1번 예시) test.kensei.co.kr 이라는 도메인을 네임서버에서 certbot 을 설치한 웹 서버로 잡아준다.
2번 예시)
/etc/httpd/conf.d/ssl.conf (파일에 도메인 설정이 되어 있어야 함)
ServerName test.kensei.co.kr:443
위 2가지 작업이 미리 진행되어야 아래와 같이 에러 없이 잘 실행된다.
certbot 명령어 실행 (apache 에서 실행해보았다)
[root@iwinvhelper-8053 wordpress]# certbot –apache -m takakocap@naver.com -d test.kensei.co.kr -n –agree-tos Saving debug log to /var/log/letsencrypt/letsencrypt.log Plugins selected: Authenticator apache, Installer apache Starting new HTTPS connection (1): acme-v01.api.letsencrypt.org Cert not yet due for renewal Keeping the existing certificate Deploying Certificate for test.kensei.co.kr to VirtualHost /etc/httpd/conf.d/ssl.conf
——————————————————————————- Congratulations! You have successfully enabled https://test.kensei.co.kr
You should test your configuration at: https://www.ssllabs.com/ssltest/analyze.html?d=test.kensei.co.kr ——————————————————————————-
IMPORTANT NOTES: – Congratulations! Your certificate and chain have been saved at: /etc/letsencrypt/live/test.kensei.co.kr/fullchain.pem Your key file has been saved at: /etc/letsencrypt/live/test.kensei.co.kr/privkey.pem Your cert will expire on 2017-12-19. To obtain a new or tweaked version of this certificate in the future, simply run certbot again with the “certonly” option. To non-interactively renew *all* of your certificates, run “certbot renew” – If you like Certbot, please consider supporting our work by:
Donating to ISRG / Let’s Encrypt: https://letsencrypt.org/donate Donating to EFF: https://eff.org/donate-le
[root@iwinvhelper-7795 etc]# certbot –nginx -m takakocap@naver.com -d cert.kensei.co.kr -n –agree-tos Saving debug log to /var/log/letsencrypt/letsencrypt.log Starting new HTTPS connection (1): acme-v01.api.letsencrypt.org Obtaining a new certificate Performing the following challenges: tls-sni-01 challenge for cert.kensei.co.kr Waiting for verification… Cleaning up challenges Deployed Certificate to VirtualHost /etc/ngi 설치nx/nginx.conf for set([‘cert.kensei.
——————————————————————————- Congratulations! You have successfully enabled https://cert.kensei.co.kr
You should test your configuration at: https://www.ssllabs.com/ssltest/analyze.html?d=cert.kensei.co.kr ——————————————————————————-
IMPORTANT NOTES: – Congratulations! Your certificate and chain have been saved at /etc/letsencrypt/live/cert.kensei.co.kr/fullchain.pem. Your cert will expire on 2017-12-06. To obtain a new or tweaked version of this certificate in the future, simply run certbot again with the “certonly” option. To non-interactively renew *all* of your certificates, run “certbot renew” – If you like Certbot, please consider supporting our work by:
Donating to ISRG / Let’s Encrypt: https://letsencrypt.org/donate Donating to EFF: https://eff.org/donate-le