Upgrade to Pro — share decks privately, control downloads, hide ads and more …

入門Let's Encrypt

Hirokazu Sugiuchi
January 15, 2016
2.3k

入門Let's Encrypt

2016/01/15に社内勉強会で使用した資料です。内容の補足記事はこちら http://tech.feedforce.jp/study-letsencrypt.html

Hirokazu Sugiuchi

January 15, 2016
Tweet

Transcript

  1. SSL

  2. Let’s Encryptͷূ໌ॻ • DV(Domain Validation): υϝΠϯͷॴ༗Λ֬ೝͯ͠ൃߦ • OV(Organization Validation): ૊৫ͷ࣮ࡏͷ֬ೝΛͯ͠ൃߦ

    • EV(Extended Validation): OVΑΓݫີͳ࣮ࡏ֬ೝΛͯ͠ൃߦ • Let's Encrypt͸͜ͷ͏ͪυϝΠϯͷॴ༗Λ֬ೝͯ͠ൃߦ͢Δ
 DV SSLΛൃߦ͢Δ
  3. Let’s Encryptͷূ໌ॻ • DV(Domain Validation): υϝΠϯͷॴ༗Λ֬ೝͯ͠ൃߦ • OV(Organization Validation): ૊৫ͷ࣮ࡏͷ֬ೝΛͯ͠ൃߦ

    • EV(Extended Validation): OVΑΓݫີͳ࣮ࡏ֬ೝΛͯ͠ൃߦ • Let's Encrypt͸͜ͷ͏ͪυϝΠϯͷॴ༗Λ֬ೝͯ͠ൃߦ͢Δ
 DV SSLΛൃߦ͢Δ
  4. εςοϓʹ͢Δͱ͜Μͳײ͡ • 1 ൿີ伴Λ࡞੒ • 2 ൿີ伴ΛݩʹɺCSRʢূ໌ॻΛൃߦ͢ΔͨΊͷॺ໊ཁٻʣΛੜ੒ • 3 ೝূہͷαΠτʹϩάΠϯͯ͠CSRΛϑΥʔϜ͔Βૹ৴

    • 4 ূ໌ॻͷྉۚΛࢧ෷͏(ΫϨδοτΧʔυorۜߦৼࠐ) • 5 ೝূہ͔ΒυϝΠϯॴ༗ऀ΁֬ೝϝʔϧ͕ಧ͘ͷͰঝೝ͢Δ • 6 ೝূہ͔Βূ໌ॻ͕ϝʔϧͳͲͰಧ͘ • 7 ূ໌ॻΛαʔόʹઃఆ
  5. Ҿ༻ݩΑΓ • ᶃ·ͣ͸ɺൿີ伴ͱCSRΛੜ੒͠ɺൿີ伴͸ϩʔΧϧϑΝΠϧʹอଘ͠·͢ɻ • ͜Ε͸ɺΤʔδΣϯτʢΫϥΠΞϯτιϑτ)͕ੜ੒ͯ͠΋͍͍Ͱ͢͠ɺผ్OpenSSLͰ४උͯ͠΋͍Ͱ ͢ɻ • ᶄΤʔδΣϯτ(ΫϥΠΞϯτιϑτ)͸ɺLet'sEncryptͷACMEαʔόʹ઀ଓ͠CSRΛૹΓ·͢ɻ • ᶅACMEαʔό͸ɺnonceͱݺ͹ΕΔೝূ༻ͷ৘ใΛΤʔδΣϯτιϑτʹฦ͠·͢ɻ

    • ᶆΤʔδΣϯτ͸ɺnonce͔Βɺೝূ༻ͷϑΝΠϧΛੜ੒͠ɺhtdocs഑ԼͷಛఆͷσΟϨΫτʹ഑ஔ͠·͢ɻ • ᶇ४උ͕੔ͬͨͱ͜ΖͰɺΤʔδΣϯτ͸ɺACMEαʔόʹʹೝূνϟϨϯδΛཁٻ͠·͢ɻ • ᶈACMEαʔό͸ɺࢦఆͷυϝΠϯʹೝূ༻ͷϑΝΠϧ͕ઃஔ͞Ε͍ͯΔ͔ɺWebαʔό(HTTPD)ʹ֬ೝ͠ʹ ͍͖·͢ɻ • ᶉACMEαʔό͕ɺظ଴ͨ͠௨Γͷೝূ༻ϑΝΠϧΛμ΢ϯϩʔυͰ͖Ε͹ɺαʔόূ໌ॻΛൃߦ͠ɺᶊͰ ΤʔδΣϯτʹૹ෇͠·͢ɻ
  6. letsencrypt-auto • ͪΌΜͱऔಘͰ͖͍ͯΕ͹Լهʹ഑ஔ͞Ε·͢ • /etc/letsencrypt/live/{domain}/ • cert.pem -> ূ໌ॻ •

    chain.pem -> தؒূ໌ॻ • fullchain.pem -> ূ໌ॻͱதؒূ໌ॻΛͭͳ͛ͨ΋ͷ • privkey.pem -> ൿີ伴
  7. ߋ৽͸ʁ • --renew-by-defaultΛ͚ͭͯcronʹ࢓ࠐΉ • ౰વɺߋ৽͞ΕͨλΠϛϯάͰwebαʔόΛreloadͯ͠ূ໌ ॻಡΈ௚͞ͳ͍ͱ͍͚ͳ͍ͷͰ && systemctl reload httpd

    ͷΑ͏ʹ͢Δ • ূ໌ॻͷ༗ޮظؒ͸90೔ʹͳ͍ͬͯΔͷͰ(ηΩϡϦςΟత ͳҙຯ߹͍΍ɺࣗಈߋ৽͕લఏͷͨΊ)1ϲ݄ʹ1ճcronͰ࣮ ߦ͢ΔΑ͏ʹ͢Ε͹OK
  8. ࢀߟϦϯΫ • Let's Encrypt ૯߹ϙʔλϧ • https://letsencrypt.jp/ • Apache 2.4ܥͰHTTP/2αʔόΛߏஙͯ͠ΈΔςετɻ

    • https://http2.try-and-test.net/letsencrypt.html • GoݴޠͰLet's EncryptͷACMEΛཧղ͢Δ • http://deeeet.com/writing/2015/12/01/go-letsencrypt-acme/