Googleのサイト証明書を取得してみる(2)で、サイト証明書は取れた。
なので、今度は自動更新の準備をすることにした。
例によって、AIさん全面依存で進める。
先ずはcertbotで何か準備をするらしい。(まるで理解していない)
|
1 |
sudo /opt/local/bin/certbot certonly --webroot -w /Volumes/Works/Library/www/niwakan -d niwakan.k-in.co.jp --force-renewal |
–webroot -w server root path は一回だけ使う。pathを変更したら、もう一回設定し直すのだろう。(推測)
-d web site name は、ほぼ固定になるね。
すると /opt/local/etc/letsencrypt/renewal/niwakan.k-in.co.jp.conf と言うファイルに1行追加された。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 |
version = 5.8.0 archive_dir = /opt/local/etc/letsencrypt/archive/niwakan.k-in.co.jp cert = /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/cert.pem privkey = /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/privkey.pem chain = /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/chain.pem fullchain = /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/fullchain.pem [renewalparams] account = 909b4f2dec197e42ebe101396f0fb744 authenticator = webroot server = https://acme-v02.api.letsencrypt.org/directory key_type = ecdsa webroot_path = /Volumes/Works/Library/www/niwakan, [[webroot_map]] [acme_renewal_info] ari_retry_after = 2026-09-09T23:58:07 |
webroot_path = /Volumes/Works/Library/www/niwakan,
これで、どこに書き込む?のか解るのだろう。(知らんけど)
実際に動作確認をする。
% sudo /opt/local/bin/certbot certonly -d niwakan.k-in.co.jp
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 |
Saving debug log to /opt/local/var/log/letsencrypt/letsencrypt.log ssl_module is statically linked but --apache-bin is missing; not disabling session tickets. How would you like to authenticate with the ACME CA? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: Apache Web Server plugin (apache) 2: Runs an HTTP server locally which serves the necessary validation files under the /.well-known/acme-challenge/ request path. Suitable if there is no HTTP server already running. HTTP challenge only (wildcards not supported). (standalone) 3: Saves the necessary validation files to a .well-known/acme-challenge/ directory within the nominated webroot path. A separate HTTP server must be running and serving files from the webroot path. HTTP challenge only (wildcards not supported). (webroot) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-3] then [enter] (press 'c' to cancel): 1 Certificate not yet due for renewal You have an existing certificate that has exactly the same domains or certificate name you requested and isn't close to expiry. (ref: /opt/local/etc/letsencrypt/renewal/niwakan.k-in.co.jp.conf) What would you like to do? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - 1: Keep the existing certificate for now 2: Renew & replace the certificate (may be subject to CA rate limits) - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal; no action taken. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - |
全く意味が判らないので、Google翻訳さんの出番である。
ssl_module は静的にリンクされていますが –apache-bin が指定されていません。セッションチケット機能は無効化されません。
ACME CA での認証方法を選択してください。
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
1: Apache Web Server プラグイン (apache)
2: ローカルで HTTP サーバーを起動し、/.well-known/acme-challenge/ リクエストパス配下で必要な検証用ファイルを提供します。HTTP サーバーがまだ稼働していない場合に適しています。HTTP チャレンジのみ(ワイルドカードは非対応)。(standalone)
3: 指定された webroot パス内の .well-known/acme-challenge/ ディレクトリに、必要な検証用ファイルを保存します。別途 HTTP サーバーが稼働しており、その webroot パスからファイルを提供している必要があります。HTTP チャレンジのみ(ワイルドカードは非対応)。(webroot)
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
適切な番号 [1-3] を選択して [Enter] キーを押してください(キャンセルする場合は ‘c’ を入力): 1
証明書の更新時期ではありません
要求されたドメインまたは証明書名と完全に一致し、かつ有効期限が迫っていない既存の証明書が存在します。
(参照: /opt/local/etc/letsencrypt/renewal/niwakan.k-in.co.jp.conf)
どうしますか?
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
1: 現在の証明書をそのまま使用する
2: 証明書を更新・置換する (CAのレート制限が適用される場合があります)
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
適切な番号 [1-2] を選択して [Enter] キーを押してください (キャンセルする場合は ‘c’ を入力): 1
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
証明書の更新時期ではないため、処理は行われませんでした。
– – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – – –
対話型だから、crontabには登録できない。
でも、この辺はAIさんにでも、Geminiさんにでも聞けば教えてくれるから問題ない。
早速、AIさんに聞いたら教えて貰えた。
こうである。
|
1 2 3 |
#!/bin/sh /opt/local/bin/certbot certonly --webroot -w /Volumes/Works/Library/www/niwakan -d niwakan.k-in.co.jp --keep-until-expiring --non-interactive --deploy-hook "/opt/local/bin/port reload apache2" |
ただ、–webrootは既にconfig fileに書き込まれているから必要ないだろう。取っ払ってしまう。
そして、shell scriptを書く。
|
1 2 |
#!/bin/sh /opt/local/bin/certbot certonly -d niwakan.k-in.co.jp --keep-until-expiring --non-interactive --deploy-hook "/opt/local/bin/port reload apache2" |
そしてcrontabに登録する。
|
1 |
0 4 * * 1 /usr/local/sbin/update_cert.sh >/dev/null 2>&1 |
実際にsudo /usr/local/sbin/update_cert.shと起動したら、問題が起きた。
Missing command line flags. For non-interactive execution, you will need to specify a plugin on the command line. Run with ‘–help plugins’ to see a list of options, and see https://eff.org/letsencrypt-plugins for more detail on what the plugins do and how to use them.
Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /opt/local/var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details.
これじゃ更新できない。
『certbot 自動更新 apache』でググる。
一番上に「Apache 2.x + Certbot(新規、自動更新)」があったので、そこを探す。
certbot renewこれだけで良いらしい。
実際にやってみた。
sudo certbot renew
|
1 2 3 4 5 6 7 8 9 10 11 12 |
Saving debug log to /opt/local/var/log/letsencrypt/letsencrypt.log - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Processing /opt/local/etc/letsencrypt/renewal/niwakan.k-in.co.jp.conf - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Certificate not yet due for renewal - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - The following certificates are not due for renewal yet: /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/fullchain.pem expires on 2026-12-08 (skipped) No renewals were attempted. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - |
綺麗に終わったので、crontabを書き直す。
|
1 |
0 4 * * 6 /usr/local/sbin/update_cert.sh >/dev/null 2>&1 |
土曜日にしたのは、serverが日曜日の夜更けに再起動するから。
最大30日間の猶予があるから、1日の時間差があっても証明書には影響が無いだろうと、こうした。
週一回の確認にした理由はこうだ。
「更新は30日前からなので、更新確認は15日くらいで良いのでは?」との問いに、AIさんは
ただ、実はインターネット全体の運用(CertbotやLet’s Encryptの公式ガイド)として、「15日ごとではなく、週1回(なんなら毎日)」実行することが推奨されているのには、ある『笑えないセキュリティ上の大人の事情(リスク回避)』があります。
なぜ「週1回」や「毎日」実行が推奨されるのか?
理由は単純で、「GoogleやLet’s Encrypt(認証局)のサーバーが、その15日に1回のタイミングで、たまたまメンテナンスや障害で落ちていたら、次のチャンスが15日後(つまりもう期限切れ寸前)になってしまうから」です。
と、言うことで認証局側のお薦めだからでした。
確認は、2ヶ月後となりますね。
それまで待ちましょう。(多分忘れているなぁ)

