Certbot: Ubuntu letsencrypt ํŒจํ‚ค์ง€์šฉ ๊ณต์‹ PPA ๋งŒ๋“ค๊ธฐ

์— ๋งŒ๋“  2015๋…„ 12์›” 04์ผ  ยท  144์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: certbot/certbot

letsencrypt ํŒจํ‚ค์ง€์— ๋Œ€ํ•œ ๊ณต์‹ Ubuntu PPA ๊ฐ€ ์žˆ๋‹ค๋ฉด ๊ต‰์žฅํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

debian / ubuntu pkging soccer ball

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

JFTR ppa:certbot/certbot ์—๋Š” ์ด์ œ ์•ฝ๊ฐ„์˜ ์ฃผ์˜๋ฅผ ๊ธฐ์šธ์—ฌ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ค์ง€๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ๋‹น๋ถ„๊ฐ„ ์—ฌ๊ธฐ์—์„œ ํŒŒ์†์„ ์‹ ๊ณ ํ•ด ์ฃผ์‹ญ์‹œ์˜ค.

๋ชจ๋“  144 ๋Œ“๊ธ€

:+1:

:+1:

:์—„์ง€์†๊ฐ€๋ฝ:

:+1:

์˜ˆ์˜๋‹ค ์ œ๋ฐœ?

์˜ˆ, ๋ถ€ํƒํ•ฉ๋‹ˆ๋‹ค!

์˜ˆ, ๋ถ€ํƒํ•ฉ๋‹ˆ๋‹ค.

+1

+1

+1

letsencrypt-auto ์— ๋งŽ์€ ๋…ธ๋ ฅ์„ ๊ธฐ์šธ์˜€์œผ๋ฉฐ ์—ฌ๊ธฐ์—๋Š” ์—†์Šต๋‹ˆ๋‹ค. ๋ฌด์Šจ ์ผ์ด์•ผ? letsencrypt-auto ๋Š” ์šฐ๋ฆฌ๊ฐ€ ํŒจํ‚ค์ง€๋ฅผ ๋ฐ›์„ ๋•Œ๊นŒ์ง€ ์ž„์‹œ ํ•ด๊ฒฐ์ฑ…์ด์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด ์ƒํ™ฉ์ด ์ ˆ๋Œ€์ ์œผ๋กœ ์–ด์ƒ‰ํ•˜๋‹ค๋Š” ๊ฒƒ์„ ์•Œ์•˜์Šต๋‹ˆ๋‹ค. @hlieberman ๊ณผ @fmarier ๋Š” debs์— ๋งŽ์€ ์‹œ๊ฐ„์„ ํˆฌ์žํ–ˆ์œผ๋ฉฐ ์ด์ œ ๊ธฐ๋ณธ์ ์œผ๋กœ ๋ชจ๋“  ํŒจํ‚ค์ง• ์†”๋ฃจ์…˜์„ ๋Œ€์ฒดํ•˜๋ ค๊ณ  ์‹œ๋„ํ•˜๋Š” ์ง‘์—์„œ ๋งŒ๋“  "์ž๋™ ๋งˆ๋ฒ•" ์Šคํฌ๋ฆฝํŠธ์— ์‹œ๊ฐ„์„ ๋‚ญ๋น„ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ). ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์–ผ๋งˆ๋‚˜ ํ„ฐ๋ฌด๋‹ˆ์—†์ด ๋ณต์žกํ•˜๋‹ค๋Š” ๋ถˆํ‰์ด ๋งŽ์•˜๊ณ , ๋ฌดํ•œํžˆ ํ™•์žฅ๋˜๊ธฐ๋ณด๋‹ค๋Š” ์ถ•์†Œ๋˜์–ด์•ผ ํ•˜๋Š” ๊ฒƒ์ด ๋‹น์—ฐํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ์Šต๋‹ˆ๋‹ค.

@pde - ์œ„์—์„œ ๋ช…ํ™•ํžˆ ํ•˜๊ณ  PPA์— ETA๋ฅผ ์ œ๊ณตํ•˜์‹ญ์‹œ์˜ค.

์ตœ์‹  ๋ฒ„์ „์˜ Ubuntu์˜ ๊ฒฝ์šฐ Debian ๋ถˆ์•ˆ์ •ํ•œ ํŒจํ‚ค์ง€๊ฐ€ ์ œ๋Œ€๋กœ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค. ํŒจํ‚ค์ง€๋ฅผ Debian jessie๋กœ ๋ฐฑํฌํŠธํ•˜๋ฉด Ubuntu 14.04์—์„œ ๋” ์‰ฝ๊ฒŒ ์ž‘๋™ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

๋ฌผ๋ก  ์ด๊ฒƒ์€ ๋งŽ์€ ์ข…์† ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋„ ํŒจํ‚ค์ง•ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

ํŒจํ‚ค์ง€๋˜์ง€ ์•Š์€ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ์„ค์น˜ํ•˜๋Š” ๋ณด๋‹ค ์ „ํ†ต์ /ํ‘œ์ค€ํ™”๋œ ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•˜๋Š” PPA์˜ ๊ฒฝ์šฐ +1์ž…๋‹ˆ๋‹ค.

์ง€๋‚œ์ฃผ Harlan์—์„œ ๋ฐ›์€ ์—…๋ฐ์ดํŠธ๋Š” ๋‹ค์–‘ํ•œ ๋ฐ๋น„์•ˆ ์œ ์ง€ ๊ด€๋ฆฌ์ž๊ฐ€ ๋ชจ๋“  ํŒŒ์ด์ฌ ์ข…์†์„ฑ์„ ๋ฐฑํฌํŒ…ํ•˜๋Š” ์ผ์„ ํ›Œ๋ฅญํ•˜๊ฒŒ ์ˆ˜ํ–‰ํ–ˆ์ง€๋งŒ ๋›ฐ์–ด๋‚œ ์ฐจ๋‹จ๊ธฐ๋Š” doc ํŒจํ‚ค์ง€์— ๋Œ€ํ•ด sphinx-doc ์ด์—ˆ๊ณ  ์‚ฌ์†Œํ•˜์ง€ ์•Š์€ ์‚ฌ์—…. PPA๊ฐ€ ํฌ๊ฒŒ ๋‹ค๋ฅด๊ฑฐ๋‚˜ ์‰ฌ์šด์ง€ ํ™•์‹คํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

PPA ํŒจํ‚ค์ง€์— ๋Œ€ํ•ด Sphinx ๋ฌธ์„œ ์ž‘์„ฑ์„ ์ผ์‹œ์ ์œผ๋กœ ๋น„ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๊นŒ? ์‚ฌ์šฉ์ž๋กœ์„œ ๋‚˜๋Š” ๋ฌธ์„œ๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์˜จ๋ผ์ธ์— ์ ‘์†ํ•ด์•ผ ํ•˜๋Š” ๋ฐ ์ „ํ˜€ ๋ฌธ์ œ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค(์‚ฌ์‹ค ์ €๋Š” /usr/share/doc/์—์„œ ๋กœ์ปฌ HTML ํŒŒ์ผ์„ ์ฝ๋Š” ๊ฒƒ๋ณด๋‹ค ์„ ํ˜ธํ•ฉ๋‹ˆ๋‹ค).

๋ฌธ์„œ์˜ sphinx-doc ๊ฑด๋ฌผ์ผ ๊ฒฝ์šฐ ์–ด๋””์— ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?

  • letsencrypt ๋ฐ letsencrypt-doc 2๊ฐœ ํŒจํ‚ค์ง€ ์ œ๊ณต
  • letsencrypt.1 ์— letsencrypt_x.y.deb
  • ๋ฌธ์„œ๋ฅผ HTML๋กœ ๋ฏธ๋ฆฌ ๋นŒ๋“œ
    letsencrypt-doc_x.y.deb ๋กœ ํŒจํ‚ค์ง€

์ด์œ :
์ž๋™์œผ๋กœ ๋ฌธ์„œ๋ฅผ ๋นŒ๋“œํ•˜๋Š” ๊ฒƒ์€ ์ข‹์ง€๋งŒ ์„ ํƒ ์‚ฌํ•ญ์ž…๋‹ˆ๋‹ค.
๋ฌธ์„œ๋ฅผ ๋นŒ๋“œํ•˜๊ธฐ ์œ„ํ•ด sphinx-doc ๋ฅผ ์ œ๊ฑฐํ•ด๋„ letsencrypt ๋ฐฉ์ง€๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
๋ชจ๋‘๊ฐ€ ์›ํ•˜๋Š” ๋นŒ๋“œ, ์„ค์น˜ ๋ฐ ์ž‘๋™

์‘์šฉ ํ”„๋กœ๊ทธ๋žจ๊ณผ ๋ฌธ์„œ์— ๋Œ€ํ•œ debs๋ฅผ ๋ถ„๋ฆฌํ•˜๋ ค๋Š” @zwetan ์˜ ์ œ์•ˆ์€ ๊น€ํ”„์—์„œ LibreOffice์— ์ด๋ฅด๊ธฐ๊นŒ์ง€ ๋‹ค๋ฅธ ๋งŽ์€ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ ์ด๋ฏธ ์ž˜ ์ž…์ฆ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ณด์•ˆ ์—…๊ทธ๋ ˆ์ด๋“œ๊ฐ€ ์žˆ์„ ๋•Œ๋งˆ๋‹ค ๋ฌธ์„œ๋ฅผ ๋‹ค์‹œ ๋นŒ๋“œํ•  ํ•„์š”๊ฐ€ ์—†๋Š” ๊ฐœ๋ฐœ์ž์—๊ฒŒ ๋„์›€์ด ๋˜๋ฉฐ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ์‚ฌ์šฉ๋˜์ง€ ์•Š๋Š” ๋™์•ˆ ๋ฌธ์„œ๋ฅผ ์ž์œ ๋กญ๊ฒŒ ์—…๋ฐ์ดํŠธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•„์ด๋””์–ด๋ฅผ ์นญ์ฐฌํ•ฉ๋‹ˆ๋‹ค.

xenial ์— ์ด๋ฏธ letsencrypt๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค(16.04 ์˜ˆ์ •): http://packages.ubuntu.com/xenial/letsencrypt

๋ฌธ์„œ๋Š” ์„ ํƒ์  deps์ธ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.

์ •ํ™•ํžˆ ๋งํ•˜์ž๋ฉด prod์˜ ์ผ๋ถ€ ์„œ๋ฒ„๋Š” LTS -> ๋ณด์•ˆ ํŒจ์น˜ -> ๋‹ค์Œ LTS๋กœ๋งŒ ๋กค๋ง๋ฉ๋‹ˆ๋‹ค.
14.04 LTS์— ์ด๋ฏธ deb ํŒจํ‚ค์ง€๊ฐ€ ์žˆ์„ ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ 16.04 LTS๋ฅผ ๊ธฐ๋‹ค๋ ค์•ผ ํ•จ
๋ฌธ์„œ ๋นŒ๋“œ๊ฐ€ ๋ฌธ์ œ๊ฐ€ ์žˆ๊ธฐ ๋•Œ๋ฌธ์—? ์ปด์˜จ :)

๊ฐ€์žฅ ์ตœ๊ทผ ์—…๋ฐ์ดํŠธ๋Š” sphinx ๋ฐฑํฌํŠธ์— Debian 8์šฉ ํฌ์žฅ์ด ํ•ด์ œ๋˜์—ˆ์œผ๋ฉฐ ๊ณง PPA๊ฐ€ ์ œ๊ณต๋  ์˜ˆ์ •์ž…๋‹ˆ๋‹ค.

@zwetan :+1: 14.04๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๊ณ  14.04์— ๋Œ€ํ•œ ๊ณต์‹ ์ €์žฅ์†Œ๊ฐ€ ์—†๊ธฐ ๋•Œ๋ฌธ์— letsencrypt๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

:+1:

:+1:

+1 ๋‚ด ์ธ์ƒ์—์„œ ๋‹ค์‹œ๋Š” letsencrypt-auto๋ฅผ ์‹คํ–‰ํ•˜์ง€ ์•Š์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค....

Ubuntu Wily์šฉ PPA๋ฅผ ๋งŒ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. ์ž์‹ ์˜ ์ฑ…์ž„ํ•˜์— ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค. ํ˜„์žฌ๋กœ์„œ๋Š” ๋Œ€๋ถ€๋ถ„ ํ…Œ์ŠคํŠธ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.

https://launchpad.net/~letsencrypt/+archive/ubuntu/letsencrypt

@hlieberman ์€ ํ•ด๋‹น ํŒจํ‚ค์ง€๋ฅผ 14.0.4 ๋ณ„์นญ TrustyThar์—์„œ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์•„๋‹ˆ๋ฉด ๊ฑฐ๋ถ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

๋‹จ์ง€ ์ฃผ์˜, PPA๋Š” /etc ๋ฐ /opt์˜ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์ƒ์„ฑํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ด์ œ letsencrypt-auto๊ฐ€ ์ข…์†์„ฑ ๋ฌธ์ œ(urllib3, acme)๋กœ ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค. ํ•ด๊ฒฐ๋˜๋Š” ๋ฌธ์ œ๋ฅผ ๊ฐ์•ˆํ•  ๋•Œ ์ด๋Š” ๊ฐ„๋‹จํ•œ ๊ฐ„๋‹จํ•œ ํ”„๋กœ์„ธ์Šค์—ฌ์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์˜์กด์„ฑ et-al๊ณผ ์”จ๋ฆ„ํ•˜๋Š” ๋ฐ ๋ช‡ ์‹œ๊ฐ„์„ ๋ณด๋‚ด๊ณ  ์‹ถ์ง€ ์•Š์•„ ๋ถ€์„œ์ง€๊ธฐ ์‰ฝ์Šต๋‹ˆ๋‹ค.

(์ถ”์‹ : PPA๋Š” 14.04์—์„œ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค)

Ubuntu 14.04.5 LTS์— ๋Œ€ํ•œ ์ตœ์‹  ํ…Œ์ŠคํŠธ์—์„œ
PPA๋ฅผ ๋ฌด์‹œํ•˜๋Š” ๊ฒƒ์ด ๋” ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค.

"์ˆ˜๋™" ์„ค์น˜๋ฅผ ์ˆ˜ํ–‰ํ•˜์‹ญ์‹œ์˜ค.

git clone https://github.com/letsencrypt/letsencrypt /opt/letsencrypt
/opt/letsencrypt/letsencrypt-auto --help

(๋‘ ๋ฒˆ์งธ ์ค„์€ ์ข…์†์„ฑ์„ ๊ฐ•์ œ๋กœ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค)
์ด๊ฒƒ์€ 12๊ฐœ์˜ ์„œ๋ฒ„์—์„œ ์ž˜ ์ž‘๋™ํ–ˆ์Šต๋‹ˆ๋‹ค.

ํ•œ ๊ฐ€์ง€ ์ถ”๊ฐ€ ์ œ์•ˆ: ์ƒ๋Œ€์ ์œผ๋กœ ๋งŽ์€ ์ˆ˜์˜ ์ข…์†์„ฑ์ด ๋ถˆํŽธํ•˜๋‹ค๋ฉด ์ž‘์€ lxc ์ธ์Šคํ„ด์Šค(ํ˜„์žฌ ์•ฝ 350MB ํฌ๊ธฐ)๋ฅผ ๋งŒ๋“ค๊ณ  ์•ž์„œ ์–ธ๊ธ‰ํ•œ ์ˆ˜๋™ ์„ค์น˜๋ฅผ ๋”ฐ๋ฅด์„ธ์š”.
lxc-create -n letsencrypt -t ubuntu

ํ˜ธ์ŠคํŠธ์—์„œ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์ž๋™ํ™”๋œ ํ…Œ์ŠคํŠธ๋ฅผ ํ—ˆ์šฉํ•˜๋ ค๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๊ตฌ์„ฑ์— ๋‘ ๊ฐœ์˜ ๋ฐ”์ธ๋“œ ๋งˆ์šดํŠธ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ธฐ๋งŒ ํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค. ์ด๊ฒƒ์— ์ฃผ์˜):
lxc.mount.entry = /var/www/letsencrypt var/www/letsencrypt none bind 0 0
lxc.mount.entry = /etc/letsencrypt etc/letsencrypt none bind 0 0

(๋ฌผ๋ก  _letsencrypt_ ์ปจํ…Œ์ด๋„ˆ ์™ธ๋ถ€์—์„œ ๋™๊ธฐํ™”๋œ ๊ฐฑ์‹ /์›น ์„œ๋ฒ„ ์„œ๋น„์Šค ์žฌ์‹œ์ž‘์„ ํŠธ๋ฆฌ๊ฑฐํ•ด์•ผ ํ•˜์ง€๋งŒ ๊ฝค ํŽธ๋ฆฌํ•ฉ๋‹ˆ๋‹ค...)

๊ฐœ์ธ์ ์œผ๋กœ ๋‚˜๋Š” ์˜์กด์„ฑ์— ์‹ ๊ฒฝ ์“ฐ์ง€ ์•Š๋Š”๋‹ค

๋‚˜์—๊ฒŒ ์ •๋ง ํ•„์š”ํ•œ ๊ฒƒ์€ ํ”„๋กœ๋น„์ €๋‹ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ž๋™ํ™”ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
์„œ๋ฒ„์— Let's Encrypt ์ง€์›์„ ์ถ”๊ฐ€ํ•˜๊ณ  ์‹ถ์€์ง€ ์•Œ์•„๋ณด๊ธฐ
์ž‘๋™ํ•˜๊ณ  ํ…Œ์ŠคํŠธ๋˜์—ˆ์œผ๋ฉฐ ์„ค์ •ํ•˜๋Š” ๋ฐ ์•ฝ 10mn์ด ๊ฑธ๋ฆฝ๋‹ˆ๋‹ค.

๋ฆฌ์†Œ์Šค๊ฐ€ ์ œํ•œ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ ๋งŽ์€ ์ˆ˜์˜ ์ข…์†์„ฑ์ด ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.

์ปจํ…Œ์ด๋„ˆ์— ๊ด€์‹ฌ์ด ์žˆ๋‹ค๋ฉด ๋งค์šฐ ๋น ๋ฅด๊ฒŒ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  Docker ์ปจํ…Œ์ด๋„ˆ๋ฅผ ํ•จ๊ป˜ ๋˜์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Docker ํ—ˆ๋ธŒ์—์„œ ์ด์— ๋Œ€ํ•œ ๋ช‡ ๊ฐ€์ง€ ์ž‘์—…์ด ์žˆ๋Š” ๊ฒƒ ๊ฐ™์ง€๋งŒ ๋ฒ„๋ ค์ง„/์˜ค๋ž˜๋œ ๊ฒƒ์œผ๋กœ ๋ณด์ž…๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ ์ธ์ฆ์„œ๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๊ฒƒ์ด docker run -v/etc/letsencrypt:/etc/letsencrypt -p80:80 -p443:443 letsencrypt <FQDN> ๋งŒํผ ๊ฐ„๋‹จํ•˜๋‹ค๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค.

ํŽธ์ง‘: ์—ฌ๊ธฐ ๋‹น์‹ ์ด ์žˆ์Šต๋‹ˆ๋‹ค. https://hub.docker.com/r/samyaple/certbot/
๊ธฐ๋ณธ ์ด๋ฏธ์ง€๋ฅผ ํฌํ•จํ•˜์—ฌ ์•ฝ 250MB๋ฅผ ๋Œ์–ด๋‚ผ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‚˜๋Š” ์ง€๊ธˆ ๊ทธ ๋ฐœ์ž๊ตญ์„ ์ค„์ด๊ธฐ ์œ„ํ•ด ๋…ธ๋ ฅํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ๋ช‡ ๋ถ„ ๋งŒ์— ๋Œ€๋žต์ ์ธ ๊ตฌํ˜„์ด์—ˆ์Šต๋‹ˆ๋‹ค. ๋นŒ๋“œ๊ฐ€ ์ž๋™ํ™”๋˜์–ด ์–ด๋–ค ์žฌ๋ฏธ์žˆ๋Š” ๋น„์ฆˆ๋‹ˆ์Šค๊ฐ€ ์—†๋Š”์ง€ ์ •ํ™•ํžˆ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์›ํ•˜๋Š” ๊ฒฝ์šฐ letsencrypt ๋ฐฐ๋„ˆ์—์„œ ์ด๋ฅผ ์ง€์›ํ•˜๊ฒŒ ๋˜์–ด ๊ธฐ์ฉ๋‹ˆ๋‹ค.

:+1:

๊ด€์‹ฌ ์žˆ๋Š” ๋ถ„๋“ค์„ ์œ„ํ•ด Ubuntu ์‚ฌ์ดํŠธ์— ๋Œ€ํ•œ ์ธ์ฆ์„œ ์„ค์น˜๋ฅผ ์ž๋™ํ™”ํ•˜๊ธฐ ์œ„ํ•ด ์•ฝ๊ฐ„์˜ Ansible ์—ญํ• ์„ ์—ฐ๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค. ํ˜„์žฌ๋กœ์„œ๋Š” ๋งค์šฐ ์ œํ•œ์ ์ž…๋‹ˆ๋‹ค. ์ œ๊ฐ€ ํ•„์š”ํ•œ ๊ธฐ๋Šฅ์— ๋Œ€ํ•ด์„œ๋งŒ ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ๊ทธ๊ฒƒ์„ ์‚ฌ์šฉํ•˜๊ณ  ์‹ถ๋‹ค๋ฉด PR์„ ํ™˜์˜ํ•ฉ๋‹ˆ๋‹ค.

์—ญํ• ์€ git์˜ ๊ณต์‹ ํด๋ผ์ด์–ธํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  certonly ๋ชจ๋“œ์—์„œ ์ธ์ฆ์„œ ์„ค์น˜/๊ฐฑ์‹ ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

https://galaxy.ansible.com/jaywink/letsencrypt/

repo ์ด๋™ ํ›„ harlan์„ ๋‹ค์‹œ ํ• ๋‹นํ•˜์—ฌ ์ œ๊ฑฐํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ์—ฌ์ „ํžˆ โ€‹โ€‹์ค‘์š”ํ•˜์ง€๋งŒ ์ด์ œ ์šฐ๋ฆฌ๊ฐ€ ์ด๋ฏธ ํŒจํ‚ค์ง€ ๋œ ์œ„์น˜์—์„œ letsencrypt -> certbot์˜ ์ด๋ฆ„์„ ๋ฐ”๊พธ๋Š” ๊ฒƒ๋ณด๋‹ค ์šฐ์„  ์ˆœ์œ„๊ฐ€ ๋‚ฎ์Šต๋‹ˆ๋‹ค.

๐Ÿ‘

+1

+1

+1

+1

PPA๋ฅผ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. ๋’ค์ณ์ ธ ์žˆ์Šต๋‹ˆ๋‹ค - ์—ฌ์ „ํžˆ 0.4.1์ธ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค: https://launchpad.net/ubuntu/xenial/+package/letsencrypt

@larssn ๊ทธ๊ฒƒ์€ PPA๊ฐ€ ์•„๋‹™๋‹ˆ๋‹ค. ์ด๋Š” Ubuntu ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์˜ ํŒจํ‚ค์ง€์ž…๋‹ˆ๋‹ค. ๋‘ ๊ฐ€์ง€ ๊ณ ๋ ค ์‚ฌํ•ญ: ์ฒซ์งธ, ํŒจํ‚ค์ง€ ์—…๋ฐ์ดํŠธ๋ฅผ Ubuntu ๋ฆด๋ฆฌ์Šค๋กœ ๊ฐ€์ ธ์˜ค๊ธฐ ์œ„ํ•ด ๊ฑฐ์ณ์•ผ ํ•˜๋Š” SRU ํ”„๋กœ์„ธ์Šค[1]๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‘˜์งธ, ํŒจํ‚ค์ง€๊ฐ€ '์šฐ์ฃผ'์— ์žˆ์œผ๋ฏ€๋กœ Ubuntu/Canonical์—์„œ ๊ณต์‹์ ์œผ๋กœ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

[1] https://wiki.ubuntu.com/StableReleaseUpdates

(ํŽธ์ง‘: URL ์ถ”๊ฐ€)

์•Œ์•˜์–ด์š”.

์–ด๋–ค ๊ฒฝ์šฐ์—๋„; ์—ฌ์ „ํžˆ ์—…๋ฐ์ดํŠธ๋ฅผ ์›ํ•ฉ๋‹ˆ๋‹ค. :)

์—ฌ๋Ÿฌ๋ถ„, ์ด๊ฒƒ์€ "๊ณต์‹" ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋Š” ์•„๋‹ˆ์ง€๋งŒ ์ง‘์— ๋ฐ๋น„์•ˆ ๊ฐœ๋ฐœ์ž์ด์ž ์šฐ๋ถ„ํˆฌ ํšŒ์›์œผ๋กœ์„œ ์–ด๋Š ์ •๋„ ์‹ ๋ขฐ๋ฅผ ์–ป์—ˆ์Šต๋‹ˆ๋‹ค(๋‚ด PHP PPA๋Š” ์ˆ˜์ฒœ ๋ช…์ด ์‚ฌ์šฉํ•จ). ๊ทธ๋ž˜์„œ certbot 0.8.x์šฉ PPA๋ฅผ ๋งŒ๋“ค์—ˆ์Šต๋‹ˆ๋‹ค. ํ˜„์žฌ๋กœ์„œ๋Š” Xenial์—์„œ ๋นŒ๋“œ๋˜์—ˆ์ง€๋งŒ ์‹œ๊ฐ„์ด ๋˜๋ฉด ๋” ๋งŽ์€ ์Šคํƒ์„ Trusty๋กœ ๋ฐฑํฌํŒ…ํ•˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

PPA๋Š” ์—ฌ๊ธฐ: https://launchpad.net/~ondrej/+archive/ubuntu/letsencrypt

๋ฐฉ๊ธˆ ubuntu 16.04์—์„œ ํ…Œ์ŠคํŠธํ–ˆ์œผ๋ฉฐ ์ด๋ฏธ php, apache ๋ฐ mysql์— ๋Œ€ํ•œ ๋‚ด์šฉ์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

@oerdnj ๋‹น์‹ ์€ ๋˜ ํ•œ ๋ฒˆ ๋‚ด ํ•˜๋ฃจ๋ฅผ ๊ตฌํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‹น์‹ ์˜ ๋…ธ๊ณ ์— ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค!

@oerdnj ๋‹น์‹ ์˜ PPA๊ฐ€ ์šฐ๋ฆฌ์˜ ๋ช…๋ น์–ด ์ƒ์„ฑ๊ธฐ ์—์„œ ๊ทธ๊ฒƒ์„ ๊ฐ€๋ฆฌํ‚ค๋Š” ๊ฒƒ์„ ๊ณ ๋ คํ•ด์•ผ ํ•  ๋งŒํผ ์ถฉ๋ถ„ํžˆ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๊นŒ?

wrt Trusty: harlan์€ Trusty๊ฐ€ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” PPA๋ฅผ ์‹คํ–‰ํ•˜๊ธฐ ์œ„ํ•ด ๊ตฌ์ถ•ํ•ด์•ผ ํ•˜๋Š” ์ข…์†์„ฑ ์ง‘ํ•ฉ์„ ์•ฝ๊ฐ„ ๋‘๋ ค์›Œํ•˜๊ฒŒ ๋˜์—ˆ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ @jonathonf ๋Š” ๊ทธ ๋ฉด์—์„œ ์–ด๋Š ์ •๋„ ์ง„์ „์„ ๊ฐ™์œผ ๋ฏ€๋กœ ๋‹ค๋ฃจ๊ธฐ ์‰ฌ์šด ๋ฌธ์ œ์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

@pde ์•ˆ์ •์ ์ž…๋‹ˆ๋‹ค. ๋‚˜๋Š” ๋•Œ๋•Œ๋กœ ๋ฐ”๋น ์„œ ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ์ €์—๊ฒŒ ํ•‘์„ ๋ณด๋‚ด๊ฑฐ๋‚˜ ์—ฌ๊ธฐ ๋‚ด gh ์ถ”์ ๊ธฐ์—์„œ ๋ฌธ์ œ๋ฅผ ์ฑ„์šธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: https://github.com/oerdnj/deb.sury.org/issues

๊ทธ๋Ÿฌ๋‚˜ ๋‚˜๋Š” ์ค‘์š”ํ•œ ๊ฒƒ์€ ๋ช‡ ์‹œ๊ฐ„ ์•ˆ์— ๋ฆด๋ฆฌ์Šคํ•˜๊ณ  ์ˆ˜์ •ํ•˜๋Š” ๊ฒฝํ–ฅ์ด ์žˆ๊ณ  ๋œ ์ค‘์š”ํ•œ ๊ฒƒ์€ ๋ช‡ ์ฃผ ์•ˆ์— ๋ฆด๋ฆฌ์Šคํ•˜๊ณ  ์ˆ˜์ •ํ•˜๋Š” ๊ฒฝํ–ฅ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

๋‚˜๋Š” 10์›”์— ์—ด๋ฆฌ๋Š” ๋ช‡๋ช‡ ํšŒ์˜์— ์ฐธ์„ํ•  ์˜ˆ์ •์ด๋ฉฐ ๋ณดํ†ต์€ ์œ ํœด ์‹œ๊ฐ„์„ ํฌ์žฅ์œผ๋กœ ์ฑ„์šฐ๋ฏ€๋กœ Trusty ํฌ์žฅ์„ ๋งˆ์น  ์ˆ˜ ์žˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋ฌผ๋ก , ๊ทธ ๋ถ€๋ถ„์— ๋Œ€ํ•ด ์ด๋ฏธ ๊ธฐ์กด ์ž‘์—…์ด ์žˆ๋‹ค๋ฉด ๊ธฐ๊บผ์ด ํžŒํŠธ/ํŒจ์น˜/๋„์›€์„ ๋ฐ›๊ฒ ์Šต๋‹ˆ๋‹ค.

๋Œ€์•ˆ์œผ๋กœ ๋Ÿฐ์น˜ํŒจ๋“œ์—์„œ "๊ณต์‹" ํŒจํ‚ค์ง• ๊ทธ๋ฃน์„ ๋งŒ๋“ค๊ณ  ๋” ๋งŽ์€ ์‚ฌ๋žŒ๋“ค์„ ์ดˆ๋Œ€ํ•˜๊ณ  LE์˜ ๋ˆ„๊ตฐ๊ฐ€๋ฅผ ๊ด€๋ฆฌ์ž๋กœ ์ถ”๊ฐ€ํ•˜๊ฒŒ ๋˜์–ด ๊ธฐ์ฉ๋‹ˆ๋‹ค.

๋ฐ๋น„์•ˆ ํŒจํ‚ค์ง• ํŒ€์€ ํ›Œ๋ฅญํ•œ ์ผ์„ ํ•ด๋ƒˆ๊ธฐ ๋•Œ๋ฌธ์— Xenial์˜ ๊ฒฝ์šฐ ๋Œ€๋ถ€๋ถ„ ๊ธฐ์กด ํŒจํ‚ค์ง€๋ฅผ ๋ฐฑํฌํŒ…/์žฌํŒจํ‚ค์ง•ํ•˜๋Š” ๊ฒƒ์ด์—ˆ์Šต๋‹ˆ๋‹ค. Trusty์˜ ๊ฒฝ์šฐ ์ข€ ๋” ์ˆ˜์ •์ด ํ•„์š”ํ•  ์ˆ˜ ์žˆ์ง€๋งŒ ์•„์ง ์‚ดํŽด๋ณด์ง€๋Š” ์•Š์•˜์Šต๋‹ˆ๋‹ค.

๊ธฐ๋ก์„ ์œ„ํ•ด ์ €๋Š” @jonathonf ์˜ PPA๋ฅผ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ํ™˜๊ฒฝ์—์„œ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์œผ๋ฉฐ ๋ชจ๋“  ๊ฒƒ์ด ์ž˜ ์ž‘๋™ํ•˜๋ฉฐ ๋ช‡ ๊ฐ€์ง€ ์—…๋ฐ์ดํŠธ๋œ python-* ํŒจํ‚ค์ง€๋งŒ ํ•„์š”ํ–ˆ์Šต๋‹ˆ๋‹ค.

@pde https://launchpad.net/~letsencrypt๊ฐ€ ์žˆ๊ณ  ๋ฒ„๋ ค์ง„ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์–ด์ฉŒ๋ฉด LE๋Š” Canonical์— LE ๊ด€๋ฆฌ์ž์˜ ๋ˆ„๊ตฐ๊ฐ€์—๊ฒŒ ์ด ๋Ÿฐ์น˜ํŒจ๋“œ ํŒ€์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•œ ๋‹ค์Œ ๋‚˜์™€ @jonathonf ๋ฅผ ์ถ”๊ฐ€

@oerdnj letsencrypt ์•„๋ž˜์˜ certbot ์ €์žฅ์†Œ๊ฐ€ ์ข‹์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ฐœ์ธ์ ์œผ๋กœ ์ €๋Š” ํ•ญ์ƒ letsencrypt ํŒจํ‚ค์ง€๋ฅผ ์ฐพ๊ณ  ์žˆ์œผ๋ฉฐ letsencrypt๋ฅผ ๊ฒ€์ƒ‰ํ•˜์—ฌ ti๋ฅผ ์ฐพ์„ ์ˆ˜ ์—†์œผ๋ฉด ํ˜ผ๋ž€์Šค๋Ÿฌ์šธ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

~letsencrypt ์กฐ์ง์˜ @oerdnj ์†Œ์œ ๊ถŒ์„ ๋ถ€์—ฌ

Letsencrypt์˜ ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ์กฐ์ง์— ์ถ”๊ฐ€๋˜๊ณ  ์†Œ์œ ์ž๊ฐ€ ๋˜๊ธฐ๋ฅผ ์›ํ•˜๋ฉด ์ €์—๊ฒŒ ping์„ ๋ณด๋‚ด์ฃผ์‹ญ์‹œ์˜ค.

์ด์ œ certbot ํŒจํ‚ค์ง€๋ฅผ ppa:letsencrypt/letsencrypt ๋ณต์‚ฌํ–ˆ์Šต๋‹ˆ๋‹ค. Ubuntu Trusty๋ฅผ ์œ„ํ•ด ๋ฐฑํฌํŠธํ•ด์•ผ ํ•˜๋Š” ํŒจํ‚ค์ง€๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด @jonathonf trusty ์ €์žฅ์†Œ๋ฅผ ์‚ดํŽด๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

@floe ์‚ฌ์šฉ ์ค‘์ธ ์˜ฌ๋ฐ”๋ฅธ Trusty ์ €์žฅ์†Œ๊ฐ€ https://launchpad.net/~jonathonf/+archive/ubuntu/letsencrypt ์ž…๋‹ˆ๊นŒ?

๋„ค, ๋งž์Šต๋‹ˆ๋‹ค. ๋‚ด sources.list :

deb http://ppa.launchpad.net/jonathonf/letsencrypt/ubuntu trusty main

๊ณต์‹ Certbot PPA๋ฅผ ๋งŒ๋“ค๊ณ  ์‹ถ๋‹ค๋ฉด Certbot์ด ๋” ์ด์ƒ Let's Encrypt ํ”„๋กœ์ ํŠธ( source1 , source2 )๊ฐ€ ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์— ~letsencrypt ๋Œ€์‹  https://launchpad.net/~certbot ์—์„œ ์„ค์ •ํ•ด์•ผ ํ•œ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ~ certbot๋Š” ์šฐ๋ฆฌ์˜ ๋ฐ๋น„์•ˆ ํŒจํ‚ค์ง€ ๊ด€๋ฆฌ์ž์ž…๋‹ˆ๋‹ค @hlieberman๊ฐ€ ์†Œ์œ ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

ppa:letsencrypt/certbot ๊ฐ€ ๋” ์ž˜ ์–ด์šธ๋ฆฌ๋‚˜์š”? @hlieberman ~certbot์œผ๋กœ ์ด๋™ํ•˜๊ฑฐ๋‚˜ ๋‘˜ ์ค‘ ํ•˜๋‚˜๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. ํ•„์š”ํ•˜์ง€ ์•Š์œผ๋ฉด ์ผ์„ ์ „ํ˜€ ํ•˜์ง€ ์•Š์•„๋„ ๊ดœ์ฐฎ์Šต๋‹ˆ๋‹ค. ๋ฌด์–ธ๊ฐ€์— ๋™์˜ํ•˜๊ณ  ์•ž์œผ๋กœ ๋‚˜์•„๊ฐ€์ž. ๊ณต์‹ ์ €์žฅ์†Œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ณต์‹ Certbot PPA๊ฐ€ ์‚ฌ์šฉ์ž์—๊ฒŒ ํฐ ์ด์ ์ด ๋  ๊ฒƒ์ด๋ผ๋Š” ๋ฐ ๋™์˜ํ•ฉ๋‹ˆ๋‹ค. ์ด๊ฒƒ์ด ์ •ํ™•ํžˆ ์šฐ๋ฆฌ๊ฐ€ ์›ํ•˜๋Š” ๊ฒƒ์€ ํ•ต์‹ฌ certbot ๊ฐœ๋ฐœ์ž๊ฐ€ ์ด์•ผ๊ธฐํ•ด์•ผ ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋งค์ฃผ ์ˆ˜์š”์ผ ๋ชจ์ž„์ด ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋ฉด ์ด ๋ฌธ์ œ๋ฅผ ์ œ๊ธฐํ•˜๊ณ  ํšŒ์˜ ํ›„์— ์—ฌ๋Ÿฌ๋ถ„์—๊ฒŒ ๋‹ค์‹œ ์•Œ๋ ค ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.

@bmw @oerdnj @ArchimedesPi ๋‚ด๊ฐ€ ํ•ด์•ผ ํ•  ์˜ฌ๋ฐ”๋ฅธ ์ผ์€ ์•„๋งˆ๋„ ppa:letsencrypt , ์ด์ƒ์ ์œผ๋กœ๋Š” ๋Ÿฐ์น˜ํŒจ๋“œ๊ฐ€ ๊ทธ๊ฒƒ์„ certbot ๋ฆฌ๋””๋ ‰์…˜ํ•˜๋„๋ก ํ•˜๋Š” ๊ฒƒ ๊ฐ™์ง€๋งŒ ํ•„์š”ํ•œ ๊ฒฝ์šฐ ๋‹ค๋ฅธ ์ˆ˜๋‹จ์„ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด๋ผ๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

@oerdnj ์—ฌ๊ธฐ์„œ ๋‹ค์‹œ ๋งŒ๋‚˜์„œ ๋ฐ˜๊ฐ‘์Šต๋‹ˆ๋‹ค :) ์‚ฌ์‹ค ์ €๋Š” trusty๋กœ ๋ฐฑ

@oerdnj @pde @bmw PPA ์ด๋ฆ„ ์ง€์ • ๋ฌธ์ œ ์™ธ์— ๋ฐ๋น„์•ˆ์—์„œ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ฒ„์ „์œผ๋กœ ๊น”๋”ํ•˜๊ฒŒ ๋ฐฑํฌํŠธํ•œ ์‚ฌ๋žŒ์€ ๋ˆ„๊ตฌ์ž…๋‹ˆ๊นŒ? ๊ทธ๋ฆฌ๊ณ  PHP5 ์•ฑ์ด LE๋„ ์›ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ด์— ๋Œ€ํ•œ ์šฐ๋ฆฌ์˜ ๋…ธ๋ ฅ์„ ๋™๊ธฐํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€์žฅ ์ข‹์€ ๊ณณ์€ ์–ด๋””์ž…๋‹ˆ๊นŒ? ;)

๋ฐ๋น„์•ˆ์—๋Š” 0.8.1 ํŒจํ‚ค์ง€๊ฐ€ jessie-backports๋กœ ๋ฐฑํฌํŠธ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ ๊ฑฐ๊ธฐ์—์„œ xenial๋กœ์˜ ๋งค์šฐ ๊นจ๋—ํ•œ ๋ฐฑํฌํŠธ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. pyopenssl ๋ฐ python-cryptography ์— ๋Œ€ํ•œ Debian ํŒจํ‚ค์ง€์˜ deps๋ฅผ ๋‚ฎ์ถ”๋Š” ๊ฒƒ์€ python-acme ๋ฐ python-certbot ๋‘˜ ๋‹ค ๋‹ค๋ฅธ ํ•„์š” ์—†์ด ๋ฐฑํฌํŠธ๋œ๋‹ค๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ์ด ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ yakkety ํŒจํ‚ค์ง€๋ฅผ ๋ฐฑํฌํŠธํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

Trusty๋Š” ์—ฌ์ „ํžˆ python-acme ํŒจํ‚ค์ง€์— ๋Œ€ํ•œ ํŒจ์น˜๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ๋ชจ๋“  ๊ฒƒ์€ (๋Œ€๋ถ€๋ถ„) jessie-backport ๋ฒ„์ „์— ๋Œ€ํ•ด ์ •์ƒ์ ์œผ๋กœ ๋นŒ๋“œ๋ฉ๋‹ˆ๋‹ค. ๋ˆ„๊ฐ€ ์–ด๋–ค ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š”์ง€ ์•Œ ์ˆ˜ ์žˆ๋Š” ์—…๋ฐ์ดํŠธ๋œ ์ข…์†์„ฑ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ํŒจํ‚ค์ง€๊ฐ€ ์—ฌ์ „ํžˆ ๋งŽ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

@-all using ppa:jonathonf/letsencrypt : ์ด๊ฒƒ์€ jessie-backport Debian ํŒจํ‚ค์ง€๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋Š” ppa:jonathonf/certbot ์˜ ๋” ๊นจ๋—ํ•œ ๋ฐฑํฌํŠธ๋ฅผ ์œ„ํ•ด ๊ณง ์‚ฌ๋ผ์งˆ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋˜ํ•œ ์œ„์™€ ๊ฐ™์ด xenial ๋ฐฑํฌํŠธ๋ฅผ ์ฒญ์†Œํ•˜๊ธฐ ์œ„ํ•ด ์ตœ์‹  PPA๋ฅผ ์•ฝ๊ฐ„ ๋‹ค์‹œ ์ง€๊ทธํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

ํŽธ์ง‘: ๋‚ด certbot PPA๋Š” Jessie์—์„œ ๋ช‡ ๊ฐ€์ง€ ์ถ”๊ฐ€ Python ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ์ด๋ ‡๊ฒŒ ํ•˜๋ฉด Trusty Python ์Šคํƒ์—์„œ ๋ฒ—์–ด๋‚˜๋Š” ๋น„์šฉ์œผ๋กœ Sid์—์„œ ์ง์ ‘ ๋ฐฑํฌํŒ…์ด ํ›จ์”ฌ ์‰ฌ์›Œ์ง‘๋‹ˆ๋‹ค. ์–ด์จŒ๋“  ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๊ฐ€ universe ์— ์žˆ๋‹ค๋ฉด ์ด๊ฒƒ์€ ํฐ ๋ฌธ์ œ๊ฐ€ ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

@jonathonf ๋ฐ˜๊ฐ‘์Šต๋‹ˆ๋‹ค :) trusty์˜ "python-acme" ํŒจ์น˜์— ๋Œ€ํ•ด ๋” ๋งŽ์€ ํžŒํŠธ๋ฅผ ์ค„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์—ฐ์‡„ ํšจ๊ณผ์˜ ๊ฒฝ์šฐ ํ”„๋กœ๋•์…˜์œผ๋กœ ๊ฐ€์ ธ์˜ค๋Š” ๋™์•ˆ ์•ˆ์ •ํ™” ๋‹จ๊ณ„๊ฐ€ ํ•„์š”ํ•˜๋ฉฐ ๋ฌผ๋ก  ํ•ญ์ƒ ๊ฐœ๋ฐœ ์„œ๋ฒ„๋ฅผ ์ค‘๋‹จํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.) ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ค์ง€ ๋˜๋Š” ์ž‘์—… ์ค‘์ธ ์‚ฌ๋žŒ์„ ์–ด๋–ป๊ฒŒ ๋„์šธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

@jonathonf ppa:jonathonf/certbot ์—์„œ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ค์ง€๋ฅผ ํ…Œ์ŠคํŠธํ•  ๋•Œ ๋‹ค์Œ์„ ์–ป์Šต๋‹ˆ๋‹ค.
pkg_resources.DistributionNotFound: The 'python2-pythondialog>=3.2.2rc1' distribution was not found and is required by certbot
๊ทธ๋Ÿฌ๋‚˜ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ง€๊ธˆ ์ž‘๋™ํ•˜๋Š” ์ข…์†์„ฑ์— ๋Œ€ํ•œ ๋น ๋ฅธ ์†Œ์Šค ๋ณ€๊ฒฝ ๋ฐฑํฌํŠธ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. https://launchpad.net/~trio-interactive/+archive/ubuntu/unstable/+sourcepub/7045266/+listing-archive-extra

@all : ๋ฐฐํฌํŒ ๋ฆด๋ฆฌ์Šค์™€ ํ•จ๊ป˜ ์ œ๊ณต๋˜๋Š” ์—ฌ๋Ÿฌ Python ํŒจํ‚ค์ง€๋ฅผ ์—…๊ทธ๋ ˆ์ด๋“œํ•ด์•ผ ํ•˜๋ฏ€๋กœ Python ์ข…์†์„ฑ์„ ๊น”๋”ํ•˜๊ฒŒ ๋ฐฑ

ํ . certbot ํŒจํ‚ค์ง€ ๋‚ด์—์„œ ํ•„์š”ํ•œ ์ข…์†์„ฑ ๋ฒ„์ „์„ ๋กœ์ปฌ๋กœ ๋ฐฉ๋ฌธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

@bhat3 : debian.tar.gz์—์„œ python-acme ๋ฅผ ์ฐพ์œผ๋ฉด ํ€ผํŠธ ํŒจ์น˜๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚˜๋Š” ์ด ์Šค๋ ˆ๋“œ์˜ ์•ž๋ถ€๋ถ„์—์„œ ๊ทธ๊ฒƒ์„ ์–ป์—ˆ๋‹ค๊ณ  ํ™•์‹ ํ•˜์ง€๋งŒ, ์ง€๊ธˆ ๋น ๋ฅธ ์Šค์บ” ํ›„์— ๊ทธ๊ฒƒ์„ ๋ณด์ง€ ๋ชปํ–ˆ์Šต๋‹ˆ๋‹ค.

@jonathonf ์˜ค๋Š˜ ํฌ์žฅ์„ ๋ณด๋ ค๊ณ  ํ•˜๋Š”๋ฐ ์•„์ง ์‹œ๊ฐ„์ด ์žˆ์„ ๊ฑฐ๋ผ๊ณ  ์žฅ๋‹ดํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ํŒจ์น˜ ์™ธ์— trusty์— ๋Œ€ํ•œ ์ตœ์†Œํ•œ์˜ ์ข…์†์„ฑ์œผ๋กœ ๋ณผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ? ๋”ฐ๋ผ์„œ trusty์˜ Python ์Šคํƒ์„ ๊ทธ๋ ‡๊ฒŒ ๋งŽ์ด ์—‰๋ง์œผ๋กœ ๋งŒ๋“ค ํ•„์š”๊ฐ€ ์—†์Šต๋‹ˆ๊นŒ?
@oerdnj ๋ณด์•ˆ ๋‹ด๋‹น์ž์™€ ์ƒ๋‹นํžˆ

๊ทธ๊ฒƒ์€ ๋‹น์‹ ์ดํ•˜๊ณ  ์‹ถ์€ ํฌ์žฅ์˜ ์–‘์— ๋‹ฌ๋ ค ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚ด ์›๋ž˜ letsencrypt PPA์˜ deps๋Š” ๋‚ด๊ฐ€ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ํ•œ ์ตœ์†Œํ•œ์ด์ง€๋งŒ ๋ฐ๋น„์•ˆ์˜ ์ถ”๊ฐ€ ๋ฐฑํฌํŠธ๋ฅผ ๋” ์–ด๋ ต๊ฒŒ ๋งŒ๋“ญ๋‹ˆ๋‹ค. ๋‚ด certbot PPA์˜ ๋ฐฑํฌํŠธ๋œ dep๋Š” ๋” ๋งŽ๊ณ  ๊ด‘๋ฒ”์œ„ํ•˜์ง€๋งŒ ์ง์ ‘ ๋ฐฑํฌํŠธ๋ฅผ ํ›จ์”ฌ ์‰ฝ๊ฒŒ ๋งŒ๋“ญ๋‹ˆ๋‹ค.

Python ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๊ฐ€ universe ์žˆ์œผ๋ฉด ํฌ๊ฒŒ ๊ฑฑ์ •ํ•  ํ•„์š”๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ํ•ต์‹ฌ Ubuntu ์Šคํƒ์˜ ์–ด๋–ค ๊ฒƒ๋„ universe ์— ์˜์กดํ•˜์ง€ ์•Š์œผ๋ฉฐ universe ํŒจํ‚ค์ง€๋Š” ๋ณด์•ˆ ๋ฌธ์ œ์˜ ๊ฒฝ์šฐ์—๋„ ๋ฌผ๋ก  ์–ด์จŒ๋“  ์—…๋ฐ์ดํŠธ๋จ).

@jonathonf ์šฐ๋ถ„ํˆฌ์˜ "์šฐ์ฃผ" ์ฝ”๋„ˆ ์‚ฌ๋ก€์— ๋Œ€ํ•ด ์ž˜ ์ƒ๊ฐํ–ˆ์Šต๋‹ˆ๋‹ค ;) ์‚ฌ์‹ค ์ €๋Š” ์–ด์ œ ๋…ธ๋ ฅ์„ ๊ณ„์†ํ•  ์ˆ˜ ์—†์—ˆ๊ณ  ์ด๋ฒˆ ์ฃผ์—๋Š” ๋” ์ด์ƒ ๊ธฐํšŒ๊ฐ€ ์—†์—ˆ์Šต๋‹ˆ๋‹ค. :)

์ด ๋ฌธ์ œ๊ฐ€ ์ฒ˜์Œ ์ƒ์„ฑ๋œ ์ง€ ๊ฑฐ์˜ 1๋…„์ด ์ง€๋‚ฌ์ง€๋งŒ ์•„์ง ํ•ฉ์˜๋œ ์‚ฌํ•ญ์ด ์—†์œผ์‹ ๊ฐ€์š”?

์—ฌ๊ธฐ์—์„œ ์ถ”์ง„๋ ฅ์„ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์–ด๋Š ์ชฝ์ด๋“ .

https://launchpad.net/~jonathonf/+archive/ubuntu/certbot ์ด ์šฐ๋ฆฌ๊ฐ€ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ๊ณต์‹์ ์ž…๋‹ˆ๊นŒ?

@jonathonf ๋ชจ๋“  - ๋‚˜๋Š”์— @hlieberman์™€ ํ˜‘๋ ฅ PPA : certbot / certbot ์™€ ๋‚ด๊ฐ€ ๋ฏฟ์„ ์ˆ˜์žˆ๋Š”, ์ฃผ๊ฐ ๊ด€๊ณ„์˜ ๋ฐ yakkety์˜ ๋นŒ๋“œ deps์˜ ๋Œ€๋ถ€๋ถ„์„ ๊ฐ€์ง€๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ๋ˆ„๋ฝ๋œ ์œ ์ผํ•œ ๊ฒƒ์€ ์ตœ๊ทผ ์Šคํ•‘ํฌ์Šค์ด๋ฉฐ ์ด์— ๋Œ€ํ•œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์ด ์žˆ๊ธฐ๋ฅผ ๋ฐ”๋ž๋‹ˆ๋‹ค.

@oerdnj ์‚ฌ์šฉํ•  ์ค€๋น„๊ฐ€ ๋˜์—ˆ์Šต๋‹ˆ๊นŒ?
์ถ”๊ฐ€ํ•˜๋ ค๊ณ  ํ•˜๋ฉด "์˜ค๋ฅ˜: ์„œ๋ช… ํ‚ค ์ง€๋ฌธ์ด ์—†์Šต๋‹ˆ๋‹ค"๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

์ฃ„์†กํ•˜์ง€๋งŒ ์•„์ง ~์ฃผ ์•ˆ์— ์™„๋ฃŒ๋ฉ๋‹ˆ๋‹ค. ๋‚˜๋Š” ๋‚ด์ผ IETF๋กœ ๋– ๋‚˜๊ณ  ๊ทธ๊ณณ์—์„œ ๊ทธ๊ฒƒ์„ ๋งˆ์น˜๊ธฐ ์œ„ํ•ด ์•ฝ๊ฐ„์˜ ์ž์œ  ์‹œ๊ฐ„์„ ๊ฐ€์งˆ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

builddep์ธ ๊ฒฝ์šฐ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ๋Š” Sphinx ๋ฐฑํฌํŠธ PPA๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.
PPA ์ข…์†์„ฑ์œผ๋กœ. ๊ทธ๊ฒƒ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํŒจํ‚ค์ง€๋ฅผ "์ง€์›"์— ๋ณต์‚ฌํ•˜์‹ญ์‹œ์˜ค.
PPA ๋˜๋Š” ๋™์ผํ•œ ํŒจํ‚ค์ง€ ์„ธํŠธ๋ฅผ ๋ฐฑํฌํŠธํ•ฉ๋‹ˆ๋‹ค.

์ œ์ด

2016๋…„ 11์›” 9์ผ 12์‹œ 39๋ถ„์— "Ondล™ej Surรฝ" ์•Œ๋ฆผ @github.com์ด ์ž‘์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค.

@jonathonf https://github.com/jonathonf and all - ๋‚˜๋Š” ํ˜‘๋ ฅ
@hlieberman https://github.com/hlieberman in ppa:certbot/certbot ๊ทธ๋ฆฌ๊ณ  ๋‚˜๋Š”
์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๊ณ  xenial ๋ฐ yakkety์— ๋Œ€ํ•œ ๋Œ€๋ถ€๋ถ„์˜ ๋นŒ๋“œ dep๊ฐ€ ์žˆ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. NS
๋ˆ„๋ฝ๋œ ๊ฒƒ์€ ์ตœ๊ทผ ์Šคํ•‘ํฌ์Šค๋ฟ์ด๋ฉฐ ์ผ๋ถ€๊ฐ€ ์žˆ๊ธฐ๋ฅผ ๋ฐ”๋ž๋‹ˆ๋‹ค.
์ด์— ๋Œ€ํ•œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•.

โ€”
๋‹น์‹ ์ด ์–ธ๊ธ‰๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด๊ฒƒ์„ ๋ฐ›๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
์ด ์ด๋ฉ”์ผ์— ์ง์ ‘ ๋‹ต์žฅํ•˜๊ณ  GitHub์—์„œ ํ™•์ธํ•˜์„ธ์š”.
https://github.com/certbot/certbot/issues/1706#issuecomment -259405442,
๋˜๋Š” ์Šค๋ ˆ๋“œ ์Œ์†Œ๊ฑฐ
https://github.com/notifications/unsubscribe-auth/AAiJCY1dmSHhspzOgNcT8tQu4XigyNJdks5q8b7ygaJpZM4Guho5
.

@oerdnj @jonathonf @hlieberman
์ž‘์—…ํ•ด ์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

์šฐ๋ฆฌ ๋ชจ๋‘๋Š” ๋˜ ํ•œ ์ฃผ๋ฅผ ๊ธฐ๋‹ค๋ฆด ์ˆ˜ ์žˆ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

@oerdnj @jonathonf ๊ทผ๋ฌด ์‹œ๊ฐ„ ๋‚ด์— ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฑํฌํŠธ์— ๋Œ€ํ•ด ๋„์›€์„ ๋“œ๋ฆด ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ด ์žˆ์Šต๋‹ˆ๊นŒ?

@bhat3 ํ˜„์žฌ ppa:certbot/certbot ์— ์žˆ๋Š” ๊ฒƒ์„ ๊ด‘๋ฒ”์œ„ํ•˜๊ฒŒ ํ…Œ์ŠคํŠธํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด ์ •๋ง ์ข‹์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋Ÿฐํƒ€์ž„ ์˜ค๋ฅ˜ ๋ฐœ์ƒ์„ ์ค‘์ง€ํ•˜๊ธฐ ์ „์— ์ผ๋ถ€ (Build-)Depends๋ฅผ ์กฐ์—ฌ์•ผ ํ–ˆ์ง€๋งŒ ์ง€๊ธˆ์€ ๋ชจ๋‘ ์ข‹์•„ ๋ณด์ž…๋‹ˆ๋‹ค.

JFTR ppa:certbot/certbot ์—๋Š” ์ด์ œ ์•ฝ๊ฐ„์˜ ์ฃผ์˜๋ฅผ ๊ธฐ์šธ์—ฌ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ค์ง€๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ๋‹น๋ถ„๊ฐ„ ์—ฌ๊ธฐ์—์„œ ํŒŒ์†์„ ์‹ ๊ณ ํ•ด ์ฃผ์‹ญ์‹œ์˜ค.

@oerdnj ์ข‹์•„, ์šฐ๋ฆฌ ๊ฐœ๋ฐœ ์„œ๋ฒ„์—์„œ ๋‚ด ์ž์‹ ์˜ ํŒจํ‚ค์ง•์„ ppa:certbot/certbot ๋ฐ”๊ฟ€ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ํ‘œ์ค€ Debian/Ubuntu ๋„๊ตฌ ์™ธ์— ์šฐ๋ฆฌ๋Š” Python์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š๊ณ  PHP๋ฅผ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ ์ด๋Ÿฌํ•œ ์†์ƒ์„ ๊ฐ•์กฐํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.)

Ubuntu-16.04-xeinal์—์„œ ๋‹ค์Œ ์˜ค๋ฅ˜๋กœ ์ธํ•ด ๊ฐฑ์‹ ์— ์‹คํŒจํ•œ 0.4.1์— ๋ฉˆ์ท„์Šต๋‹ˆ๋‹ค.

๊ฒฝ๊ณ :letsencrypt.cli:/etc/letsencrypt/renewal/gableroux.com.conf ์—์„œ ์ธ์ฆ์„œ๋ฅผ ๊ฐฑ์‹ ํ•˜๋ ค๊ณ  ํ•˜๋ฉด '์„œ๋ฒ„'๋ผ๋Š” ์˜ˆ๊ธฐ์น˜ ์•Š์€ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ฑด๋„ˆ๋›ฐ๊ธฐ.

์—…๊ทธ๋ ˆ์ด๋“œ ํ›„ ๊ฐฑ์‹ ์ด ๋‹ค์‹œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค! :NS

python -mplatform

Linux-3.11.0-12-generic-x86_64-with-Ubuntu-16.04-xenial

letsencrypt --version

๋ ›์„ผํฌ๋ฆฝํŠธ 0.4.1

sudo add-apt-repository ppa:certbot/certbot
sudo apt-get update
sudo apt-get install --upgrade letsencrypt
letsencrypt --version

๋ ›์„ผํฌ๋ฆฝํŠธ 0.9.3

letsencrypt renew --agree-tos 

์ถ•ํ•˜ํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  ๊ฐฑ์‹ ์— ์„ฑ๊ณตํ–ˆ์Šต๋‹ˆ๋‹ค.

:๋งˆ์Œ:

@oerdnj ์ง€๊ธˆ๊นŒ์ง€ @jonathonf ์˜ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ํŒจํ‚ค์ง€์™€ ํ•˜๋‚˜์˜ ์ž์ฒด ๋ฐฑํฌํŠธ๋ฅผ ์‚ฌ์šฉํ•œ ๊ฐœ๋ฐœ ์„œ๋ฒ„์—์„œ ์ž˜ ๋ณด์ž…๋‹ˆ๋‹ค.

Reading package lists... Done
Building dependency tree       
Reading state information... Done
Calculating upgrade... Done
The following packages will be upgraded:
  certbot letsencrypt python-acme python-certbot python-cffi-backend
  python-configargparse python-cryptography python-dialog python-dnspython
  python-idna python-ipaddress python-ndg-httpsclient python-openssl
  python-parsedatetime python-pkg-resources python-pyasn1 python-requests
  python-rfc3339 python-setuptools python-six python-urllib3
21 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
Need to get 1,410 kB of archives.
After this operation, 398 kB of additional disk space will be used.
Do you want to continue? [Y/n]

99๊ฐœ์˜ ํ•˜์œ„ ๋„๋ฉ”์ธ์œผ๋กœ ๋ฏธ๋ฆฌ ์ƒ์„ฑ๋œ LE ์ธ์ฆ์„œ๋ฅผ ์„ฑ๊ณต์ ์œผ๋กœ ๊ฐฑ์‹ ํ–ˆ์œผ๋ฉฐ ์ž˜ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค. ๋‚ด์ผ ๋” ๋งŽ์€ ํ…Œ์ŠคํŠธ๊ฐ€ ์ด์–ด์ง‘๋‹ˆ๋‹ค ...

๋งํ–ˆ๋“ฏ์ด LE๋Š” ์ด๋ฏธ ์ „์ฒด ์ข…์†์„ฑ ์ฒด์ธ์„ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜์ง€ ์•Š๊ณ  ๋™์ผํ•œ ์‹œ์Šคํ…œ์—์„œ ์ž‘์—…ํ•˜๊ณ  ์žˆ์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์™„์ „ํ•œ ์ข…์†์„ฑ ๋ฐฑํฌํŒ…์— ๋Œ€ํ•ด ์•ฝ๊ฐ„ ํšŒ์˜์ ์ž…๋‹ˆ๋‹ค.

BTW certbot/certbot PPA์˜ ์ด๋ฆ„์„ ๊ธฐ๋ณธ ์ด๋ฆ„(certbot/ppa)์œผ๋กœ ๋ฐ”๊พธ๋ฉด ์‚ฌ์šฉ์ž๋Š” ์ด๋ฆ„์˜ ๋‹จ์ถ• ๋ฒ„์ „์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ:

sudo add-apt-repository ppa:certbot

@oerdnj trusty์— ๋Œ€ํ•œ ๋‹ค์Œ ํ…Œ์ŠคํŠธ๋Š” cron ๋ฐ shell์„ ํ†ตํ•œ ์ž๋™ ๊ฐฑ์‹ ์ด์—ˆ์ง€๋งŒ ์‹ค์ œ๋กœ๋Š” ์ด์ „์— ๋งŒ๋‚˜์ง€ ๋ชปํ•œ ๋ช‡ ๊ฐ€์ง€ ๋ฌธ์ œ๋ฅผ ๋ฐœ๊ฒฌํ–ˆ์Šต๋‹ˆ๋‹ค.

/usr/bin/letsencrypt certonly --force-renewal --webroot -w /var/www/letsencrypt -d DOMAIN.TLD
An unexpected error occurred:
Bug in pythondialog: expected an empty output from u'infobox', but got: u'Error opening terminal: unknown.\n'Please see the logfile 'certbot.log' for more details.

๊ฐฑ์‹  ์Šคํฌ๋ฆฝํŠธ์˜ ๋ชจ๋“  ์ถœ๋ ฅ์„ ๊ธฐ๋กํ•˜๊ณ  ๊ทธ ์•ˆ์— ๋ฉ”์ผ ์•Œ๋ฆผ์„ ๋ฐ›๋Š” ๋™์•ˆ certbot.log๋ฅผ ์ฐพ์ง€ ๋ชปํ•˜๊ณ  ์‹ค์ œ๋กœ ๋””๋ฒ„๊ทธํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ์— ๋Œ€ํ•œ ํžŒํŠธ๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?

@bhat3 cron ์Šคํฌ๋ฆฝํŠธ์—์„œ certbot์„ ํ˜ธ์ถœํ•˜๋Š” ๊ฒฝ์šฐ --noninteractive ๋˜๋Š” --quiet ( --noninteractive )๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

(/var/log/, ์•„๋งˆ๋„ /var/log/letsencrypt/์—์„œ certbot.log ๋ฅผ ์ฐพ์„ ๊ฒƒ์ž…๋‹ˆ๊นŒ? TBH ๊ฑฐ๊ธฐ์—๋Š” letsencrypt.log๋งŒ ์žˆ์Šต๋‹ˆ๋‹ค. certbot.log๋Š” ์ƒˆ๋กœ์šด ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ž…๋‹ˆ๋‹ค.)

certbot์€ ๋ชจ๋‘ ๊ฐฑ์‹ ์„ ์‹œ๋„ํ•˜์ง€ ์•Š์Šต๋‹ˆ๊นŒ? ๋‚˜๋Š” ๊ทธ๊ฒƒ์„ ์‹คํ–‰ํ•˜๊ณ  ๊ทธ๊ฒƒ์€ ๊ทธ๊ฒƒ์„ํ•œ๋‹ค

@bhat3 ์€ ํŒจํ‚ค์ง€์—์„œ ์ œ๊ณตํ•˜๋Š” ๊ธฐ๋ณธ cronjob์ž…๋‹ˆ๊นŒ?

@oerdnj ์•„๋‹ˆ์š”, ๊ทธ๊ฑด ์ž์‹ ์˜ ๊ฒƒ์ด๊ณ  --noninteractive ์Šค์œ„์น˜๋Š” @jonathonf ์˜ ํŒจํ‚ค์ง€๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์ „์—๋Š” ํ•„์š”ํ•˜์ง€ nginx -t && systemctl restart nginx ์™€์˜ ์ƒํ˜ธ ์ž‘์šฉ์— ๋Œ€ํ•ด์„œ๋Š” ํ™•์‹คํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

@chrismccoy ๊ทธ๋ฆฌ๊ณ  ๊ฐฑ์‹  ํ›„ ์›น ์„œ๋ฒ„๋ฅผ ์–ด๋–ป๊ฒŒ ๋‹ค์‹œ ์‹œ์ž‘ํ•ฉ๋‹ˆ๊นŒ?

@mgedmin Thx, ์Šค์œ„์น˜์™€ ํ•จ๊ป˜ ์ž‘๋™ํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ๋‚˜๋Š” ์—ฌ์ „ํžˆ certbot.log๊ฐ€ ๋ธŒ๋žœ๋”ฉ ๋ฌธ์ œ์ด๊ณ  /var/log/letsencrypt/letsencrypt.log๊ฐ€ ์Šค์œ„์น˜ ์—†์ด ์ƒ์„ฑ๋˜์ง€ ์•Š์€ ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ด๋Š” ๊ทธ๊ฒƒ์„ ์˜๋ฏธํ•˜๋Š”์ง€ ๊ถ๊ธˆํ•ฉ๋‹ˆ๋‹ค.

/usr/bin/letsencrypt certonly --noninteractive --force-renewal --webroot -w /var/www/letsencrypt -d DOMAIN.TLD
Saving debug log to /var/log/letsencrypt/letsencrypt.log

์ƒˆ๋กœ์šด ์ž๋ฅด๊ธฐ ์ž‘์—…์„ ๋ณด์„ธ์š”. hooks ๋””๋ ‰ํ† ๋ฆฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

@oerdnj ๋‹น์‹ ์€ ๋‚ด๊ฐ€ Nginx๋ฅผ ๋Œ๋ณด๋Š” ์„ฑ๊ณต์ ์ธ ๊ฐฑ์‹  ํ›„์—๋งŒ ํ›„ํฌ๋ฅผ ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๊นŒ?

certbot renew ํ˜ธ์ถœ์—๋Š” ๋‹ค์Œ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. /usr/bin/certbot -q renew --pre-hook '/bin/run-parts /etc/letsencrypt/pre-hook.d/' --post-hook '/bin/run-parts /etc/letsencrypt/post-hook.d/' --renew-hook '/bin/run-parts /etc/letsencrypt/renew-hook.d/'

๊ทธ๋ฆฌ๊ณ  ๋ฐฉ๊ธˆ @hlieberman ๋ฐ๋น„์•ˆ ๋ฒ„๊ทธ์— ๋Œ€ํ•œ ํŒจ์น˜๋ฅผ ๋ณด๋ƒˆ์Šต๋‹ˆ๋‹ค.#838548

# cat /etc/letsencrypt/post-renewal.d/nginx 
#!/bin/sh
set -e
PATH="/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
nginx -t -q && nginx -s reload
exit 0

@oerdnj , ์šฐ๋ฆฌ๋Š” @hlieberman์—๊ฒŒ ํŠนํžˆ ๋ชจ๋“  ๋ฐฐํฌํŒ์ด ํ˜œํƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ๋Š” ์†”๋ฃจ์…˜ ์—…์ŠคํŠธ๋ฆผ์„ ๊ฐœ๋ฐœํ•˜๊ธฐ ์œ„ํ•ด Debian์— ๊ทธ๋Ÿฐ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์ถ”๊ฐ€ํ•˜์ง€ ํ–ˆ์Šต๋‹ˆ๋‹ค . ์ด๋Ÿฌํ•œ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์ œ๊ฑฐํ•˜๊ณ  ๋‹น์‚ฌ์˜ ์†”๋ฃจ์…˜์„ ๊ธฐ๋‹ค๋ฆฌ๋Š” ๊ฒƒ์— ๋Œ€ํ•ด ์–ด๋–ป๊ฒŒ ์ƒ๊ฐํ•˜์‹ญ๋‹ˆ๊นŒ?

PPA์— ์žˆ๋Š” ํŒจํ‚ค์ง€ ๋ฒ„์ „์˜ certbot์— Apache ๊ตฌ์„ฑ ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ์žˆ์Šต๋‹ˆ๊นŒ? Universe์™€ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ python-letsencrypt-apache์™€ ๋™์ผํ•œ ํŒจํ‚ค์ง€๊ฐ€ ์—†๋‹ค๋Š” ๊ฒƒ์„ ์•Œ์•˜์Šต๋‹ˆ๋‹ค.

Certbot/Letsencrypt๊ฐ€ Universe ๋ฒ„์ „์œผ๋กœ ์ž‘๋™ํ•˜์ง€๋งŒ PPA๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์—…๊ทธ๋ ˆ์ด๋“œํ•  ๋•Œ ์•„ํŒŒ์น˜ ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ๋‘˜๋Ÿฌ์‹ผ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ

$ sudo certbot renew --dry-run
Saving debug log to /var/log/letsencrypt/letsencrypt.log

-------------------------------------------------------------------------------
Processing /etc/letsencrypt/renewal/XXXXXX.conf
-------------------------------------------------------------------------------
Renewal configuration file /etc/letsencrypt/renewal/XXXXXX.conf produced an unexpected error: 'Namespace' object has no attribute 'apache_enmod'. Skipping.
** DRY RUN: simulating 'certbot renew' close to cert expiry
**          (The test certificates below have not been saved.)

No renewals were attempted.

Additionally, the following renewal configuration files were invalid: 
  /etc/letsencrypt/renewal/XXXXXXXXX.conf (parsefail)
** DRY RUN: simulating 'certbot renew' close to cert expiry
**          (The test certificates above have not been saved.)
0 renew failure(s), 1 parse failure(s)

๊ทธ๋ฆฌ๊ณ 

$ sudo certbot --apache
The requested apache plugin does not appear to be installed

๊ตฌ์„ฑ ํŒŒ์ผ(์ด๋ฆ„์ด /etc/letscrypt๋กœ ๋ณ€๊ฒฝ๋จ)์„ ์‚ญ์ œํ•˜๋ ค๊ณ  ์‹œ๋„ํ–ˆ์ง€๋งŒ ๊ฐœ์„ ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ๋‹คํ–‰ํžˆ 0.4.1๋กœ ๋‹ค์šด๊ทธ๋ ˆ์ด๋“œํ•˜๋Š” ๊ฒƒ์€ ๊ฐ„๋‹จํ•ฉ๋‹ˆ๋‹ค.

@bmw ์†”์งํžˆ ๋งํ•ด์„œ ์—ฌ๊ธฐ์—์„œ Debian ํ†ตํ•ฉ์„ ํ™˜์˜ํ•˜๋ฉฐ ์ž์ฒด cron'd BASH ์Šคํฌ๋ฆฝํŠธ์—์„œ ํ†ตํ•ฉํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค. ์—…์ŠคํŠธ๋ฆผ ๋ฐ ๋ฐฐํฌํŒ ๋ถˆ๊ฐ€์ง€๋ก  ์†”๋ฃจ์…˜์œผ๋กœ ๋ฌด์—‡์„ ํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๊นŒ? ์ œ๊ณตํ•˜๋Š” ๋ฐ ์–ผ๋งˆ๋‚˜ ๊ฑธ๋ฆฝ๋‹ˆ๊นŒ?

๊ฐฑ์‹ ๊ณผ ์ธ์ฆ์„œ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์„œ๋น„์Šค์™€์˜ ํ•„์š”ํ•œ ์ƒํ˜ธ ์ž‘์šฉ๊ณผ ๊ด€๋ จํ•˜์—ฌ ๊ณต๊ฐœ์ ์œผ๋กœ ๋„ˆ๋ฌด ๋”์ฐํ•œ ์†”๋ฃจ์…˜์ด ์žˆ์œผ๋ฏ€๋กœ @oerdnj ๋“ฑ์ด ์ง€๊ธˆ ๋ฐ๋น„์•ˆ ๋ฐฐํฌํŒ์—์„œ ํ‘œ์ค€ํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ์ •์ƒ์ ์ธ ์†”๋ฃจ์…˜์„ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ์„ ์ •๋ง ์„ ํ˜ธํ•ฉ๋‹ˆ๋‹ค.+1:

@bmw ์ „์ ์œผ๋กœ ๋™์˜ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋ฐ๋น„์•ˆ ํ™•์žฅ์ด ๋™๊ฒฐ ๊ธฐ๊ฐ„์— ์ ‘์–ด๋“ค๊ณ  ์žˆ์œผ๋ฉฐ ๋ชจ๋“  ์‚ฌ๋žŒ์ด ํ–ฅํ›„ 2๋…„ ์ด์ƒ ๋™์•ˆ ์ž์‹ ์˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•˜๋Š” ๊ฒƒ์„ ์›ํ•˜์ง€ ์•Š๋Š”๋‹ค๋ฉด ๋ฐ๋น„์•ˆ ํ†ตํ•ฉ์ด ์ œ์–ด๋˜๊ณ  ์–ธ์ œ( ๊ทธ๋ฆฌ๊ณ ) ๊ณต์‹ ์‹คํ–‰ ๋ถ€ํ’ˆ์„ ์ œ๊ณตํ•˜๋ฉด ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜์ด ์ƒ๋‹นํžˆ ์‰ฌ์šธ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์•„๋งˆ๋„ ๋‚ด๊ฐ€ ์ด ๋ถ„์•ผ์— ๋„ˆ๋ฌด ์˜ค๋ž˜ ์žˆ์—ˆ์„์ง€ ๋ชจ๋ฅด์ง€๋งŒ, ์‚ฌ๋žŒ๋“ค์ด ์ฐฝ์˜๋ ฅ์„ ๋ฐœํœ˜ํ•˜๊ธฐ ์‹œ์ž‘ํ•  ๊ฒƒ์ด๊ธฐ ๋•Œ๋ฌธ์— ์™„๋ฒฝํ•œ ํ•ด๊ฒฐ์ฑ…์„ ๊ธฐ๋‹ค๋ฆฌ๋Š” ๊ฒƒ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์žฌ์•™์œผ๋กœ ๊ฐ€๋Š” ๊ธธ์ผ ๋ฟ์ž…๋‹ˆ๋‹ค.

@hlieberman ์ด run-parts ์†”๋ฃจ์…˜์„ ๊ธฐ๋ณธ ๋ฐ๋น„์•ˆ ํŒจํ‚ค์ง€์— ํ†ตํ•ฉํ•œ๋‹ค๋ฉด ์ •๋ง ๊ฐ์‚ฌํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ์ด ์†”๋ฃจ์…˜์€ ํ˜„์žฌ ๋ฐ๋น„์•ˆ ์ŠคํŠธ๋ ˆ์น˜์— ๋Œ€ํ•œ ์ž‘๋™ ์†”๋ฃจ์…˜์„ ์ œ๊ณตํ•˜๊ณ  ๋ฐ๋น„์•ˆ ๋‚ด๋ถ€๊ฐ€ ์ž‘๋™ํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ ์ž˜ ํ†ตํ•ฉ๋ฉ๋‹ˆ๋‹ค.

์•ˆ๋…•ํ•˜์„ธ์š” @oerdnj , ๋‘ ๊ฐ€์ง€ ์ :

  1. ์šฐ๋ฆฌ๋Š” ์—…์ŠคํŠธ๋ฆผ์„ ์ œ์–ดํ•˜๊ณ  unstable ๋ฐ testing ๋กœ์˜ ๋ฆด๋ฆฌ์Šค์—์„œ ๊ฝค ์ข‹์€ ํŒŒ์ดํ”„๋ผ์ธ์„ ๊ฐ€์ง€๊ณ  ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ๋ฐ๋น„์•ˆ๊ณผ ๋Œ€๋ถ€๋ถ„์˜/๋ชจ๋“  ๋‹ค๋ฅธ ๋ฐฐํฌํŒ ๋ชจ๋‘์—์„œ ์ž‘๋™ํ•˜๋Š” ์—…์ŠคํŠธ๋ฆผ Certbot์— ํŒจ์น˜๋ฅผ ์ ์šฉํ•  ์‹œ๊ฐ„์ด ์žˆ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. , ๋ฐ๋น„์•ˆ์œผ๋กœ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. ์›ํ•˜๋Š” ๊ฒฝ์šฐ 2์›” ๋™๊ฒฐ ์ „์— ๋งค์šฐ ์‰ฝ๊ฒŒ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. PR์„ ๋ณด๋‚ด๊ฑฐ๋‚˜ @hlieberman ์ด ๊ทธ๋ ‡๊ฒŒ ํ•˜๋„๋ก ๊ฒฉ๋ คํ•˜์‹ญ์‹œ์˜ค. :)
  2. ์šฐ๋ฆฌ๋Š” ์ŠคํŠธ๋ ˆ์น˜ ํ”„๋ฆฌ์ฆˆ์— ๋Œ€์ฒ˜ํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•ด ๋งŽ์€ ๋Œ€ํ™”๋ฅผ ๋‚˜๋ˆด์Šต๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” Certbot์ด ์‚ฌ๋žŒ๋“ค์ด ๋ฐ๋น„์•ˆ ์•ˆ์ • ๋ฆด๋ฆฌ์Šค๋ฅผ ์œ„ํ•ด ์‹œํ–‰ํ•˜๋ ค๊ณ  ํ•˜๋Š” ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ด๋Š” 5๋…„ ์ด์ƒ ๋™์•ˆ ์ฃผ์–ด์ง„ ๋ฒ„์ „์— ๊ณ ์ •๋  ๋งŒํผ ์„ฑ์ˆ™ํ•˜์ง€ ์•Š๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” ์—ฌ์ „ํžˆ ๊ทธ๊ฒƒ์— ๋Œ€ํ•ด ๋ฌด์—‡์„ ํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ์•Œ์•„ ๋‚ด๋ ค๊ณ  ๋…ธ๋ ฅํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. Ubuntu์—์„œ ์šฐ๋ฆฌ๋Š” ์ตœ์‹  Certbot ๋ฒ„์ „์„ Xenial LTS๋กœ ๊ฐ€์ ธ์˜ค๊ธฐ ์œ„ํ•ด SRU ํ”„๋กœ์„ธ์Šค๋ฅผ ์ง„ํ–‰ํ•˜๊ณ  ์žˆ์ง€๋งŒ Debian์ด ์ด๋ฅผ ํ™•์žฅํ•  ๊ฒƒ์ด๋ผ๊ณ  ๋‚™๊ด€ํ•˜์ง€๋Š” ์•Š์Šต๋‹ˆ๋‹ค. ํ˜„์žฌ ๊ณ„ํš์€ debian-devel ๋ชฉ๋ก์— ๋‹ค์Œ ์ค‘์—์„œ ์„ ํƒํ•˜๋„๋ก ์š”์ฒญํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. (2) Debian์— Certbot์„ ์•ˆ์ •์ ์ธ ๋ฆด๋ฆฌ์Šค๋กœ ์ œ๊ณตํ•˜์ง€ ๋ง๋ผ๊ณ  ์š”์ฒญํ•˜๊ณ  ๋Œ€์‹  ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฐฑํฌํŠธ ์ง€์นจ ์„ ์ œ๊ณตํ•˜๋Š” ๋ฐ ์˜์กดํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์šฐ๋ฆฌ๊ฐ€ ํ˜„์žฌ Jessie์™€ ํ•จ๊ป˜ ํ•˜๊ณ  ์žˆ๋Š” ์ผ์ด๋ฉฐ ์šฐ๋ฆฌ๋Š” ๊ทธ๊ฒƒ์ด ์ƒ๋‹นํžˆ ์ •์ƒ์ ์ด๋ผ๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.
  3. ์›ํ•˜์‹ ๋‹ค๋ฉด ์ฃผ๊ฐ„ Certbot ๊ฐœ๋ฐœ ํ†ตํ™”์— ์ฐธ์—ฌํ•˜์—ฌ ์ด๋Ÿฌํ•œ ๋ฌธ์ œ๋ฅผ ๋…ผ์˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค! Brad๊ฐ€ ์ดˆ๋Œ€์žฅ์„ ๋ณด๋‚ธ ๊ฒƒ ๊ฐ™์ง€๋งŒ ๊ทธ๋ ‡์ง€ ์•Š์€ ๊ฒฝ์šฐ lmk์—์„œ ์ˆ˜์ •ํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

@pde ์•Œ๊ฒ ์Šต๋‹ˆ๋‹ค . run-parts ์™€ ๋น„์Šทํ•œ ๊ฒƒ์„ ์š”๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด ์ž์œ  ์‹œ๊ฐ„์„ ์˜ˆ์•ฝํ•˜๋ ค๊ณ  ํ•ฉ๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ๊ธฐ๋ณธ ํŒŒ์ด์ฌ ์ฝ”๋“œ์—์„œ.

์˜ˆ, ์ดˆ๋Œ€์žฅ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค(์ •ํ™•ํ•œ ์‹œ๊ฐ„์€ Freenode์—์„œ ํ™•์ธํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค). ์ผ/์ฃผ/์›”/๋…„์— ์‹œ๊ฐ„์ด ํ•œ์ •๋˜์–ด ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด ํŠน์ • ๋ฌธ์ œ ์™ธ์—๋Š” ์•„๋ฌด ๊ฒƒ๋„ ์•ฝ์†ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. :)

ํŽธ์ง‘๋จ: ์–ด์ฉŒ๋ฉด ๋‚ด ์•ˆ์˜ IETF ๊ฒฝํ—˜์ผ ์ˆ˜๋„ ์žˆ์ง€๋งŒ ์‹ค์ œ๋กœ๋Š” ๋งํ•˜๋Š” ๊ฒƒ๋ณด๋‹ค ์‹คํ–‰ ์ค‘์ธ ์ฝ”๋“œ๋ฅผ ์„ ํ˜ธํ•ฉ๋‹ˆ๋‹ค. :). ๋” ๋งŽ์€ ์‹คํ–‰ ์ฝ”๋“œ๋ฅผ ์ƒ์„ฑํ•  ์‹œ๊ฐ„๋งŒ ๋” ์žˆ๋‹ค๋ฉด.

์•„ํŒŒ์น˜ ํ”Œ๋Ÿฌ๊ทธ์ธ๋„ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด ์ข‹์„ ํ…๋ฐ :)

์•ˆ๋…•ํ•˜์„ธ์š”, ์–ธ์ œ PPA๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๊ณ  ์‹ถ์—ˆ์Šต๋‹ˆ๋‹ค. Lets Encrypt๋ฅผ ์ฒ˜์Œ ์‚ฌ์šฉํ•œ ์ดํ›„๋กœ ๊ณง ์žˆ์„ ์ฒซ ๋ฒˆ์งธ ๊ฐฑ์‹ ์„ ์™„๋ฃŒํ•˜๊ธฐ ์œ„ํ•ด ๊ฐ€๊นŒ์šด ์‹œ์ผ ๋‚ด์— certbot-auto๋ฅผ ์„ค์น˜ํ•˜๊ธฐ ์ง์ „์ž…๋‹ˆ๋‹ค. ์—ฌ๋Ÿฌ๋ถ„์ด ์ด ์ผ์„ ํ•จ๊ป˜ ํ•˜๊ธฐ ์œ„ํ•ด ํ•˜๊ณ  ์žˆ๋Š” ์ผ์— ๋Œ€ํ•ด ๊ฑด๋ฐฐ์™€ ๊ฐ์‚ฌ๋ฅผ ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

@jesseiqmi ๋‹น์‹ ์€ ์ด๋ฏธ ๊ทธ๊ฒƒ์„ ํƒˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

sudo add-apt-repository ppa:certbot/certbot
sudo apt-get update
sudo apt-get install --upgrade letsencrypt
letsencrypt --version

ํ”„๋กœ๋•์…˜์—์„œ๋„ ์‚ฌ์šฉํ•˜์ง€๋งŒ ์—ฌ์ „ํžˆ ์ ์ ˆํ•œ ๊ฐฑ์‹  ํ†ตํ•ฉ์ด ์—†์ง€๋งŒ ํ”„๋กœ๋•์…˜์—์„œ ์ž์ฒด ์ œ์ž‘ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ…Œ์ŠคํŠธํ–ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์ ์–ด๋„ ํ”„๋กœ๋•์…˜์„ ๋งŒ์ง€๊ธฐ ์ „์— ๊ฐœ๋ฐœ ๋ฐ ์Šคํ…Œ์ด์ง• ์‹œ์Šคํ…œ์—์„œ ํ•ญ์ƒ ์ƒˆ ๋ฒ„์ „์„ ํ…Œ์ŠคํŠธํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. apt-mark hold PKGNAME ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ KISS ๋ฆฐ ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•˜๊ฑฐ๋‚˜ ๋‹ค์Œ ํ…Œ์ŠคํŠธ๊ฐ€ ์Šคํ…Œ์ด์ง•์„ ํ†ต๊ณผํ•  ๋•Œ๊นŒ์ง€ ํ”„๋กœ๋•์…˜์—์„œ PPA๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜๊ฑฐ๋‚˜ ์ž์ฒด PPA๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ QA ์ฒด์ธ์˜ ์‹œ์Šคํ…œ ๊ฐ„์— ํŒจํ‚ค์ง€๋ฅผ ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

PPA์—๋Š” certbot-apache์™€ ๊ฐ™์€ ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š์€ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ์„ค์น˜ํ•˜๋Š” ์˜ฌ๋ฐ”๋ฅธ ์ ˆ์ฐจ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

@oerdnj ์—…๋ฐ์ดํŠธ๋‚˜ ๋„์›€์ด ํ•„์š”ํ•œ ์‚ฌํ•ญ์ด ์žˆ์œผ์‹ ๊ฐ€์š”?

@pde sphinx-build 1.2.2๋กœ ๋ฌธ์„œ๋ฅผ ์ˆ˜์ •ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ https://launchpadlibrarian.net/301768953/buildlog_ubuntu-trusty-i386.python-certbot-nginx_0.9.3-1+certbot ~trusty+2_BUILDING.txt.gz

๊ทธ๊ฒƒ์€ certbot_nginx/nginxparser.py ์˜ ์ฝ”๋“œ ๋ฒ„๊ทธ์ธ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. Sphinx์™€ ์•„๋ฌด ๊ด€๋ จ์ด ์—†์Šต๋‹ˆ๋‹ค(Sphinx๊ฐ€ ๋ฒ„๊ทธ๋กœ ์ธํ•ด ์‹คํŒจํ•˜๋Š” autodoc ๋ชฉ์ ์œผ๋กœ ๋ชจ๋“ˆ์„ ๊ฐ€์ ธ์˜ค๋ ค๋Š” ๊ฒƒ ์™ธ์—๋Š”).

AFAICS์— ๋Œ€ํ•œ ํŒŒ์‹ฑ์€ ์‚ฌ์šฉ์„ ์›ํ•˜๋Š” ... + restOfLine ๋Œ€์‹  ... + restOfLine() .

@mgedmin ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ํŒจํ‚ค์ง€์—์„œ ํŒจ์น˜๋ฅผ ์‹œ๋„ํ•˜๊ณ  https://github.com/certbot/certbot/pull/3989๋กœ ์ œ์ถœํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค.

์ด์ œ PPA์— apache ๋ฐ nginx ํ”Œ๋Ÿฌ๊ทธ์ธ์ด ๋ชจ๋‘ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ์ฐŒ๋ฅด๊ฒŒ ํ•ด์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

@oerdnj์˜ ๋ชจ๋“  ์ž‘์—…์— ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค! PPA๊ฐ€ ์ผ๋ฐ˜ Certbot ์‚ฌ์šฉ์ž์—๊ฒŒ ์ œ์•ˆํ•  ์ˆ˜ ์žˆ๋Š” ์‹œ์ ์ด๋ผ๊ณ  ์ƒ๊ฐํ•˜์‹ญ๋‹ˆ๊นŒ?

@bmw ์ €๋Š” ๊ทธ๋ ‡๊ฒŒ ๋ฏฟ์Šต๋‹ˆ๋‹ค. ๊ธ€์Ž„์š”, ์ €์žฅ์†Œ์— ์—ฌ์ „ํžˆ rundirs ํ•ดํ‚น์ด ์žˆ๋‹ค๋Š” ๋ฌธ์ œ๋ฅผ ์ œ์™ธํ•˜๊ณ ๋Š” ๋†“์•„์ฃผ๊ณ  ์‹ถ์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ๊ธฐ๋Šฅ์ด ์—…์ŠคํŠธ๋ฆผ certbot์— ๋„๋‹ฌํ•˜๋ฉด ์•ˆ์ •์ ์ธ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ ๊ฒฝ๋กœ๋ฅผ ์ค€๋น„ํ•˜๊ฒŒ ๋˜์–ด ๊ธฐ์ฉ๋‹ˆ๋‹ค.

@ordnj ๋„ค! ๋‚˜์ค‘์— PPA๋ฅผ ๋ถ„๊ธฐํ•  ํ•„์š” ์—†์ด rundirs "ํ•ดํ‚น"์— ๋Œ€ํ•ด ๋งˆ์นจ๋‚ด ํ†ตํ•ฉํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค. +1:
@bmw ์—…์ŠคํŠธ๋ฆผ Python ์ ‘๊ทผ ๋ฐฉ์‹์— ๋Œ€ํ•œ ๊ท€ํ•˜์˜ ํ•„์š”์„ฑ์„ ์ดํ•ดํ•  ์ˆ˜ ์žˆ์ง€๋งŒ ์—ฌ๊ธฐ์—์„œ๋Š” ๋ฐ๋น„์•ˆ ํŒจํ‚ค์ง€์— ๊ด€ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค! ;)

์ด ๋ฌธ์ œ๋ฅผ ๊ตฌ๋…ํ•˜๋Š” ์‚ฌ๋žŒ์ด ๋„ˆ๋ฌด ๋งŽ๊ธฐ ๋•Œ๋ฌธ์— ์—ฌ๊ธฐ์— ๋‚ด ์งˆ๋ฌธ์„ ๊ฒŒ์‹œํ•ด์„œ ์ฃ„์†กํ•ฉ๋‹ˆ๋‹ค. ํ•˜์ง€๋งŒ ๋‹ค๋ฅธ ๊ณณ์—์„œ๋Š” ์ข‹์€ ๋‹ต๋ณ€์„ ์ฐพ์ง€ ๋ชปํ•ด ์—ฌ๊ธฐ์— ์˜ฌ๋ฆฝ๋‹ˆ๋‹ค.

์šฐ๋ถ„ํˆฌ 16.04.2
apt install letsencrypt ํŒจํ‚ค์ง€ ์„ค์น˜ :
letsencrypt --version ๋Š” 0.4.1์„ ์ œ๊ณตํ•˜์ง€๋งŒ git ์—์„œ ์„ค์น˜ํ•  ๋•Œ 0.12.0์„ ์–ป์Šต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ Ubuntu๋Š” ์–ธ์ œ ํŒจํ‚ค์ง€๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๊นŒ, ์•„๋‹ˆ๋ฉด 0.4.1 ์ด 0.12.0 ์˜ Ubuntu ๋ฒ„์ „์ž…๋‹ˆ๊นŒ?

Ubuntu๋Š” ๋ฆด๋ฆฌ์Šค๋œ ๋ฒ„์ „์˜ ํŒจํ‚ค์ง€๋ฅผ ์—…๋ฐ์ดํŠธํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค(์‹ฌ๊ฐํ•œ ๋ฒ„๊ทธ๋ฅผ ์ˆ˜์ •ํ•ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ ์ œ์™ธ - ์•ˆ์ •์ ์ธ ๋ฆด๋ฆฌ์Šค ์—…๋ฐ์ดํŠธ ์ •์ฑ… ์ฐธ์กฐ ).

Ubuntu๋Š” SRU ํ”„๋กœ์„ธ์Šค๋ฅผ ์ง„ํ–‰ํ•  ๋•Œ 16.04์šฉ ํŒจํ‚ค์ง€๋ฅผ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค. Ubuntu ํŒจํ‚ค์ง€๋Š” git repo์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

PPA๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด ๋” ๋‚˜์€ ๊ฒฝ์šฐ apt-get install letsencrypt ๋Š” ์ตœ์‹  ํŒจํ‚ค์ง€ ๋ฒ„์ „์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

์ตœ์‹  git ๋ฒ„์ „์„ ์›ํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ์—๋Š” ์ˆ˜ํ–‰ํ•œ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜์‹ญ์‹œ์˜ค.

@jonathonf ์ด ๋ฌธ์ œ์— PPA๋ฅผ ์„ค์น˜ํ–ˆ์ง€๋งŒ ์ฐจ์ด๋Š” ์—†์Šต๋‹ˆ๋‹ค. :/

๋‹น์‹ ์ด ํ•˜์ง€ ์•Š์•˜๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ;)

์ด๊ฒƒ์„ ์‹œ๋„ํ•˜์‹ญ์‹œ์˜ค: https://launchpad.net/~certbot/+archive/ubuntu/certbot

@jonathonf ๊ต‰์žฅํ•ฉ๋‹ˆ๋‹ค! ๊ทธ๊ฒƒ์„ ๋†“์ณค๋‹ค.

๊ทธ๋Ÿผ ์ด๊ฒŒ ์œ ์ง€๋ ๊นŒ์š”? ๋‚˜๋Š” ๊ทธ๊ฒƒ์ด "๋ฐ˜๊ณต์‹์ "์ธ ๊ฒƒ์„ ์•Œ์•˜๋‹ค. ๋˜ํ•œ ํ•„์š”ํ•œ ๋ชจ๋“  ์ข…์†์„ฑ์„ ์„ค์น˜ํ•ฉ๋‹ˆ๊นŒ? Git ๋ฒ„์ „์ด ๋” ๋งŽ์€ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค ...

์•ˆ๋…•ํ•˜์„ธ์š”, ์ธ์šฉ๋œ PPA https://launchpad.net/~certbot/+archive/ubuntu/certbot๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?
?

์•ˆ์ „ํ•˜๊ณ  ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ ์—…๋ฐ์ดํŠธ๋˜์—ˆ์Šต๋‹ˆ๊นŒ?

๋ชจ๋“  PPA์— ๊ด€ํ•ด์„œ๋Š” ์ด๊ฒƒ์ด ๊ท€ํ•˜์˜ ์š”์ฒญ์ž…๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ @oerdnj ๋Š” ๋ฐ๋น„์•ˆ ํŒจํ‚ค์ €์ด๋ฉฐ ์ด๋ฏธ ๋‹ค๋ฅธ Ubuntu์šฉ PPA(์˜ˆ: ๊ทธ์˜ ๋งค์šฐ ์œ ์šฉํ•œ PHP PPA)์—์„œ ์—„์ฒญ๋‚˜๊ฒŒ ๋งŽ์€ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๊ทธ๋ฅผ ๋ฏฟ์œผ๋ฉด ๊ทธ์˜ PPA๋ฅผ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Git ๋ฒ„์ „์ด ๋” ๋งŽ์€ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค ...

git ๋ฒ„์ „์€ Python virtualenv๋ฅผ ์„ค์ •ํ•˜์—ฌ ์†Œํ”„ํŠธ์›จ์–ด๋ฅผ ๋นŒ๋“œํ•˜๊ณ  ์—ฐ๊ฒฐ๋œ ๋ชจ๋“  ์ข…์†์„ฑ์„ ๋กœ์ปฌ์— ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค. PPA๋Š” ๋’ค์—์„œ ์ด ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•˜๋ฏ€๋กœ ์ตœ์ข… ๊ฒฐ๊ณผ ํŒจํ‚ค์ง€๊ฐ€ ๋” ์ ์Šต๋‹ˆ๋‹ค.

์ด PPA ๋Š” ์‚ฌ์šฉํ•  ์ค€๋น„๊ฐ€ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค! certbot-auto ๋˜๋Š” ํ˜„์žฌ Ubuntu ํŒจํ‚ค์ง€(certbot/website#198 ์ฐธ์กฐ)๋ฅผ ํ†ตํ•ด ์‚ฌ์šฉํ•˜๋„๋ก ์‚ฌ๋žŒ๋“ค์—๊ฒŒ ์•Œ๋ฆฌ๊ธฐ ์œ„ํ•ด certbot.eff.org๋ฅผ ์—…๋ฐ์ดํŠธํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋งˆ์นจ๋‚ด ์ด ๋ฌธ์ œ๋ฅผ ์ข…๋ฃŒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

@hlieberman , @oerdnj : PPA ์ œ๋ชฉ์—์„œ "(

PPA๋ฅผ ์–ป๊ธฐ์˜ ์–ด๋–ค ๊ธฐํšŒ๋กœ ๋ณ€๊ฒฝ ppa ์‚ฌ๋žŒ๋“ค์ด ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก sudo add-apt-repository ppa:certbot ๋Œ€์‹  sudo add-apt-repository ppa:certbot/certbot ? ์ด๊ฒƒ์€ ์ด ์ฃผ์„์—์„œ ์–ธ๊ธ‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค: https://github.com/certbot/certbot/issues/1706#issuecomment -260585028

PPA๋Š” ์–ธ์ œ ์—…๋ฐ์ดํŠธ๋ฉ๋‹ˆ๊นŒ? ๋ฒ„์ „ 12๊ฐ€ 13์ผ ๋™์•ˆ ๋‚˜์™”์Šต๋‹ˆ๋‹ค.

๋‚˜๋Š” ๋‹น์‹ ์ด ppa์— ๋Œ€ํ•œ ์ ‘๋‘์‚ฌ๊ฐ€ ํ•„์š”ํ•˜๋‹ค๊ณ  ํ™•์‹ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ ๊ทธ๊ฒƒ์ด ์†ํ•œ ์‚ฌ์šฉ์ž์™€ repo๋„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด ์„ ํƒํ•ด์•ผ ํ•  ์‚ฌ์šฉ์ž ์ด๋ฆ„์˜ repo๋ฅผ ์•Œ์ง€ ๋ชปํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‚ด๊ฐ€ ํ‹€๋ฆด ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ์‚ฌ๋žŒ์ด ๋ชจ๋“  ppa ์ค‘์—์„œ ์ ‘๋‘์‚ฌ๋งŒ ์žˆ์œผ๋ฉด ์‚ฌ์šฉํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค.

๋‚ด iPhone์—์„œ ๋ณด๋‚ธ

2017๋…„ 3์›” 15์ผ ์˜คํ›„ 5์‹œ 18๋ถ„์— Geoffrey Fairchild [email protected]์ด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ผ์Šต๋‹ˆ๋‹ค.

@elyscape ์˜ ์ œ์•ˆ์ด ๋งˆ์Œ์—

โ€”
๋‹น์‹ ์ด ์–ธ๊ธ‰๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด๊ฒƒ์„ ๋ฐ›๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
์ด ์ด๋ฉ”์ผ์— ์ง์ ‘ ๋‹ต์žฅํ•˜๊ฑฐ๋‚˜ GitHub์—์„œ ๋ณด๊ฑฐ๋‚˜ ์Šค๋ ˆ๋“œ๋ฅผ ์Œ์†Œ๊ฑฐํ•˜์„ธ์š”.

@elyscape ๊ทธ๊ฒƒ์€ ์ด๋ฏธ ppa๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š” ๋ชจ๋“  ์‚ฌ๋žŒ๋“ค์ด ๋ฏธํ•™์„ ์œ„ํ•ด ๊ตฌ์„ฑ์„ ๋ณ€๊ฒฝํ•˜๋„๋ก ๊ฐ•์ œํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

@chrismccoy , ppa ๋Š” PPA์— ๋Œ€ํ•ด ์‚ฌ์šฉ์ž๋งŒ ์ง€์ •ํ•˜๋Š” ๊ฒฝ์šฐ ๊ฐ€์ •๋œ ์ €์žฅ์†Œ์ž…๋‹ˆ๋‹ค.

user@ubuntu-device:~$ sudo add-apt-repository ppa:certbot
Cannot add PPA: 'ppa:~certbot/ubuntu/ppa'.
The team named '~certbot' has no PPA named 'ubuntu/ppa'
Please choose from the following available PPAs:
 * 'certbot':  Certbot PPA (semi-official)
 * 'certbot-build':  Certbot Build PPA (don't use this, use ppa:certbot/certbot)

์ด ๊ธ€์„ ์“ฐ๊ณ  ์žˆ๋Š” ๋™์•ˆ @oerdnj๊ฐ€ ๋‹ต์žฅ์„ ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด์ œ ์š”์ ์€

@elyscape๊ฐ€ ๋งํ–ˆ๋“ฏ์ด ๋‹จ์ถ•๋œ apt-add-repository ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์—ฌ 'ppa'๋ผ๋Š” ์ด๋ฆ„์˜ PPA๋ฅผ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์ง€๋งŒ ์ด๊ฒƒ์€ ์ด ์‹œ์ ์—์„œ ์‹ค์ œ๋กœ๋Š” ๊ทธ๋ƒฅ ๋ฐ”์ดํฌ ์…ฐ๋”ฉ( bike-shedding)์ž…๋‹ˆ๋‹ค. certbot ํ”„๋กœ์ ํŠธ๋ฅผ ์œ„ํ•œ certbot PPA์ด๋ฉฐ ์ถ”๊ฐ€๋กœ 9๊ฐœ์˜ ๋ฌธ์ž๋Š” ๊ฑฐ์˜ ๋ถ€๋‹ด๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์—…๋ฐ์ดํŠธ ์ธก๋ฉด์—์„œ 0.12๋Š” ์•„์ง ๋ฐ๋น„์•ˆ์— ์ƒ๋ฅ™ํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค(์‹ฌ์ง€์–ด sid๋‚˜ ์‹คํ—˜์ ์ด์ง€ ์•Š์Œ). ์ ์ ˆํ•˜๊ฒŒ ๋žญ๊ธ€๋ง๋˜๊ณ  ๋‚˜๋ฉด PPA๋กœ ์ด๋™ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ Debian Let's Encrypt Team์—์„œ ์ค€๋น„ํ•˜๊ณ  Ubuntu์šฉ์œผ๋กœ ๋ฐฑํฌํŠธ๋œ ํŒจํ‚ค์ง€์šฉ PPA์ž…๋‹ˆ๋‹ค.

ํ…Œ์ŠคํŠธ๋˜๊ณ  ์ž‘๋™ํ•˜๋Š” ํŒจํ‚ค์ง€๋ฅผ ๋ฐฐํฌํ•˜๊ธฐ๋ฅผ ์›ํ•œ๋‹ค๊ณ  ๊ฐ€์ •ํ•ฉ๋‹ˆ๊นŒ? :)

--ํŽธ์ง‘ํ•˜๋‹ค
ํƒ€์ดํ•‘ํ•˜๋Š” ๋™์•ˆ ๋‘ ๊ฐ€์ง€ ๋‹ค๋ฅธ ์—…๋ฐ์ดํŠธ๊ฐ€... ํ, ์–ด์จŒ๋“  ๊ฒŒ์‹œ ์ค‘์ž…๋‹ˆ๋‹ค. :NS

@enoch85 ๊ณ ์žฅ๋‚œ๊ฒŒ ์žˆ๋‚˜์š”? #4233์ด ๋ฌธ์ œ์ง€๋งŒ ๊ทธ๊ฒŒ ๋‹ค์•ผ.

๋‚˜๋Š” ๋ณดํ†ต @hlieberman ์›Œํฌํ”Œ๋กœ๋ฅผ ๋”ฐ๋ฅด๊ณ  ๊ทธ๋Š” ์•„์ง ๋ฐ๋น„์•ˆ ํŒจํ‚ค์ง€๋ฅผ ์—…๋ฐ์ดํŠธํ•  ์‹œ๊ฐ„์ด ์—†์—ˆ๊ณ  ๊ทธ์˜

์ด๊ฒƒ์ด ์ด PPA๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋” ๋งŽ์€ ์‚ฌ๋žŒ๋“ค์—๊ฒŒ ๋ฌธ์ œ๋ฅผ ์ค€๋‹ค๋ฉด #4243์—์„œ 0.11.1 ์œ„์— ์žˆ๋Š” ํŒจ์น˜๋ฅผ ๊ฐ€์ ธ์˜ฌ ์ˆ˜ ์žˆ์ง€๋งŒ ์ €๋Š” ์ด "์ƒˆ ๋ฒ„์ „์„ ์œ„ํ•œ ์ƒˆ ๋ฒ„์ „" ์„ธ๊ณ„๊ด€์„ ์‹ค์ œ๋กœ ๋”ฐ๋ฅด์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

@bmw "(

@oerdnj ์•„๋‹ˆ์š”, ์•„์ง๊นŒ์ง€๋Š” ์•„๋‹ˆ์ง€๋งŒ ๊ณง git ๋ฒ„์ „์ด 12์ธ ์ด PPA๋กœ ๋ณ€ํ™˜ํ•˜๊ณ  12๋กœ ์ƒ์„ฑ๋œ ์ธ์ฆ์„œ์— ๋Œ€ํ•œ ๊ฒฝ๊ณ ๋ฅผ ๋ฐ›์Šต๋‹ˆ๋‹ค. ์—…๋ฐ์ดํŠธ๊ฐ€ ์žˆ์œผ๋ฉด ์ข‹์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ์–ธ์ œ๋‚˜์ฒ˜๋Ÿผ, ๋‹น์‹ ์€ ํ”๋“ค๋ฆฝ๋‹ˆ๋‹ค!

๋Ÿฐ์น˜ํŒจ๋“œ ์œ ์ง€ ๊ด€๋ฆฌ์ž๋กœ๋ถ€ํ„ฐ ์—…๋ฐ์ดํŠธ๋ฅผ ๋ฐ›๋Š” ๋ฐ ์ผ๋ฐ˜์ ์œผ๋กœ ์–ผ๋งˆ๋‚˜ ๊ฑธ๋ฆฌ๋‚˜์š”? ๋Ÿฐ์น˜ํŒจ๋“œ์˜ certbot/certbot์€ 0.11.1์ด๊ณ  0.12๋Š” github.com์— ์žˆ์Šต๋‹ˆ๋‹ค.

@chrismccoy PPA ๊ด€๋ฆฌ์ž๊ฐ€ ์ž‘์„ฑํ•œ ๋Œ“๊ธ€ 3๊ฐœ๋ฅผ ๋‹ค์‹œ ์ฝ์œผ์‹ญ์‹œ์˜ค(์˜ˆ: https://github.com/certbot/certbot/issues/1706#issuecomment -286890691).

@oerdnj ํŠนํžˆ #4233 ๋•Œ๋ฌธ์— ์—ฌ๊ธฐ๊นŒ์ง€ ์™”์Šต๋‹ˆ๋‹ค. ์ €๋Š” ํ•œ ์‚ฌ๋žŒ์ผ ๋ฟ์ด๊ณ  ์ด๊ฒƒ์€ ๋‹จ์ˆœํ•œ ๊ฐœ์ธ ํ”„๋กœ์ ํŠธ์˜€์ง€๋งŒ 0.12 ๋ฆด๋ฆฌ์Šค๋ฅผ ๊ธฐ๋Œ€ํ•ฉ๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ์˜ PPA์—์„œ Certbot 12๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ƒˆ ์ธ์ฆ์„œ๋ฅผ ์„ค์น˜ํ•˜๋ ค๊ณ  ํ•  ๋•Œ ์ด๊ฒƒ์„ ์–ป์Šต๋‹ˆ๋‹ค. Let's Encrypt ๋ฒ„๊ทธ์ธ์ง€ PPA ๊ด€๋ จ ๋ฌธ์ œ์ธ์ง€ ๋ชจ๋ฅด๊ฒ ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ์—ฌ๊ธฐ์— ๋ณด๊ณ ํ–ˆ์Šต๋‹ˆ๋‹ค: https://community.letsencrypt.org/t/ubuntu-14-04-with-certbot-auto-failing-tls-sni-challenge-with-apache/33439/2

tls-sni-01 challenge for cloud.domin.com
/usr/lib/python2.7/dist-packages/OpenSSL/rand.py:58: UserWarning: implicit cast from 'char *' to a different pointer type: will be forbidden in the future (check that the types are as you expect; use an explicit ffi.cast() if they are correct)
  result_code = _lib.RAND_bytes(result_buffer, num_bytes)
Waiting for verification...

๋‚ด ์ธ์ฆ์„œ๊ฐ€ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ƒ์„ฑ๋˜์—ˆ์ง€๋งŒ ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ํŒŒ์ด์ฌ ๊ฒฝ๊ณ  ๋ฉ”์‹œ์ง€๋ฅผ ์กฐ์‚ฌํ•ด์•ผ ํ•œ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

@oerdnj ๊ท€์ฐฎ๊ฒŒ ํ•ด์„œ ์ฃ„์†กํ•˜์ง€๋งŒ ์ƒˆ ๋ฒ„์ „์˜ ํŒจํ‚ค์ง•์„ ๋”ฐ๋ฅผ ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๊นŒ? ์ฆ‰, ์ƒˆ ํŒจํ‚ค์ง€๊ฐ€ ์ค€๋น„๋ /์ค€๋น„๋  ์ˆ˜ ์žˆ์„ ๋•Œ.

Cloudflare ๋ฐ DNS ์ธ์ฆ์„ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆ์„œ๋ฅผ ์ž๋™ ๊ฐฑ์‹ ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ƒˆ ํŒจํ‚ค์ง€(v0.14.x)๋ฅผ ๊ธฐ๋‹ค๋ฆฌ๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

@shaneog "์ง€๊ธˆ์€ ์ž์œ  ์‹œ๊ฐ„"์ด๋ฏ€๋กœ ๊ณ„ํš์ด ์—†์Šต๋‹ˆ๋‹ค(์‹ฌ๊ฐํ•œ ๋ฒ„๊ทธ๊ฐ€ ์—†๋Š” ํ•œ). ํ•˜์ง€๋งŒ 0.14.1๋กœ์˜ ์—…๋ฐ์ดํŠธ๋Š” ๊ฐ„๋‹จํ•œ ์—…๋ฐ์ดํŠธ์ธ ๊ฒƒ ๊ฐ™์•„์„œ ์ง€๊ธˆ ๋ฐ”๋กœ ๋นŒ๋“œ๋ฅผ ์—…๋กœ๋“œํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.

๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค!

PPA์—์„œ ์„ค์น˜ํ•˜์—ฌ ๋งŒ๋“  crontab์—๋Š” ๋” ์ด์ƒ /bin/run-parts ๋น„ํŠธ๊ฐ€ ํฌํ•จ๋˜์ง€ ์•Š์œผ๋ฏ€๋กœ ๊ฐฑ์‹  ํ›„ํฌ๋ฅผ ์ง€์ •ํ•˜๋Š” ๊ถŒ์žฅ ๋ฐฉ๋ฒ•์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

์ง€๊ธˆ์€ /etc/cron.d/certbot ์Šคํฌ๋ฆฝํŠธ๋ฅผ @oerdnj ๊ฐ€ ๋ช‡ ๋‹ฌ ์ „์— ์žˆ๋˜

0 */12 * * * root test -x /usr/bin/certbot -a \! -d /run/systemd/system && perl -e 'sleep int(rand(3600))' && certbot -q renew --pre-hook '/bin/run-parts /etc/letsencrypt/pre-hook.d/' --post-hook '/bin/run-parts /etc/letsencrypt/post-hook.d/' --renew-hook '/bin/run-parts /etc/letsencrypt/renew-hook.d/'

...๊ทธ๋ฆฌ๊ณ  ๋‚ด ํ›„ํฌ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ•ด๋‹น ๋””๋ ‰ํ† ๋ฆฌ์— ๋„ฃ์Šต๋‹ˆ๋‹ค. ์ด ๋ฌธ์ œ์— ๋Œ€ํ•ด ๋” ๋‚˜์€ ๋ฐฉ๋ฒ•์ด ์žˆ์Šต๋‹ˆ๊นŒ?

๋‹ฌ์„ฑํ•˜๊ณ ์ž ํ•˜๋Š” ๋ฐ”์— ๋”ฐ๋ผ ๋‹ค๋ฆ…๋‹ˆ๋‹ค. ๋‘ ๊ฐ€์ง€ ์ฃผ์š” ์˜ต์…˜์ด ์žˆ์ง€๋งŒ ์ด ๊ฒŒ์‹œ๋ฌผ ํ•˜๋‹จ์— ์žˆ๋Š” ๊ฒฝ๊ณ  ๋ฅผ

์ „์—ญ ๊ตฌ์„ฑ ํŒŒ์ผ

Certbot์˜ ๊ตฌ์„ฑ ํŒŒ์ผ์— ํ›„ํฌ๋ฅผ ํฌํ•จํ•˜๋ฉด run-parts ์†”๋ฃจ์…˜๊ณผ ์œ ์‚ฌํ•œ ๋™์ž‘์„ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. /etc/letsencrypt/cli.ini ์žˆ๋Š” ํŒŒ์ผ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

pre-hook = /bin/run-parts /etc/letsencrypt/pre-hook.d/
post-hook = /bin/run-parts /etc/letsencrypt/post-hook.d/
renew-hook = /bin/run-parts /etc/letsencrypt/renew-hook.d/

์ด๊ฒƒ๊ณผ ์ด์ „ crontab ์‚ฌ์ด์˜ ์œ ์ผํ•œ ๋™์ž‘ ์ฐจ์ด์ ์€ certbot certonly , certbot run , certbot (ํ•˜์œ„ ๋ช…๋ น ์—†์Œ)์™€ ๊ฐ™์€ ๋‹ค๋ฅธ Certbot ํ•˜์œ„ ๋ช…๋ น์œผ๋กœ ์ธ์ฆ์„œ๋ฅผ ์–ป์„ ๋•Œ๋„ ์ด๋Ÿฌํ•œ ํ›„ํฌ๊ฐ€ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. ) ๋“ฑ. ์‚ฌ์ „ ๋ฐ ์‚ฌํ›„ ํ›„ํฌ๋Š” ์ธ์ฆ์„œ๋ฅผ ์–ป์€ ๊ฒฝ์šฐ ํ•ญ์ƒ ์‹คํ–‰๋˜๋Š” ๋ฐ˜๋ฉด, ๊ฐฑ์‹  ํ›„ํฌ๋Š” ๊ธฐ์กด ๊ฒฝ๋กœ์—์„œ ์ธ์ฆ์„œ๋ฅผ ๊ฐฑ์‹ ํ•˜๋Š” ๊ฒฝ์šฐ์—๋งŒ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค.

์ธ์ฆ์„œ ๊ตฌ์„ฑ ํŒŒ์ผ

๋˜ ๋‹ค๋ฅธ ์˜ต์…˜์€ ์ธ์ฆ์„œ๋ณ„๋กœ ํ›„ํฌ๋ฅผ ์ •์˜ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์ธ์ฆ์„œ์— ๋”ฐ๋ผ ๋‹ค๋ฅธ ํ›„ํฌ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ธ์ฆ์„œ๋ฅผ ์–ป์„ ๋•Œ ํ•ด๋‹น ์ธ์ฆ์„œ๋ฅผ ์–ป๋Š” ๋ฐ ์‚ฌ์šฉํ•œ ํ›„ํฌ๋Š” /etc/letsencrypt/renewal/domain.conf ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. certbot renew ์‹คํ–‰ํ•˜๋ฉด ์ธ์ฆ์„œ๊ฐ€ ๊ฐฑ์‹ ๋  ๋•Œ ์ด๋Ÿฌํ•œ ํ›„ํฌ๊ฐ€ ์ž๋™์œผ๋กœ ๋‹ค์‹œ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. ์œ„์— ํฌํ•จ๋œ ๊ฒƒ๊ณผ ๋™์ผํ•œ ๊ตฌ๋ฌธ์„ ์‚ฌ์šฉํ•˜์—ฌ [renewalparams] ์„น์…˜ ํ—ค๋” ์•„๋ž˜์— ํ›„ํฌ๋ฅผ ๋ฐฐ์น˜ํ•˜์—ฌ ์ด๋Ÿฌํ•œ ํŒŒ์ผ์„ ์ˆ˜๋™์œผ๋กœ ํŽธ์ง‘ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ฒฝ๊ณ 

  1. ์ด ๋‘ ์˜ต์…˜์€ ํ˜ธํ™˜๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ „์—ญ ๊ตฌ์„ฑ ํŒŒ์ผ์— ๋ฐฐ์น˜๋œ ํ›„ํฌ๋Š” ์ธ์ฆ์„œ์— ๋Œ€ํ•œ ๊ตฌ์„ฑ ํŒŒ์ผ์— ์žˆ๋Š” ๊ฐ’์„ ์žฌ์ •์˜ํ•˜๋Š” ๋ช…๋ น์ค„์— ํฌํ•จ๋œ ๊ฒƒ๊ณผ ๋™์ผํ•˜๊ฒŒ ์ฒ˜๋ฆฌ๋ฉ๋‹ˆ๋‹ค.
  2. ์–ด๋–ค ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•˜๋“  ํŒŒ์ผ์„ ํŽธ์ง‘ํ•œ ํ›„ certbot renew --dry-run ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ๋ชจ๋“  ๊ฒƒ์ด ์—ฌ์ „ํžˆ ์ œ๋Œ€๋กœ ์ž‘๋™ํ•˜๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค.

์™„๋ฒฝํ•ฉ๋‹ˆ๋‹ค. ์ „์—ญ ๊ตฌ์„ฑ ํŒŒ์ผ์ด ์ •ํ™•ํžˆ ์ œ๊ฐ€ ํ•„์š”๋กœ ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค!

๊ทธ๋ ‡๋‹ค๋ฉด ๊ฐฑ์‹  ํ›„ํฌ์˜ ์‹ค์ œ ์ƒํƒœ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ? ์ด๊ฒŒ ์–ด๋–ป๊ฒŒ ์ด๋ ‡๊ฒŒ ์—‰๋ง์ด ๋˜์—ˆ๋Š”์ง€ ์ด์ƒํ•ฉ๋‹ˆ๋‹ค. ์ฒ˜์Œ์—๋Š” cronjob์ด ๋‹ค๋ฅธ ๋””๋ ‰ํ† ๋ฆฌ์˜ ๋ถ€ํ’ˆ์„ ํ˜ธ์ถœํ•œ ๋‹ค์Œ cli ํŒŒ์ผ์„ ํ˜ธ์ถœํ–ˆ์œผ๋ฉฐ ์ด์ œ cli๊ฐ€ ๋” ์ด์ƒ ์ •๋ณด๋ฅผ ๋ณด์œ ํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ์ƒˆ๋กœ ์„ค์น˜ํ•˜๋ฉด ๋””๋ ‰ํ† ๋ฆฌ๋งŒ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
certbot dev ๋ฆฌ๋“œ์˜ ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ๊ตฌ์„ฑ ํŒŒ์ผ์— ์ง€์นจ๊ณผ ํ•จ๊ป˜ ๋ช…ํ™•ํ•œ ์˜๊ฒฌ์„ ์ œ์‹œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์–ผ๋งˆ๋‚˜ ์–ด๋ ค์šธ ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์˜ˆ๋ฅผ ๋“ค์–ด CSF/LFD์— ๋Œ€ํ•ด ์–ด๋–ป๊ฒŒ ํ–ˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค: https://gist.github.com/skt-bford/4987434

๋‚˜๋Š” ๊ทธ๊ฒƒ์ด ๋งค์šฐ ํ˜ผ๋ž€์Šค๋Ÿฝ๊ณ  ์ด๊ฒƒ์— ๋Œ€ํ•ด ์ถฉ๋Œํ•˜๊ฑฐ๋‚˜ ์˜ค๋ž˜๋œ ์ •๋ณด๊ฐ€ ๋งŽ๋‹ค๋Š” ๋ฐ ๋™์˜ํ•ฉ๋‹ˆ๋‹ค. ๋‚ด ์ดํ•ด๋Š” ํ˜„์žฌ ๋ชจ๋ฒ” ์‚ฌ๋ก€๋Š” certbot ๋ช…๋ น์ค„์„ ์‚ฌ์šฉํ•˜์—ฌ --deploy-hook ( --renew-hook ๋ณด๋‹ค ๋‚ซ์Œ )๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ด๋ฉฐ ํ›„ํฌ ์ •๋ณด๋ฅผ ๋„๋ฉ”์ธ์— ์ €์žฅํ•˜๋Š” /etc /letsencrypt/newal, ๋”ฐ๋ผ์„œ ํ›„ํฌ๋Š” ๋งค๋ฒˆ ์ž๋™์œผ๋กœ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. /etc/letsencrypt/cli.ini๋ฅผ ์ง์ ‘ ํŽธ์ง‘ํ•˜๋Š” ๊ฒƒ๋ณด๋‹ค ์„ ํ˜ธํ•˜๋Š” ์†”๋ฃจ์…˜์œผ๋กœ ๊ฐ„์ฃผ๋˜๋ฉฐ ๋‹ค๋ฅธ ์ธ์ฆ์„œ์— ๋Œ€ํ•ด ๋‹ค๋ฅธ ํ›„ํฌ๋ฅผ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋‹ค๋Š” ์žฅ์ ๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ ๋‚ด๊ฐ€ ์ฐพ์€ ์ตœ๊ณ ์˜ ์ •๋ณด์ž…๋‹ˆ๋‹ค. https://community.letsencrypt.org/t/certbot-dovecot-postfix-certificate-renewal-issue/72226/11

๋‚˜๋Š” ๊ทธ๊ฒƒ์ด ๋งค์šฐ ํ˜ผ๋ž€์Šค๋Ÿฝ๊ณ  ์ด๊ฒƒ์— ๋Œ€ํ•ด ์ถฉ๋Œํ•˜๊ฑฐ๋‚˜ ์˜ค๋ž˜๋œ ์ •๋ณด๊ฐ€ ๋งŽ๋‹ค๋Š” ๋ฐ ๋™์˜ํ•ฉ๋‹ˆ๋‹ค.

์˜ˆ, ํ˜ผ๋ž€์Šค๋Ÿฝ์Šต๋‹ˆ๋‹ค(!)... ํ•˜์ง€๋งŒ ๊ท€ํ•˜์˜ ๋งํฌ๋„ ํ˜ผ๋ž€์Šค๋Ÿฝ๊ณ  ๊ทธ ๋‚ด์šฉ์ด ์‹ ๋ขฐํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค....

์•ˆ๋…•ํ•˜์„ธ์š”, ์ „๋ฌธ๊ฐ€ ์ค‘ ์ผ๋ถ€๊ฐ€ ์ •๋ฆฌํ•˜๊ณ  ์š”์•ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? "2020๋…„์— ๋Œ€ํ•œ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์š”์•ฝ"์„ ํ‘œํ˜„ํ•˜์‹ญ์‹œ์˜ค .

๊ธ€์Ž„์š”, ์ด๋ฒˆ ํ˜ธ์˜ ์ œ๋ชฉ์ธ "PPA for UBUNTU"์— ๋Œ€ํ•ด ์š”์•ฝ์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์™„๋ฒฝํ•ด ๋ณด์ž…๋‹ˆ๋‹ค!
https://certbot.eff.org/lets-encrypt/ubuntubionic-nginx

@oerdnj ์š”์ฆ˜ ์ €์žฅ์†Œ์—์„œ ์—…๋ฐ์ดํŠธ๋œ certbot + dns ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ์–ป๋Š” ๋ฐ ํ•„์š”ํ•œ ๊ฒƒ์ด ๋ฌด์—‡์ธ์ง€ ๊ถ๊ธˆํ–ˆ์Šต๋‹ˆ๋‹ค. ํŠนํžˆ certbot 1.2๊ฐ€ ์ œํ•œ๋œ ๋ฒ”์œ„์˜ Cloudflare DNS-01 ํ† ํฐ์— ๋Œ€ํ•œ ์ง€์›์„ ์ถ”๊ฐ€ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ „์—ญ API ํ‚ค๊ฐ€ ํ•„์š”ํ•œ ์ด์ „ ๋ฐฉ์‹์— ๋น„ํ•ด ๋ณด์•ˆ์ด ํฌ๊ฒŒ ํ–ฅ์ƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

https://github.com/certbot/certbot/milestone/81?closed=1

๊ทธ๋ ‡๋‹ค๋ฉด ๊ฐฑ์‹  ํ›„ํฌ์˜ ์‹ค์ œ ์ƒํƒœ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

๊ทธ๊ฑธ ๋…ผํ•  ๋ฌธ์ œ๊ฐ€ ์•„๋‹ˆ๋ผ๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ์ด _๋‹ซํžŒ_ ๋ฌธ์ œ๋Š” certbot ๋„๊ตฌ๋ฅผ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•œ ์ ์ ˆํ•œ ์ €์žฅ์†Œ์— ๊ด€ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด๋Š” ๊ท€ํ•˜์˜ ์ฟผ๋ฆฌ์™€ ์ „ํ˜€ ๊ด€๋ จ์ด ์—†๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ž…๋‹ˆ๋‹ค.

๊ทธ๋ ‡๋‹ค๋ฉด ๊ฐฑ์‹  ํ›„ํฌ์˜ ์‹ค์ œ ์ƒํƒœ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

๊ทธ๊ฑธ ๋…ผํ•  ๋ฌธ์ œ๊ฐ€ ์•„๋‹ˆ๋ผ๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค. ์ด _๋‹ซํžŒ_ ๋ฌธ์ œ๋Š” certbot ๋„๊ตฌ๋ฅผ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•œ ์ ์ ˆํ•œ ์ €์žฅ์†Œ์— ๊ด€ํ•œ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด๋Š” ๊ท€ํ•˜์˜ ์ฟผ๋ฆฌ์™€ ์ „ํ˜€ ๊ด€๋ จ์ด ์—†๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ž…๋‹ˆ๋‹ค.

๊ธ€์Ž„, ๋‚˜๋Š” ๊ทธ๊ฒƒ์— ๋Œ€ํ•œ ๋Œ€๋‹ต์ด ์‹ค์ œ๋กœ ๋‚ด ๊ฒฝ์šฐ์—๋Š” ์ž‘๋™ํ•˜์ง€ ์•Š์•˜๊ธฐ ๋•Œ๋ฌธ์— drawcking์ด ์š”์ฒญํ•œ ๊ฒƒ์„ ๊ณ„์†ํ•˜๊ณ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. ์šฐ๋ถ„ํˆฌ LE ํŒจํ‚ค์ง€(์ตœ์‹  ์ƒํƒœ๊ฐ€ ์•„๋‹˜)์™€ ๊ด€๋ จ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰