Googleのサイト証明書を取得してみる(1)の続きだよ。
今回も笑える結果が待っている。
さて、結果を先に書くと、証明書は取れました。
前回、extra/httpd-vhosts.confをインクルードするとApacheが落ちる件。
これは、記述方法が間違っていたのが理由だった。
全文記載しておく。
多分、ちょこちょこっと書き直すと、どこのサイトでも対応できそうなんだ。
おまけにAIさんの丁寧なコメント入りだよ。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 |
# 枠1:今動いている本番の「リアル(k-in.co.jp)」を一番上に置く # (中身を空っぽにしておくと、自動的に大元の「リアル設定」がそのまま身代わりとして適用されます!) <VirtualHost *:80> ServerName k-in.co.jp ServerAlias www.k-in.co.jp </VirtualHost> # 枠2:新しく独立させたい「バーチャル(niwakan.k-in.co.jp)」 <VirtualHost *:80> ServerName niwakan.k-in.co.jp DocumentRoot "/Volumes/Works/Library/www/niwakan" <Directory "/Volumes/Works/Library/www/niwakan"> Options FollowSymLinks AllowOverride All Require all granted </Directory> ErrorLog "/opt/local/var/log/apache2/niwakan-error_log" CustomLog "/opt/local/var/log/apache2/niwakan-access_log" common RewriteEngine on RewriteCond %{SERVER_NAME} =niwakan.k-in.co.jp RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent] </VirtualHost> # ================================================== # 【ポート443番:HTTPS(SSL)側の融合ルール】 # ================================================== # 枠2-A:本番サイト(リアル)の443番を一番上に置いて守る # (★ここには大元のFujiSSLの設定を「そのまま」コピーして持ってきます!) <VirtualHost *:443> ServerName k-in.co.jp ServerAlias www.k-in.co.jp # 大元の httpd-ssl.conf等に書かれているFujiSSLのパスをそのまま貼る SSLEngine on SSLCertificateFile "/opt/local/etc/apache2/conf/server.crt" SSLCertificateKeyFile "/opt/local/etc/apache2/conf/none-pass-server.key" SSLCertificateChainFile "/opt/local/etc/apache2/conf/server.ca" </VirtualHost> |
当然だが、この記載内容はAIさんに全面的に依存している。
さて、これで立ち上がれば……をぉエラー吐かないぞ。普通にwww.k-in.co.jpの内容が見られた。
因みにhttpd.confに追加した
NameVirtualHosts *:80
NameVirtualHosts *:443
は、要らなかった、もうすぐ切り捨てられるんだそう。
何故ならApacheが賢くなって、
多分、Apacheは自分より頭良いな。(羨ましい……
さあ、次です。
実際にSafariで見てみましょう。
niwakanなんて無いって帰ってくる。何故?
|
1 2 3 4 5 6 7 |
% nslookup niwakan.k-in.co.jp Server: 192.168.0.36 Address: 192.168.0.36#53 Non-authoritative answer: *** Can't find niwakan.k-in.co.jp: No answer |
あぁ、内部DNSに追加するの忘れてた。
追加しました。
nslookupではきちんとipが出ます。
そっか、逆引きできないサイトって、逆引きが書けない(ローカル内部で動いている)のか、そうかこうなっているのか。
あれ違うかも、外に出た後では書けるな、その筈だ。単なる手抜き?どっちだ?
閑話休題。
SafariはmDNSResponder全面依存だろうから、Google Chromeで確認してみる。

立ち上がった。
index.htmlがたった一つ入っているだけだけど、見ることはできた。
pathも通ったことだし、これで証明書取得条件は整ったね。
AIさんに言われた通りに、コマンドを叩く。
|
1 2 3 4 5 6 |
sudo certbot --apache -d niwakan.k-in.co.jp (Enter 'c' to cancel): support@k-in.co.jp - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Please read the Terms of Service at:https://letsencrypt.org/documents/LE-SA-v1.8-July-06-2026.pdf You must agree in order to register with the ACME server. Do you agree?letsencrypt.org |
あれ?Googleと関係ないよ。letsencrypt.orgってどういうことだろう?
LE-SA-v1.8-July-06-2026.pdfってGoogleとも共通な解説かなんかなのだろうか?
でもGoogleなら自前の用意しそうな物だけどなぁ。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 |
Would you be willing, once your first certificate is successfully issued, toshare your email address with the Electronic Frontier Foundation, a foundingpartner of the Let's Encrypt project and the non-profit organization thatdevelops Certbot? We'd like to send you email about our work encrypting the web,EFF news, campaigns, and ways to support digital freedom. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: y Account registered.Requesting a certificate for niwakan.k-in.co.jp Successfully received certificate. Certificate is saved at: /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/fullchain. pemKey is saved at: /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/privkey.pem This certificate expires on 2026-12-07.These files will be updated when the certificate renews. Deploying certificate Successfully deployed certificate for niwakan.k-in.co.jp to /opt/local/etc/apache2/extra/httpd-vhosts-le-ssl.conf Congratulations! You have successfully enabled HTTPS on https://niwakan.k-in.co.jp NEXT STEPS:- The certificate will need to be renewed before it expires. Certbot can automatically renew the certificate in the background, but you may need to take steps to enable that functionality. See https://certbot.org/renewal-setup for instructions. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - If you like Certbot, please consider supporting our work by: * Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate * Donating to EFF: https://eff.org/donate-le - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - |
上手く行ったみたい。
では試してみよう。

エラーになった。
AIさん曰く、「niwakan.k-in.co.jpの証明書の記述が無いから、Apacheがwww.k-in.co.jpの証明書を流用した」とのこと。
若しかしてhttpd.confの中に証明書ファイルの記述がないのか。
exstra/httpd-vhost.confに追加されるのだと思ったのだけどな。
とextraの中を覗くと新しいファイルが増えていた。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 |
<IfModule mod_ssl.c> <VirtualHost *:443> ServerName niwakan.k-in.co.jp DocumentRoot "/Volumes/Works/Library/www/niwakan" <Directory "/Volumes/Works/Library/www/niwakan"> Options FollowSymLinks AllowOverride All Require all granted </Directory> ErrorLog "/opt/local/var/log/apache2/niwakan-error_log" CustomLog "/opt/local/var/log/apache2/niwakan-access_log" common SSLCertificateFile /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/fullchain.pem SSLCertificateKeyFile /opt/local/etc/letsencrypt/live/niwakan.k-in.co.jp/privkey.pem Include /opt/local/etc/letsencrypt/options-ssl-apache.conf </VirtualHost> </IfModule> |
そっか、別ファイルになるんだね。
なので、httpd.confに、httpd-vhosts.confの後へ追加する。
そしてapachectl restart。
さてどうなりますことか。
結果。

無事に読み込めるようになりました。
当然、証明書を確認します。
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 |
% openssl s_client -connect niwakan.k-in.co.jp:443 Connecting to 192.168.0.35 CONNECTED(00000005) depth=3 C=US, O=Internet Security Research Group, CN=ISRG Root X2 verify return:1 depth=2 C=US, O=ISRG, CN=Root YE verify return:1 depth=1 C=US, O=Let's Encrypt, CN=YE2 verify return:1 depth=0 CN=niwakan.k-in.co.jp verify return:1 --- Certificate chain 0 s:CN=niwakan.k-in.co.jp i:C=US, O=Let's Encrypt, CN=YE2 a:PKEY: EC, (prime256v1); sigalg: ecdsa-with-SHA384 v:NotBefore: Sep 8 08:27:08 2026 GMT; NotAfter: Dec 7 08:27:07 2026 GMT 1 s:C=US, O=Let's Encrypt, CN=YE2 i:C=US, O=ISRG, CN=Root YE a:PKEY: EC, (secp384r1); sigalg: ecdsa-with-SHA384 v:NotBefore: Sep 3 00:00:00 2025 GMT; NotAfter: Sep 2 23:59:59 2028 GMT 2 s:C=US, O=ISRG, CN=Root YE i:C=US, O=Internet Security Research Group, CN=ISRG Root X2 a:PKEY: EC, (secp384r1); sigalg: ecdsa-with-SHA384 v:NotBefore: May 13 00:00:00 2026 GMT; NotAfter: Sep 2 23:59:59 2032 GMT 3 s:C=US, O=Internet Security Research Group, CN=ISRG Root X2 i:C=US, O=Internet Security Research Group, CN=ISRG Root X1 a:PKEY: EC, (secp384r1); sigalg: sha256WithRSAEncryption v:NotBefore: May 13 00:00:00 2026 GMT; NotAfter: Sep 2 23:59:59 2032 GMT --- |
さて、タイトルの「Googleのサイト証明書を取得してみる(2)」ですが、証明書はInternet Security Research Groupに発行して貰えました。
Googleコンソールの設定、何処へ行った?

