ãAWS Certificate Managerãè¤æ°ãã¡ã¤ã³ã®è¨¼ææ¸ãåä¸ELBã§å¦çã§ãããæ¤è¨¼
åæç¥è
ãçåã
1å°ã®EC2ã¤ã³ã¹ã¿ã³ã¹ã«è¤æ°ã®ãã¼ãã£ã«ãã¹ããåä½ãã¦ããã
SSLã¯ACMã§åå¾ãã¦ELBã«ã¦SSLãªããã¼ããã¦ããã
ãã¼ãã£ã«ãã¹ãããããã®ã«ã¼ããã¡ã¤ã³ãç°ãªãã¨ããELBã¯1å°ã§å¦çã§ãããï¼
ãçµæã
å¦çã§ããã
ACMã§è¨¼ææ¸ã®ãªã¯ã¨ã¹ããè¡ãéããã¡ã¤ã³åã®ã»ãã«ã追å ã®ååããè¨è¼ã§ãããããã¡ãã«
[hoge.aa.com][*.bbb.jp]ãªã©ã«ã¼ããã¡ã¤ã³ã®ç°ãªããã¡ã¤ã³ã追å ã§ããã
ãã®è¨¼ææ¸ãå©ç¨ãããã¨ã§1å°ã®ELBã§è¤æ°ãã¡ã¤ã³ã®SSLãªããã¼ãå¦çãå¯è½ã
ãå ·ä½çãªä½æ¥ã¤ã¡ã¼ã¸ã
[Certification Manager]-[証ææ¸ã®ãªã¯ã¨ã¹ã]
ãã¡ã¤ã³åï¼hogehoge.com
[ãã®è¨¼ææ¸ã«å¥ã®ååã追å ]
*.hogehoge.com fugafuga.jp *.fugafuga.jp
ãªã©ãè¨å®ãã[確èªã¨ãªã¯ã¨ã¹ã]
â確èªã¨ãªã¯ã¨ã¹ããç»é¢ã§ç¢ºèªãã[確å®ã¨ãªã¯ã¨ã¹ã]
âåãã¡ã¤ã³ã®ç»é²ææè
ã«ãCertificate approval for hogehoge.comã E ã¡ã¼ã«ãéä»ãããã®ã§ãã¡ã¼ã«ã®ãªã³ã¯ï¼To approve this request, go to Amazon Certificate Approvalsï¼ãéãã¦[I Approve]ã§æ¿èªããã
ãæ ¹æ ã
https://aws.amazon.com/jp/certificate-manager/faqs/
Q: ACM ã«ããæä¾ããã証ææ¸ã«è¤æ°ã®ãã¡ã¤ã³åãå«ãããã¨ã¯ã§ãã¾ãã?ã¯ããå証ææ¸ã«ã¯å°ãªãã¨ã 1 ã¤ã®ãã¡ã¤ã³åãå«ã¾ãã¦ããå¿ è¦ãããã¾ãããå¿ è¦ãªå ´åã¯ããã«ãã¡ã¤ã³åã追å ã§ãã¾ããä¾ãã°ã両æ¹ã®ãã¡ã¤ã³åã§ãµã¤ãã«ã¢ã¯ã»ã¹ã§ãããªãã°ã"www.example.com" ã®è¨¼ææ¸ã« "www.example.net" ã¨ãããã¡ã¤ã³åã追å ã§ãã¾ãã証ææ¸ãªã¯ã¨ã¹ãã«å«ã¾ãããã¡ã¤ã³åãã¹ã¦ãææã¾ãã¯å¶å¾¡ãã¦ããå¿ è¦ãããã¾ãã
ãããã証ææ¸ã¯ããã«ããã¡ã¤ã³è¨¼ææ¸ãã¨ããããããå¥åã¯SANãç¥ãããã£ãã
rms-digicert.ne.jp
ã注æç¹ï¼ã
ãã«ããã¡ã¤ã³è¨¼ææ¸ã®å ´åããã©ã¦ã¶ã§SSL証ææ¸ãã¼ã¯ãå³ã¯ãªãã¯ããéã«è¡¨ç¤ºãããSSL証ææ¸ã®çºè¡å
(CN)ã¨ãã¦è¡¨ç¤ºãããã®ã¯ACM証ææ¸ã®æ¬ä½å称ãªã®ã§ããã®è¾ºãæ°ã«ãã人ã¯æ°ãä»ãã¾ãããã
ä¾ï¼
ãã¡ã¤ã³åï¼aaa.com
追å ã®ååï¼bbb.co.jp/*.ccc.com
ã¨ãã§ACMãç»é²ãã¦ELBã§SSLãªããã¼ãããå ´åãhttps://bbb.co.jpãã«ã¯æ£å¸¸ã«æ¥ç¶ããããã®ã®ã証ææ¸ã®ãçºè¡å
ãã¯aaa.comã¨ãã¦è¡¨ç¤ºããã¾ãã
ã注æç¹ï¼ã
ãã£ã¡ã«æ¸ãã¾ãããã©ãããã©ã«ãã§ã¯ãã«ããã¡ã¤ã³10åã¾ã§ã ããã§ãã
zuntan02.hateblo.jp
ãã以ä¸ã¯ä¸éç·©åç³è«ãå¿
è¦ã