛹悶ッ螳御コ縲
繧オ繧、繝亥縺ァ縲粂ttp://ス槭阪〒繝ェ繝ウ繧ッ繧貞シオ縺」縺ヲ縺繧句エ蜷医
荳願ィ倡判蜒上ョ讒倥↓縲御ソ晁ュキ縺輔l縺滄壻ソ。縲阪→縺ェ繧峨★縲√鯉シ√阪′陦ィ遉コ縺輔l縺ヲ縺繧句エ蜷医ッ縲√粂ttps://ス槭阪↓螟画峩縺吶k
HTTP竊辿TTPS縺ク繝ェ繝繧、繝ャ繧ッ繝
.htaccess繝輔ぃ繧、繝ォ
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R,L]
險シ譏取嶌縺ョ閾ェ蜍募ョ壽悄譖エ譁ー
# crontab -e
00 04 01 * * ス/certbot-auto renew フ–force-renew && service httpd graceful
豈取怦1譌・4:00縺ォcertbot-auto繧貞ョ壽悄螳溯。
縲Linux CRON縲榊盾辣ァ