AIさんの発言から、サイト証明書をGoogleから取得してみようということになった。
Googleのサイト証明書(Google Trust Services)の取得方法とサーバーの設定を順に書いていきたい。
その結果、ここはniwakan.k-in.co.jpと独立したサイトになる(かも知れない)。
先ずApacheのextra/httpd-vhosts.confに下記を書く。
niwakanを独立したサイトにする訳で、最終的にはここから移動するかも知れない。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 |
<VirtualHost *:80> ServerAdmin foopa@k-in.co.jp DocumentRoot "/Volumes/Works/Library/www/html/niwakan" ServerName niwakan.k-in.co.jp ServerAlias niwakan.k-in.co.jp ErrorLog "var/log/apache2/error_log" CustomLog "var/log/apache2/access_log" common </VirtualHost> <VirtualHost *:443> ServerAdmin foopa@k-in.co.jp DocumentRoot "/Volumes/Works/Library/www/html/niwakan" ServerName niwakan.k-in.co.jp ErrorLog "var/log/apache2/niwakan-error_log" CustomLog "var/log/apache2/niwakan-access_log" common SSLEngine on </VirtualHost> |
未だ本体(www.k-in.co.jp)とは切り離さない。
立ち上がってwordpressが名称エラーを起こしてからが本番だから。
次にcertbotとcertbot-apacheをインストール。
この二つはGooleから適時(30日毎?)新しいkeyとcertを作り直すらしい。
それも自動で。
毎年、証明書発行業者に頼まずとも、自動で発行され更新される。
何て言うか、今まで何やってきたんだって話だわ。
発行業者潰れるぞ。
|
1 2 3 4 5 6 |
sudo port install certbot sudo port install certbot-apache The following dependencies will be installed: augeas mod_perl2 +perl5_34 py314-python-augeas |
と3つが新規で入るらしい。
そして最後に
|
1 2 3 |
cd /opt/local/lib/apache2/modules/ sudo /opt/local/bin/apxs -a -e -n "perl" mod_perl.so /opt/local/sbin/apachectl restart |
こうしろと言われたので、言われたまま実行した。
modulesに入れたら自動で読み込まれるんだっけ。
httpd.confにはincludeなんたらって、ずらっと並んでいるけれど、要るのかな?
既にお役御免な過去の遺品?
先ほど入れたのを使う。
AIさんが言うには「Google Trust Services(GTS)のアカウント登録」だそうだ。
|
1 2 |
sudo certbot register --email foopa@k-in.co.jp --server https://pki.goog --agree-tos sudo certbot certonly --apache -d niwakan.k-in.co.jp --server https://pki.goog |
何が起きているのかは全く判らない。
理由も聞いていない。AIさんに言われるままである。
AIさん曰く『サブドメインの証明書を「一発取得」する』のだそうだ。
|
1 |
sudo certbot certonly --apache -d niwakan.k-in.co.jp --server https://pki.goog |
そして、何故だかgoogle-cloud-sdkのインストール。
多分、後々使うことになるのだろう。
|
1 |
sudo port install google-cloud-sdk |
早速使うことになった。
|
1 2 3 |
% gcloud auth login gcloud config set project public-ca-manager |
public-ca-managerはGoogle Cloudで新規に作ったプロジェクト。
別に何でも良いけれど、先に作っておかないといけない。
|
1 2 3 |
% gcloud services enable publicca.googleapis.com Operation "operations/acat.p2-57230096736-9f15d6f6-55b9-4af3-834e-779c692f30b6" finished successfully. |
|
1 2 3 4 5 |
% gcloud publicca external-account-keys create Created an external account key [b64MacKey: ここにMacKeyの数字の羅列が入る keyId: ここにKeyIDの英数字の羅列か来る] |
この二つは大事なものなので公開してはいけないらしい。
なので、記録はshell scriptの中にしかない。
ここからshell scriptになる。
理由は、Geminiさんはbashでone linnerを書くが、自分はtcshなのでそのままだと動かないからだ。
|
1 2 3 4 5 6 7 8 |
% cat ~/certbot.sh certbot --apache \ --server https://dv.acme-v02.api.pki.goog/directory \ --eab-kid KeyIDの羅列を入れる \ --eab-hmac-key MacKeyの羅列を入れる \ -d niwakan.k-in.co.jp \ -m foopa@k-in.co.jp |
実際に動かしてみた。
% sudo sh ~/certbot.sh
一回目。
niwakan.k-in.co.jpがDNSに無いと怒られた。
一般公開用のzone fileを弄って戻る。
二回目。
port 80が空いていないと怒られた。
httpd-vhost.confに追加した。
それと、『にわ管』はport 443に強制移動していなかったかな?
していた気がする。
三回目。
exstra/httpd-vhost.confを組み込んだら、親(www.k-in.co.jp)毎落ちた。
これチェックに時間がかかりそうだ。
ログは一つだけ残ってたので載せておく。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 |
% sudo sh certbot.sh Saving debug log to /opt/local/var/log/letsencrypt/letsencrypt.log ssl_module is statically linked but --apache-bin is missing; not disabling session tickets. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please read the Terms of Service at: https://pki.goog/GTS-SA.pdf You must agree in order to register with the ACME server. Do you agree? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: y - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Would you be willing, once your first certificate is successfully issued, to share your email address with the Electronic Frontier Foundation, a founding partner of the Let's Encrypt project and the non-profit organization that develops Certbot? We'd like to send you email about our work encrypting the web, EFF news, campaigns, and ways to support digital freedom. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: y Account registered. Requesting a certificate for niwakan.k-in.co.jp Unable to find a virtual host listening on port 80 which is currently needed for Certbot to prove to the CA that you control your domain. Please add a virtual host for port 80. Ask for help or search for solutions at https://community.letsencrypt.org. See the logfile /opt/local/var/log/letsencrypt/letsencrypt.log or re-run Certbot with -v for more details. |
もう疲れたんで、今日はお仕舞いにするわ。
タイトルも(1)付けておこう。

