WebソスTソス[ソスoソス[ソスヤ通信ソスソスソスeソステ搾ソスソスソス(Apache+mod_SSL)

ソスナ終ソスXソスVソスソスソスF 2020.12.29

ソスソスソスTソスv

ソスソスソス[ソスUソス[ソスソスソスソスpソスXソスソスソス[ソスhソスソスソスフ機ソスソスソスソスソスソスWebソスuソスソスソスEソスUソスソスソスソスソスソスヘゑソスソスソス鼾ソスAソスソスソスソスソスソスソスソス驪ーソス黷ェソスソスソス驍スソス゚、WebソスTソス[ソスoソス[ソスヤの通信ソスソスソスeソスソスソステ搾ソスソスソスソスソスソスソスB
ソスソスソスソスソスナは、WebソスTソス[ソスoソス[ソスソスmod_sslソス導難ソスソスソスソスト、URLソスソスhttp://ソス`ソスナはなゑソスソスAhttps://ソス`ソスナアソスNソスZソスXソスソスソス驍アソスニにゑソスソスソスト、WebソスTソス[ソスoソス[ソスヤの通信ソスソスソスeソスソスソステ搾ソスソスソスソスソスソスソス謔、ソスノゑソスソスソスB
ソスネゑソスソスAWebソスTソス[ソスoソス[ソスニの通信ソスソスソスeソスソスソステ搾ソスソスソスソスソスソスソスノは、ソスTソス[ソスoソス[ソスリ厄ソスソスソスソス発行ソスソスソスソスKソスvソスソスソスソスソス驍ェソスAソスソスソスソスソスナは、ソスソスソスソスTソス[ソスoソス[ソスリ厄ソスソスソスソス発行ソスソスソスト各ソスNソスソスソスCソスAソスソスソスgソスノイソスソスソス|ソス[ソスgソスソスソスソスB
ソスソスソスTソス[ソスoソス[ソスリ厄ソスソスソスソスソスソスeソスNソスソスソスCソスソスソスgソスヨイソスソスソス|ソス[ソスgソスソスソスネゑソスソストゑソスソステ搾ソスソスソスソスハ信ソスヘ行ソスソスソス驍ェソスAソスNソスソスソスCソスAソスソスソスgソスソスソスハ信ソスソスソス驍スソスム(WebソスuソスソスソスEソスUソスNソスソスソスソスソスjソスノセソスLソスソスソスソスソスeソスBソスフ警ソスソスソスソスソス\ソスソスソスソスソスソストゑソスソスワゑソス


ソスソスmod_sslソスCソスソスソスXソスgソス[ソスソス

[root@centos ~]# yum -y install mod_sslソス@ソスソスソス@mod_sslソスCソスソスソスXソスgソス[ソスソス

ソスソスWebソスTソス[ソスoソス[SSLソスン抵ソス

ソスiソスPソスjソスTソス[ソスoソス[ソスpソス髢ァソスソスソスEソスリ厄ソスソスソスソス成
[root@centos ~]# cd /etc/pki/tls/certs/ソス@ソスソスソス@ソスfソスBソスソスソスNソスgソスソスソスレ難ソス

[root@centos certs]# sed -i 's/365/3650/g' Makefileソス@ソスソスソス@ソスTソス[ソスoソス[ソスpソスリ厄ソスソスソスソスLソスソスソスソスソスソスソスソス1ソスNソスソスソスソス10ソスNソスノ変更

[root@centos certs]# make server.crtソス@ソスソスソス@ソスTソス[ソスoソス[ソスpソス髢ァソスソスソスEソスリ厄ソスソスソスソス成
umask 77 ; \
        /usr/bin/openssl genrsa -des3 1024 > server.key
Generating RSA private key, 1024 bit long modulus
.................++++++
............++++++
e is 65537 (0x10001)
Enter pass phrase:ソス@ソスソスソス@ソスCソスモのパソスXソスソスソス[ソスhソスソスソスソスソスソスソスソスソス\ソスソスソスヘゑソスソスソスネゑソス
Verifying - Enter pass phrase:ソス@ソスソスソス@ソスCソスモのパソスXソスソスソス[ソスhソスソスソスソスソスソス(ソスmソスF)ソスソスソス\ソスソスソスヘゑソスソスソスネゑソス
umask 77 ; \
        /usr/bin/openssl req -utf8 -new -key server.key -x509 -days 3650 -out server.crt -set_serial 0
Enter pass phrase for server.key:ソス@ソスソスソス@ソスソスLソスナ会ソスソスソスソスソスソスソスソスpソスXソスソスソス[ソスhソスソスソスソスソスソスソスソスソス\ソスソスソスヘゑソスソスソスネゑソス
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [GB]:JPソス@ソスソスソス@ソスソスソスソスソスソスソスソス
State or Province Name (full name) [Berkshire]:Kanagawaソス@ソスソスソス@ソスsソスソスソス{ソスソスソスソスソスソスソスソス
Locality Name (eg, city) [Newbury]:Kawasakiソス@ソスソスソス@ソスsソス謦ャソスソスソスソスソスソスソスソス
Organization Name (eg, company) [My Company Ltd]:centossrv.comソス@ソスソスソス@ソスTソスCソスgソスソスソスソスソスソス(ソスネゑソスナゑソスソスソスソスソス)
Organizational Unit Name (eg, section) []:ソス@ソスソスソス@ソスソスENTER
Common Name (eg, your name or your server's hostname) []:centossrv.comソス@ソスソスソス@WebソスTソス[ソスoソス[ソスソスソスソスソスソス
Email Address []:[email protected]ソス@ソスソスソス@ソスヌ暦ソスソスメソスソス[ソスソスソスAソスhソスソスソスXソスソスソスソス

[root@centos certs]# openssl rsa -in server.key -out server.keyソス@ソスソスソス@ソスTソス[ソスoソス[ソスpソス髢ァソスソスソスソスソスソスpソスXソスソスソス[ソスhソス除
Enter pass phrase for server.key:ソス@ソスソスソス@ソスTソス[ソスoソス[ソスpソス髢ァソスソスソスEソスリ厄ソスソスソスソス成ソスソスソスフパソスXソスソスソス[ソスhソスソスソスソスソスソスソス\ソスソスソスヘゑソスソスソスネゑソス
writing RSA key
ソスソスソスpソスXソスソスソス[ソスhソスソスソス除ソスソスソスソスフは、WebソスTソス[ソスoソス[ソスNソスソスソスソスソスノパソスXソスソスソス[ソスhソスソスvソスソスソスソスソスソスネゑソスソス謔、ソスノゑソスソス驍スソスソス

ソスiソスQソスjSSLソスン抵ソス
[root@centos certs]# vi /etc/httpd/conf.d/ssl.confソス@ソスソスソス@ApacheSSLソスン抵ソスtソス@ソスCソスソスソスメ集
SSLCertificateFile /etc/pki/tls/certs/server.crtソス@ソスソスソス@ソスTソス[ソスoソス[ソスpソスリ厄ソスソスソスソスソスソスwソスソス

SSLCertificateKeyFile /etc/pki/tls/certs/server.keyソス@ソスソスソス@ソスTソス[ソスoソス[ソスpソス髢ァソスソスソスソスソスwソスソス

#  General setup for the virtual host, inherited from global configuration
#DocumentRoot "/var/www/html"ソス@ソスソスソス@#ソスソスソス除(ソスRソスソスソスソスソスgソスソスソスソス)
ソスソス
DocumentRoot "/var/www/html"

POODLE SSLv3.0 ソスニ弱性ソスソスソスホ擾ソス
#   SSL Protocol support:
# List the enable protocol levels with which clients will be able to
# connect.  Disable SSLv2 access by default:
SSLProtocol all -SSLv2
ソスソス
SSLProtocol All -SSLv2 -SSLv3ソス@ソスソスソス@SSLv2ソスASSLv3ソス無鯉ソスソスソスソスソスソスソス

ソスiソスRソスjApacheソスン抵ソスiAWStatsソスホ会ソスソスj
ApacheソスAソスNソスZソスXソスソスソスOソスソスソス(AWStats)ソスナ会ソスヘでゑソスソスソス謔、ソスソスhttpsソスAソスNソスZソスXソスソスソスOソスソスhttpソスAソスNソスZソスXソスソスソスOソスニ難ソスソスソスソスtソス@ソスCソスソスソスノ難ソスソスソスソスtソスHソス[ソス}ソスbソスgソスナ出ソスヘゑソスソスソス謔、ソスノゑソスソスソスB
[root@centos ~]# vi /etc/httpd/conf.d/ssl.confソス@ソスソスソス@SSLソスン抵ソスtソス@ソスCソスソスソスメ集
# Use separate log files for the SSL virtual host; note that LogLevel
# is not inherited from httpd.conf.
ErrorLog logs/error_logソス@ソスソスソス@ソスソスソスOソスtソス@ソスCソスソスソスソスソスマ更
CustomLog logs/access_log combined env=!no_logソス@ソスソスソス@ソスソスソスOソス謫セソスfソスBソスソスソスNソスeソスBソスuソスニソスソスOソスtソス@ソスCソスソスソスソスソスマ更
LogLevel warn

ソスソスApacheソスン定反ソスf

ソスiソスPソスjApacheソスン定反ソスf
[root@centos ~]# systemctl restart httpdソス@ソスソスソス@httpdソスNソスソスソスソスCentOS7ソスフ場合

ソスiソスQソスjソス|ソス[ソスg443ソスヤゑソスOPEN
ソスソスソス[ソス^ソス[ソスソスソスフ設抵ソスナポソス[ソスg443ソスヤゑソスOPENソスソスソスソスB
ソスソスソスソスソス[ソス^ソス[ソスフ設抵ソスヘ各ソスソスソス[ソス^ソス[ソスフマソスjソスソスソスAソスソスソスワゑソスソスソスソスソスソス[ソスJソス[ソスハソスソス[ソス^ソス[ソス|ソス[ソスgソスJソスソスソス闖ソスソスソスQソスソス

ソス|ソス[ソスgソス`ソスFソスbソスNソスyソスOソスソスソスソスソスソス|ソス[ソスgソスJソスソスソスmソスFソスzソスナ「hostソスソスソスvソスノサソス[ソスoソス[ソスソス(ソスソス:centossrv.com)ソスAソスuportソスヤ搾ソスソスvソスソス443ソスニ難ソスソスヘゑソスソスト「ソス|ソス[ソスgソス`ソスFソスbソスNソスvソス{ソス^ソスソスソスソスソスソスソスソスソスAソスuソスzソスXソスgソスソスcentossrv.comソス@ソス|ソス[ソスgソスソス443ソス@ソスノアソスNソスZソスXソスナゑソスソスワゑソスソスソスソスBソスvソスニ表ソスソスソスソスソスソス驍アソスニゑソスソスmソスFソスB


ソスソスWebソスTソス[ソスoソス[SSLソスmソスF

https://ソスTソス[ソスoソス[IPソスAソスhソスソスソスX/ソスノアソスNソスZソスXソスソスソスト「ソスZソスLソスソスソスソスソスeソスBソスフ警ソスソスソスvソスEソスBソスソスソスhソスEソスソスソス\ソスソスソスソスソスソスA"ソスヘゑソス"ソス{ソス^ソスソスソスソスソスソスソスソスWebソスyソス[ソスWソスソスソス\ソスソスソスソスソスソスソスソスOK

ソスネゑソスソスAhttps://ソスTソス[ソスoソス[IPソスAソスhソスソスソスX/ソスノアソスNソスZソスXソスソスソスト「ソスZソスLソスソスソスソスソスeソスBソスフ警ソスソスソスvソスEソスBソスソスソスhソスEソスソスソス\ソスソスソスソスソス黷スソスソスA"ソスリ厄ソスソスソスソスフ表ソスソス"ソスソス"ソスリ厄ソスソスソスソスフイソスソスソスXソスgソス[ソスソス"ソスソスソスsソスソスソスホ、ソスネ降ソスAソスuソスZソスLソスソスソスソスソスeソスBソスフ警ソスソスソスvソスEソスBソスソスソスhソスEソスヘ表ソスソスソスソスソスソスネゑソスソスネゑソスB


ソスソスソスヨ連ソスRソスソスソスeソスソスソスc

<!ソス\ソスeソスLソスXソスgソスフみゑソス4ソスsソス\ソスソスソスノ追会ソスソスソスCソスソスソスソスソスソス\>



ソスソスソスソスソスフペソス[ソスWソスフトソスbソスvソスヨ戻ゑソス

ソスvソスソスソスCソスoソスVソス[ソス|ソスソスソスVソス[
centossrv.com