<p>๋„๋ฉ”์ธ ์ด๋ฆ„์ด ์†Œ๋ฌธ์ž๊ฐ€ ์•„๋‹Œ ๊ฒฝ์šฐ certbot์€ acme-challenge๋ฅผ ์ž˜๋ชป๋œ ๊ตฌ์„ฑ์— ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.</p>

์— ๋งŒ๋“  2019๋…„ 02์›” 17์ผ  ยท  3์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: certbot/certbot

  • ๋ฐ๋น„์•ˆ 9.6
  • OS ํŒจํ‚ค์ง€ ๊ด€๋ฆฌ์ž๋กœ Certbot์„ ์„ค์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • certbot 0.28.0
  • nginx

  • /etc/nginx/conf.d/RussianChurchVancouver.ca.conf ๋‚ด ๊ตฌ์„ฑ์—์ด ํ˜ธ์ŠคํŠธ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

server {
  listen       80;
  server_name  RussianChurchVancouver.ca www.RussianChurchVancouver.ca;
...
  • certbot์„ ์‹คํ–‰ํ–ˆ์ง€๋งŒ certbot์ด ์‹คํŒจํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ธ์ฆ์„œ๊ฐ€ ์ƒ์„ฑ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.
root<strong i="18">@deb96</strong>:/var/www/RussianChurchVancouver.ca/web# certbot -m [email protected] --agree-tos --nginx -d RussianChurchVancouver.ca -d www.RussianChurchVancouver.ca
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator nginx, Installer nginx
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for russianchurchvancouver.ca
http-01 challenge for www.russianchurchvancouver.ca
nginx: [warn] conflicting server name "www.russianchurchvancouver.ca" on 0.0.0.0:80, ignored
nginx: [warn] conflicting server name "russianchurchvancouver.ca" on 0.0.0.0:80, ignored
Waiting for verification...
Cleaning up challenges
Failed authorization procedure. russianchurchvancouver.ca (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://russianchurchvancouver.ca/.well-known/acme-challenge/b4vlj_zIdB4H_a94FlltJWx2JBGBDS_ihAFWrpJSl5U: "<html>\r\n<head><title>404 Not Found</title></head>\r\n<body>\r\n<center><h1>404 Not Found</h1></center>\r\n<hr><center>nginx</center>\r\n", www.russianchurchvancouver.ca (http-01): urn:ietf:params:acme:error:unauthorized :: The client lacks sufficient authorization :: Invalid response from http://www.russianchurchvancouver.ca/.well-known/acme-challenge/B8e0i1p0jhjNtfV1Dd36rlE8eh4K2bpefVvABc6Na48: "<html>\r\n<head><title>404 Not Found</title></head>\r\n<body>\r\n<center><h1>404 Not Found</h1></center>\r\n<hr><center>nginx</center>\r\n"

๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ๋™์•ˆ certbot์ด์ด ๊ตฌ์„ฑ ํŒŒ์ผ์— acme-challenge๋ฅผ ์ถ”๊ฐ€ํ•˜๋Š” ๊ฒƒ์„ ๋ฐœ๊ฒฌํ–ˆ์Šต๋‹ˆ๋‹ค.

Writing nginx conf tree to /etc/nginx/conf.d/default.conf

๊ทธ๊ฒƒ์€ ๋ฒ„๊ทธ์ž…๋‹ˆ๋‹ค. ๊ทธ๋ž˜์„œ ๋กœ๊ทธ์— conflicting server name ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค ( default.conf ์™€ RussianChurchVancouver.ca.conf russianchurchvancouver.ca ๊ฐ€์žˆ์„ ๋•Œ certbot ์ƒ์„ฑ ์ƒํ™ฉ
์ด ํŒŒ์ผ์— acme-challenge๋ฅผ ์ถ”๊ฐ€ ํ•  ๊ฒƒ์œผ๋กœ ์˜ˆ์ƒ๋ฉ๋‹ˆ๋‹ค.

/etc/nginx/conf.d/RussianChurchVancouver.ca.conf

์ด ์‹œ์ ์—์„œ certbot์ด ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ๋„๋ฉ”์ธ์ด ์†Œ๋ฌธ์ž๊ฐ€ ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ทธ๋ ‡๊ฒŒํ•œ๋‹ค๊ณ  ์˜์‹ฌํ•˜๊ธฐ ์‹œ์ž‘ํ–ˆ์Šต๋‹ˆ๋‹ค.
๊ทธ๋ž˜์„œ ์ €๋Š” ๊ทธ๋“ค์„ ์†Œ๋ฌธ์ž๋กœํ–ˆ์Šต๋‹ˆ๋‹ค.

  server_name  russianchurchvancouver.ca www.russianchurchvancouver.ca;

certbot์ด ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ž‘๋™ํ–ˆ์Šต๋‹ˆ๋‹ค.

root<strong i="37">@deb96</strong>:/etc/nginx/conf.d# certbot -m [email protected] --agree-tos --nginx -d russianchurchvancouver.ca,www.russianchurchvancouver.ca
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator nginx, Installer nginx
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for www.russianchurchvancouver.ca
http-01 challenge for russianchurchvancouver.ca
Waiting for verification...
Cleaning up challenges
Deploying Certificate to VirtualHost /etc/nginx/conf.d/RussianChurchVancouver.ca.conf
Deploying Certificate to VirtualHost /etc/nginx/conf.d/RussianChurchVancouver.ca.conf
...
Congratulations! You have successfully enabled https://russianchurchvancouver.ca
and https://www.russianchurchvancouver.ca
nginx ui / ux bug has pr unplanned

๋ชจ๋“  3 ๋Œ“๊ธ€

์‹ ๊ณ  ํ•ด ์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ๋ฒ„๊ทธ์ž…๋‹ˆ๋‹ค. ๋‹น์‹  ๋ง์ด ๋งž์•„์š”. ์ง€๊ธˆ์˜ ์ˆ˜์ •์€ ์„ค์ • ํŒŒ์ผ์— ์“ฐ์—ฌ์ง„ ๊ฒƒ๊ณผ ์ผ€์ด์Šค๋ฅผ ์ผ์น˜์‹œํ‚ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์ด ๋ฌธ์ œ๊ฐ€ ๊ณต๊ฐœ ๋œ ์ดํ›„๋กœ Certbot์— ๋งŽ์€ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์žˆ์Šต๋‹ˆ๋‹ค. Certbot์˜ ์ตœ์‹  ๋ฒ„์ „์—์„œ ์—ฌ์ „ํžˆ์ด ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ ์˜๊ฒฌ์„ ์ถ”๊ฐ€ํ•˜์—ฌ ์•Œ๋ ค์ฃผ์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ? ์ด๋ฅผ ํ†ตํ•ด ์‚ฌ์šฉ์ž์—๊ฒŒ ์—ฌ์ „ํžˆ ์˜ํ–ฅ์„ ๋ฏธ์น˜๋Š” ๋ฌธ์ œ๋ฅผ ๋” ์ž˜ ํŒŒ์•…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ–ฅํ›„ 30 ์ผ ๋™์•ˆ ํ™œ๋™์ด ์—†์œผ๋ฉด์ด ๋ฌธ์ œ๋Š” ์ž๋™์œผ๋กœ ์ข…๊ฒฐ๋ฉ๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ ์—ฌ์ „ํžˆ โ€‹โ€‹๋ฒ„๊ทธ์ž…๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰