Let’s Encrypt セットアップしてみた


sudo yum install epel-release
sudo yum install certbot python2-certbot-apache

実際、webmin プログラムインストールで
epel-release
certbot
python2-certbot-apache
をそれぞれインストール

シェルで
以下を実行
# certbot –apache
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator apache, Installer apache
Enter email address (used for urgent renewal and security notices) (Enter ‘c’ to
cancel): xxxxxxxxxxx@yahoo.co.jp
Starting new HTTPS connection (1): acme-v02.api.letsencrypt.org

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Please read the Terms of Service at
https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must
agree in order to register with the ACME server at
https://acme-v02.api.letsencrypt.org/directory
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
(A)gree/(C)ancel: A

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Would you be willing to share your email address with the Electronic Frontier
Foundation, a founding partner of the Let’s Encrypt project and the non-profit
organization that develops Certbot? We’d like to send you email about our work
encrypting the web, EFF news, campaigns, and ways to support digital freedom.
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
(Y)es/(N)o: Y
Starting new HTTPS connection (1): supporters.eff.org

Which names would you like to activate HTTPS for?
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
1: bytech.ecopls.link
2: esuppo.ecopls.link
4: golf.ecopls.link
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter ‘c’ to cancel):そのままEnter

Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter ‘c’ to cancel):
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for bytech.ecopls.link
http-01 challenge for esuppo.ecopls.link
http-01 challenge for golf.ecopls.link
Waiting for verification…
Cleaning up challenges
Created an SSL vhost at
……

Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
1: No redirect – Make no further changes to the webserver configuration.
2: Redirect – Make all requests redirect to secure HTTPS access. Choose this for
new sites, or if you’re confident your site works on HTTPS. You can undo this
change by editing your web server’s configuration.
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Select the appropriate number [1-2] then [enter] (press ‘c’ to cancel): 1

– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
Congratulations! You have successfully enabled https://bytech.ecopls.link,
https://esuppo.ecopls.link,
https://golf.ecopls.link

You should test your configuration at:
https://www.ssllabs.com/ssltest/analyze.html?d=bytech.ecopls.link
https://www.ssllabs.com/ssltest/analyze.html?d=esuppo.ecopls.link
https://www.ssllabs.com/ssltest/analyze.html?d=golf.ecopls.link
– – – –

IMPORTANT NOTES:
– Congratulations! Your certificate and chain have been saved at:
/etc/letsencrypt/live********
Your key file has been saved at:
/etc/letsencrypt/**************
Your cert will expire on 2018-11-22. To obtain a new or tweaked
version of this certificate in the future, simply run certbot again
with the “certonly” option. To non-interactively renew *all* of
your certificates, run “certbot renew”
– Your account credentials have been saved in your Certbot
configuration directory at /etc/letsencrypt. You should make a
secure backup of this folder now. This configuration directory will
also contain certificates and private keys obtained by Certbot so
making regular backups of this folder is ideal.
– If you like Certbot, please consider supporting our work by:

Donating to ISRG / Let’s Encrypt: https://letsencrypt.org/donate
Donating to EFF: https://eff.org/donate-le

以上

https://certbot.eff.org/lets-encrypt/centosrhel7-apache
ここを参考にやったけど
最初から ちょいちょいやってたら サーバーレベルの証明書になってしまった。
ドメインレベルにするべきか(--)

またあとでやりましょう。

https://esuppo.ecopls.link/wp/

コメントを残す

メールアドレスが公開されることはありません。 * が付いている欄は必須項目です