{"id":1686,"date":"2023-01-05T19:30:18","date_gmt":"2023-01-05T10:30:18","guid":{"rendered":"https:\/\/ysfarm.jp\/blog\/?p=1686"},"modified":"2023-01-06T20:53:17","modified_gmt":"2023-01-06T11:53:17","slug":"centos-stream9-%e5%88%9d%e6%9c%9f%e8%a8%ad%e5%ae%9a-%e3%81%9d%e3%81%ae4-apache-ssl-tls%e5%af%be%e5%bf%9c-lets-encrypt","status":"publish","type":"post","link":"https:\/\/ysfarm.jp\/blog\/2023\/01\/05\/centos-stream9-%e5%88%9d%e6%9c%9f%e8%a8%ad%e5%ae%9a-%e3%81%9d%e3%81%ae4-apache-ssl-tls%e5%af%be%e5%bf%9c-lets-encrypt\/","title":{"rendered":"CentOS Stream9 \u521d\u671f\u8a2d\u5b9a \u305d\u306e4 apache SSL\/TLS\u5bfe\u5fdc Let&#8217;s Encrypt"},"content":{"rendered":"<p>\u300cLet&#8217;s Encrypt\u300d\u304b\u3089\u7121\u6599\u306eSSL\/TLS\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002<\/p>\n<p>\u5916\u90e8\u304b\u3089\u30a2\u30af\u30bb\u30b9\u3055\u308c\u308b\u306e\u3067DDNS\u306a\u3069\u3067\u5916\u90e8\u304b\u3089\u30c9\u30e1\u30a4\u30f3\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u524d\u63d0\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\nDDNS\u306b\u3064\u3044\u3066\u306f\u307e\u305f\u5f8c\u65e5\uff08\u66f8\u304f\u304b\u3082\u3057\u308c\u306a\u3044\uff09<\/p>\n<p>\u300cLet&#8217;s Encrypt\u300d\u306fWeb \u5168\u4f53\u306e\u5b89\u5168\u6027\u3092\u6539\u5584\u3059\u308b\u3053\u3068\u3092\u30df\u30c3\u30b7\u30e7\u30f3\u306b\u63b2\u3052\u3066\u3044\u307e\u3059\u3002<br \/>\nLet&#8217;s Encrypt \u306e\u8a73\u7d30\u306f\u516c\u5f0f\u30b5\u30a4\u30c8\u3092\u53c2\u7167\u304f\u3060\u3055\u3044\u3002<br \/>\n\u21d2 <a href=\"https:\/\/letsencrypt.org\/\">https:\/\/letsencrypt.org\/<\/a><\/p>\n<p>\u8a3c\u660e\u66f8\u306e\u6709\u52b9\u671f\u9650\u306f90\u65e5\u306a\u306e\u3067\u300190\u65e5\u4ee5\u5185\u306b\u66f4\u65b0\u4f5c\u696d\u3092\u518d\u5ea6\u5b9f\u65bd\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>SSL\/TLS\u306e\u8a2d\u5b9a\u3092\u6709\u52b9\u5316\u3057\u307e\u3059<\/p>\n<pre>\r\nsudo dnf -y install mod_ssl\r\n\r\nsudo vi \/etc\/httpd\/conf.d\/ssl.conf\r\n\r\n#43\u884c\u76ee : \u30b3\u30e1\u30f3\u30c8\u89e3\u9664\r\nDocumentRoot \"\/var\/www\/html\"\r\n\r\n# 44\u884c\u76ee : \u30b3\u30e1\u30f3\u30c8\u89e3\u9664\u3057\u30b5\u30fc\u30d0\u30fc\u540d\u6307\u5b9a\r\nServerName ysfarmsvr.com:443\r\n\r\n\r\nsudo systemctl restart httpd\r\n\r\nfirewall-cmd --add-service=https\r\nfirewall-cmd --runtime-to-permanent\r\n\r\n<\/pre>\n<p>Cerbot\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u4f7f\u3063\u3066\u81ea\u52d5\u66f4\u65b0\u3092\u8a2d\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p>\u6700\u521d\u306bSnapd \u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u304a\u304d\u307e\u3059\u3002<br \/>\nSnapd\u306f\u30d1\u30c3\u30b1\u30fc\u30b8\u7ba1\u7406\u30c4\u30fc\u30eb\u3067\u3059\u3002<br \/>\nyum\u3084dnf\u3067\u3082\u3044\u3044\u3088\u3046\u306b\u611f\u3058\u307e\u3059\u304c\u3001\u53c2\u8003\u30b5\u30a4\u30c8\u3067Snapd\u3092\u4f7f\u3046\u3088\u3046\u306b\u66f8\u3044\u3066\u3042\u3063\u305f\u306e\u3067\u305d\u308c\u306b\u5f93\u3063\u3066\u307f\u307e\u3059\u3002<\/p>\n<pre>\r\nsudo dnf --enablerepo=epel -y install snapd\r\n\r\nsudo ln -s \/var\/lib\/snapd\/snap \/snap\r\n\r\nsudo systemctl enable --now snapd.service snapd.socket\r\n\r\n\r\n# \u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6e08 Snap \u30d1\u30c3\u30b1\u30fc\u30b8\u4e00\u89a7\r\nsudo snap list\r\nNo snaps are installed yet. Try 'snap install hello-world'.\r\n\r\n# Snap \u30ea\u30dd\u30b8\u30c8\u30ea\u304b\u3089\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30ef\u30fc\u30c9\u691c\u7d22\r\nsnap find kubernetes\r\n\r\nName                         Version                Publisher              Notes    Summary\r\nkubernetes-worker            0.0.2                  canonical\u2713            -        A complete Kubernetes worker\r\nkubernetes-test              1.23.4                 canonical\u2713            classic  tests for kubernetes\r\nkubernetes-test-eks          1.10.3                 canonical-cloud-snaps  classic  tests for kubernetes\r\nmicrok8s                     v1.23.4                canonical\u2713            classic  Kubernetes for workstations and ap\r\n.....\r\n.....\u4ee5\u4e0b\u7d9a\u304f\u30fb\u30fb\u30fb\r\n\r\n\r\n[hello-world] \u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\r\nsudo snap install hello-world\r\nhello-world 6.4 from Canonical\u2713 installed\r\n\r\n\u30ea\u30b9\u30c8\u3092\u8868\u793a\uff1a\u5165\u3063\u3066\u308b\u5165\u3063\u3066\u308b\r\nsudo snap list\r\nName         Version    Rev    Tracking       Publisher   Notes\r\ncore         16-2.57.6  14399  latest\/stable  canonical\u2713  core\r\nhello-world  6.4        29     latest\/stable  canonical\u2713  -\r\n\r\n<\/pre>\n<p>\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306e\u30c4\u30fc\u30eb Certbot \u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002<\/p>\n<pre>\r\nsudo snap install certbot --classic\r\n\r\ncertbot 1.32.2 from Certbot Project (certbot-eff\u2713) installed\r\n\r\nsudo ln -s \/snap\/bin\/certbot \/usr\/bin\/certbot\r\n\r\nsudo firewall-cmd --add-port=443\/tcp --zone=public\r\nsudo firewall-cmd --add-port=443\/tcp --zone=public --permanent\r\n\r\n<\/pre>\n<p>cerbot\u30b3\u30de\u30f3\u30c9\u304c\u901a\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059<\/p>\n<pre>\r\nsudo certbot --version\r\n\r\ncertbot 1.32.2\r\n<\/pre>\n<p>\u30d0\u30fc\u30b8\u30e7\u30f3\u60c5\u5831\u304c\u8868\u793a\u3055\u308c\u305f\u3089\u6210\u529f\u3067\u3059<\/p>\n<hr>\n<p>SSL\u3068cerbot\u304c\u5165\u3063\u305f\u3089\u300cLet&#8217;s Encrypt\u300d\u306b\u767b\u9332\u3057\u307e\u3059\u3002<\/p>\n<pre>\r\nsudo certbot --apache\r\n\r\n# \u521d\u56de\u306e\u307f\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u306e\u767b\u9332\u3068\u5229\u7528\u6761\u4ef6\u3078\u306e\u540c\u610f\u304c\u5fc5\u8981\r\nEnter email address (used for urgent renewal and security notices)\r\n# \u53d7\u4fe1\u53ef\u80fd\u306a\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u6307\u5b9a\r\n (Enter 'c' to cancel): root@mail.ysfarmsvr.com\r\n\r\n# \u5229\u7528\u6761\u4ef6\u306b\u540c\u610f\u3059\u308b\r\n(Y)es\/(N)o: Y\r\n\r\n# \u975e\u55b6\u5229\u56e3\u4f53 Electronic Frontier Foundation \u306b\u3082\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u3092\u767b\u9332\u3059\u308b\u304b\u5426\u304b\r\n(Y)es\/(N)o: Y\r\n\r\nWhich names would you like to activate HTTPS for?\r\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\r\n1: ysfarmsvr.com\r\n2: xxx.xxx.jp\r\n\u8a2d\u5b9a\u3057\u3066\u3044\u308b\u30d0\u30fc\u30c1\u30e3\u30eb\u30db\u30b9\u30c8\u306e\u6570\u3060\u3051\u51fa\u3066\u304d\u307e\u3059\u306e\u3067\u8a2d\u5b9a\u3057\u305f\u3044\u30db\u30b9\u30c8\u306e\u756a\u53f7\u3092\u6307\u5b9a\u3057\u307e\u3059\r\n- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -\r\n\r\nDeploying certificate\r\nSuccessfully deployed certificate for ysfarmsvr.com\u30fb\u30fb\u30fb\u30fb\r\n\r\n\u4e0a\u8a18\u306e\u3088\u3046\u306bsuccess\u306b\u306a\u308c\u3070\u8a2d\u5b9a\u5b8c\u4e86\u3067\u3059\r\n<\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u300cLet&#8217;s Encrypt\u300d\u304b\u3089\u7121\u6599\u306eSSL\/TLS\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3057\u307e\u3059\u3002 \u5916\u90e8\u304b\u3089\u30a2\u30af\u30bb\u30b9\u3055\u308c\u308b\u306e\u3067DDNS\u306a\u3069\u3067\u5916\u90e8\u304b\u3089\u30c9\u30e1\u30a4\u30f3\u306b\u30a2\u30af\u30bb\u30b9\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u3066\u3044\u308b\u3053\u3068\u304c\u524d\u63d0\u306b\u306a\u308a\u307e\u3059\u3002 DDNS\u306b\u3064\u3044\u3066\u306f\u307e [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1508,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"vkexunit_cta_each_option":"","footnotes":""},"categories":[405,404,399],"tags":[],"class_list":["post-1686","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-centos","category-linux","category-399"],"_links":{"self":[{"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/posts\/1686","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/comments?post=1686"}],"version-history":[{"count":12,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/posts\/1686\/revisions"}],"predecessor-version":[{"id":1732,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/posts\/1686\/revisions\/1732"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/media\/1508"}],"wp:attachment":[{"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/media?parent=1686"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/categories?post=1686"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ysfarm.jp\/blog\/wp-json\/wp\/v2\/tags?post=1686"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}