ãã¼ã / ãã㯠/ Apacheå½¢å¼ã®SSL証ææ¸ãTomcatå½¢å¼ã«å¤æãã
ãã¼ã / ãã㯠/ Apacheå½¢å¼ã®SSL証ææ¸ãTomcatå½¢å¼ã«å¤æãã
opensslã³ãã³ãã§ä½æãã ç§å¯éµã¨è¨¼ææ¸ãtomcatã®SSLã³ãã¯ã¿ã«ãå ±æããããã¨ãããããnativeã®APRã使ãã°ãSSLCertificateFileå±æ§ãªã©ã使ãã¦ãã®ã¾ã¾è¨å®ãã¡ã¤ã«ã«CRTãã¡ã¤ã«ãæå®ã§ããããkeytool ã§å¤æã§ããã ã¾ãã以ä¸ã®ããã«pkcs12ã«å¤æããã # openssl pkcs12 -export -in /etc/pki/tls/certs/ssl.crt -inkey /etc/pki/tls/private/ssl.key -out /usr/local/tomcat/keystore.pkcs12 -name "tomcat"ï¼å®éã¯ï¼è¡ã§å ¥åï¼ ãã®å ´åã® -name "tomcat" ã®å¤ã¯ã次ã®å¤æã§ä½¿ç¨ããã ããã«æ¬¡ã®ã³ãã³ã㧠pkcs12å½¢å¼ã®ãã¼ã¿ãã¤ã³ãã¼ãããã # keytool -import
ã¬ãã«: ã¨ã©ã¼ ãã°ã®åå: Application ã½ã¼ã¹: Microsoft-Windows-CAPI2 ã¤ãã³ãID: 11 <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> ã«ããèªåæ´æ° cab ãã¡ã¤ã«ãããµã¼ã ãã¼ãã£ã®ã«ã¼ãä¸è¦§ãæ½åºã§ãã¾ããã§ãããã¨ã©ã¼: ç¾å¨ã®ã·ã¹ãã æè¨ã¾ãã¯ç½²åãã¡ã¤ã«ã®ã¿ã¤ã ã¹ã¿ã³ãã§ç¢ºèªããã¨ãå¿ è¦ãªè¨¼ææ¸ã®æå¹æéãéãã¦ãã¾ãã ä¸è¨ã®ã¨ã©ã¼ãçºçãã¦ããã®ã§ããããã«ãµã¼ããåèµ·åããã¨ããã èªåæ©è½ã®ãµã¼ãã¹ã®6ï½7å²ãèµ·åããªããªãã¾ããã åãã¦ããµã¼ãã¹ã¯ Active Directory Domain Services COM+ Evebt System DHCP Client
SSLã§ãµã¼ãã¼ã使ãããããSSLãé«ãã®ã§ããã©ãããããªã¬ãªã¬è¨¼ææ¸ã¯å«ã ãã ããã§StartSSLã®ç¡æ証ææ¸ãä½ããã¨ã«ããã ç¡æã§SSLã使ããã https://www.startssl.com/ æè¿Windowsã«ãBundleãããããã«ãªã£ã¦ã©ãã§ã使ãã¾ããå®ç§ã§ããã äºåã«æ¬¡ã®ï¼ç¹ãæ¸ã¾ãã¦ãããã¨ã StartLSSã®ç¡æã¢ã«ã¦ã³ããæã£ã¦ããã ãã¡ã¤ã³ã®ææè 確èªãæ¸ã¾ãã¦ããã ã¢ã«ã¦ã³ãã®ç»é²æ¹æ³ åãã¦ã®äººã¯ãã¢ã«ã¦ã³ãã®ä½ãæ¹ã§æ¸æããããã¢ã«ã¦ã³ãã®ç»é²ã¯ç°¡åã ãã©ããã°ã¤ã³ã«å人証ææ¸ã使ãã®ã§åèãµã¤ãè¦ãæ¹ãè¯ãã¨æãã StartSSLã§ç¡æã®ãµã¼ãSSL証ææ¸ãçºè¡ãã¦ã¿ãã - Yåããã³ã¢ãªæ¥èª ç¡æ SSL 証ææ¸ StartSSL ã使ã ãµã¤ãã«ã¢ã¯ã»ã¹ã㦠Certificates Wizard Certificate
ããã§ã¯ä¸ç¹å®å¤æ°ã«å ¬éãã WEB ãµã¼ãã¼ã対象ã¨ãã¦ããã¾ãããç¬èªCA ã«ãã WEBãµã¤ãã®æå·åã¯éãããç¨éã®ã¿ã«éå®ããå¿ è¦ãããã¾ãã åºæ¬çã«1.3ç³»ã¨å 容ã¯å¤ããã¾ãããã¯ã©ã¤ã¢ã³ãèªè¨¼ã®è©ä¾¡åºæºã«å¤æ´ãããã¾ããCA(èªè¨¼å±)ã¨SSLãµã¼ãã¼ã«å¿ è¦ãªãµã¼ãã¼è¨¼ææ¸ã¨ç§å¯éµãæºåã§ãã¦ããäºãåæã§ãããã¡ãã§è§£èª¬ãã¦ãã¾ãã®ã§åèã«ãã¦ä¸ããã Apache2系統ã§SSL対å¿ã«ããã«ã¯ã/etc/httpd/conf.d/ssl.conf ãä¿®æ£ãã¾ãããã¹ã¯é©å®èªã¿æ¿ãã¦ãã ããã https://www.mydomain.net ãæå¹ã«ããå ´å # ã³ã¡ã³ãã解é¤ããã¡ã¤ã³ãæå®ãã¾ãã DocumentRoot "/var/www/pub/html" #ServerName www.example.com:443 ServerName www.mydomai
CentOS 5.4ã§SSL/TLSéä¿¡ç¨ã®è¨¼ææ¸ãä½æããã®ã§ãã®æã®æé ãã¡ã¢ã 1. ç§å¯éµã®çæ ã¾ãããµã¼ãã¼ç¨ã®ç§å¯éµãçæãããçæå¾ããã¼ããã·ã§ã³ãå¤æ´ãã¦root以å¤ããã¯èªããªãããã«ããããã§ã«ãªã«ãã§ä½ææ¸ã¿ã®å ´åã¯äºéã«ä½æããå¿ è¦ã¯ãªãã®ã§çç¥å¯ã [root@localhost ~]# cd /etc/pki/tls/private [root@localhost private]# openssl genrsa -out server.key -des3 2048 Generating RSA private key, 2048 bit long modulus ................................+++ .................+++ e is 65537 (0x10001) Enter pass phrase fo
ã¦ã¼ã¶ã¼åããã¹ã¯ã¼ãçã®æ©å¯æ å ±ãWebãã©ã¦ã¶ããå ¥åããå ´åãçè´ãããæãããããããWebãµã¼ãã¼éã®éä¿¡å 容ãæå·åããã ããã§ã¯ãWebãµã¼ãã¼ã«mod_sslãå°å ¥ãã¦ãURLãhttp://ï½ã§ã¯ãªããhttps://ï½ã§ã¢ã¯ã»ã¹ãããã¨ã«ãã£ã¦ãWebãµã¼ãã¼éã®éä¿¡å 容ãæå·åããããã«ããã ãªããWebãµã¼ãã¼ã¨ã®éä¿¡å 容ãæå·åããã«ã¯ããµã¼ãã¼è¨¼ææ¸ãçºè¡ããå¿ è¦ãããããããã§ã¯ãèªä½ãµã¼ãã¼è¨¼ææ¸ãçºè¡ãã¦åã¯ã©ã¤ã¢ã³ãã«ã¤ã³ãã¼ãããã â»ãµã¼ãã¼è¨¼ææ¸ãåã¯ã©ã¤ã³ãã¸ã¤ã³ãã¼ãããªãã¦ãæå·åéä¿¡ã¯è¡ããããã¯ã©ã¤ã¢ã³ããéä¿¡ãããã³ï¼Webãã©ã¦ã¶èµ·åæ¯ï¼ã«ã»ãã¥ãªãã£ã®è¦åã表示ããã¦ãã¾ã [root@centos ~]# cd /etc/pki/tls/certs/ãâããã£ã¬ã¯ããªç§»å [root@centos certs]# sed -i
ç¡æã§å©ç¨ã§ãã StartSSL ã®è¨¼ææ¸ã使ã£ã¦ãApache + mod_ssl 㧠HTTPS éä¿¡ãã§ããããã«è¨å®ãããæ¹æ³ã§ããStartSSL ã¯ãå人ã§ããã°ã1å¹´éã®æéä»ã㧠SSL 証ææ¸ãç¡æã§åå¾ã§ãã¾ãããã ãããã¡ã¤ã³ã®ææè ã§ããå¿ è¦ãããã¾ãã ç¡æã¨ã¯ãããFirefox ã Safari ã§ããã°ãèªè¨¼å±ã¨ãã¦ç»é²ããã¦ããã®ã§ããããã®ãã©ã¦ã¶ã§è¦åã¯åºã¾ãããæ®å¿µãªãã IE ã¯å¯¾å¿ãã¦ããªãããã§ããç§ã®å ´å㯠Firefox ã§è©¦ãã¾ããããªããç§ã試ããå 容ãåèç¨åº¦ã«æ¸ãã¦ããã ãã§ãã®ã§ããã®è¨äºããã¨ã«ä½ãæ害ãçºçãã¦ãã責任ãåãã¾ããããããããèªå·±è²¬ä»»ã§ãé¡ããã¾ãã StartSSL ã«ç»é² ã¾ã StartSSL ã«ç»é²ãã¾ããStartSSL Free ãé¸æãããRegisterããé¸æãã¾ãã ä½æãæ°åãã¡ã¼ã«ã¢ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}