AWS Route53ã使ã£ã¦DNS-01ã§Let's Encryptã®è¨¼ææ¸ãåå¾ãã
DNS-01æ¹å¼
HTTPãå©ç¨ãã¦èªè¨¼ããå ´åã«ãIPå¶éã社å
ã®ã¿ã®éä¿¡ãªã©ã®å¶éããã¦ããç°å¢ã«ããã¦ã¯Let's Encryptå´ããã®éä¿¡ãå±ããªãã®ã§èªè¨¼ã§ãã¾ãããããã§DNSã®TXT
ã¬ã³ã¼ãã§èªè¨¼ããDNS-01
ã®ã¿ã¤ããããã¾ãã
ãã¡ãã®ãµã¤ãã®èª¬æãããããããã£ãã§ãã
Let's EncryptのDNS-01を使用して無料のSSL証明書をWebサーバなしで取得する -- ぺけみさお
å ¬å¼ã®certbotã対å¿ãã
å ã»ã©ã®è¨äºå·çæç¹ã§ã¯ä»¥ä¸ã®ããã«æ¸ãã¦ããã¾ãããã
ç¾å¨ãLetâs Encryptå ¬å¼ã®letsencryptã³ãã³ãã¯ãDNSã«ããèªè¨¼ããµãã¼ããã¦ãã¾ããã GitHubã§ãã«ãªã¯ã¨ã¹ãã¯ããã¦ãã¾ãããã¾ã ãã¼ã¸ããã¦ãã¾ããã
ç¾å¨ã¯ãã¼ã¸ãã使ããããã«ãªã£ã¦ãã¾ããï¼ï¼
Dockerã§certbotãåããã¦çæãã
ããããã¨ã便å©ãDocker
Dockerfileã¯ãããªæãã§
FROM certbot/certbot RUN pip install certbot-dns-route53 COPY run.sh run.sh RUN chmod +x run.sh ENTRYPOINT ["/opt/certbot/run.sh"]
ä¸èº«ã®run.sh
#!/bin/sh certbot certonly -n --agree-tos \ --email <your email address> \ --dns-route53 -d ${DOMAIN}
å®è¡ã³ãã³ãã¯ãã
$ DOMAIN=<yourdomain.example.com> $ docker run -e AWS_ACCESS_KEY_ID=$AWS_ACCESS_KEY_ID \ -e AWS_SECRET_ACCESS_KEY=$AWS_SECRET_ACCESS_KEY \ -e DOMAIN=$DOMAIN \ -v $PWD:/etc/letsencrypt dns-certbot
ããã§ã«ã¬ã³ããã£ã¬ã¯ããªé
ä¸ã«$PWD/live/${DOMAIN}/private.pem
ã¨$PWD/live/${DOMAIN}/fullchain.pem
ãçæããã¾ãã