opensslãæ´æ°ãããã¨ã§ä»è¾¼ãã çå¼¾
æè¿ã¯ Qiita ã®æ¹ã«æç¨¿ãç§»ã£ã¦ãåã§ãã
ã¡ãã£ã¨åããopensslããã¿ã®è©±é¡ãåºã¦ãã¾ããã
HeartbleedBugã¨ãCCS injectionã¨ãã
ã§ããã¡ã®ãµã¼ããopensslæ´æ°ãã¦ãããªãã¨ãªã¼ã¨æã£ã¦æ´æ°ãã¾ããã
AWSã使ã£ã¦ãã¦ãã¯ã© -> ELB(https) ELB -> EC2(http)ã¨ããæ§æã«ãã¦ããã®ã§ãapacheã®åèµ·åã¯ããªãã¦ãããã¼ã¨æ¾ç½®ãã¦ããã§ãã
æ´æ°ä½æ¥ããå½åã¯ç¹ã«ä½ãåé¡ãªãã£ããã§ãããç¿é±æææ¥ã«äºä»¶ãã»ã»ã»ã
ãapacheãããè½ãã¡ãã¦ãã
ãªãã§ã ã¼ã¨æã£ã¦ã¨ã©ã¼ãã°è¦ã¦ã¿ããã以ä¸ã®ãããªã¨ã©ã¼ã
mod_sslãèªããªãï¼ï¼
[notice] SIGHUP received. Attempting to restart
httpd: Syntax error on line 221 of /etc/httpd/conf/httpd.conf: Syntax error on line 12 of /etc/httpd/conf.d/ssl.conf: Cannot load /etc/httpd/modules/mod_ssl.so into server: /lib64/libc.so.6: version `GLIBC_2.14' not found (required by /usr/lib64/libssl.so.10)
äºä»¶ã®å¼ãéãå¼ããã®ã¯crondã§åãã¦ãlogrotatedã§ããã
ããã¤ããã°ãã¼ãã®å¾ã«apacheãreloadããã¦ãã¦ããããæ¥æã®æ·±å¤ã§ããã
ã§ãã£ã¦ãmod_ssl使ã£ã¦ãªãã¯ããªã®ã«ãããããªã¼ã¨æã£ã¦è¦ã¦ã¿ããã
ããã©ã«ãè¨å®ã ããmod_sslèªã¿è¾¼ãã§ããï¼
ãªãã§ãããã©ã«ãã®ã¾ã¾ã¯ãããªããªã£ã¦ãã¨ã¨ã
使¥å¾ã«åããããå®å¿ã£ã¦ããã«ã¯ãããªãã£ã¦æè¨ã§ããã