{"id":19688,"date":"2017-09-01T06:13:47","date_gmt":"2017-08-31T22:13:47","guid":{"rendered":"https:\/\/2blog.ilc.edu.tw\/25793\/2017\/09\/01\/debian-ubuntu-%e5%ae%89%e8%a3%9d-lets-encrypt-%e5%88%b0-apache\/"},"modified":"2021-03-18T17:25:08","modified_gmt":"2021-03-18T09:25:08","slug":"debian-ubuntu-%e5%ae%89%e8%a3%9d-lets-encrypt-%e5%88%b0-apache","status":"publish","type":"post","link":"https:\/\/2blog.ilc.edu.tw\/25793\/2017\/09\/01\/debian-ubuntu-%e5%ae%89%e8%a3%9d-lets-encrypt-%e5%88%b0-apache\/","title":{"rendered":"Debian \/ Ubuntu \u5b89\u88dd Let\u2019s Encrypt \u5230 Apache"},"content":{"rendered":"<p>\u53c3\u8003\u7db2\u7ad9\uff1a<br \/><a href=\"https:\/\/www.phpini.com\/linux\/debian-ubuntu-install-lets-encrypt\" target=\"_blank\" rel=\"noopener noreferrer\">Debian \/ Ubuntu \u5b89\u88dd Let\u2019s Encrypt \u5230 Apache \u2013 Linux \u6280\u8853\u624b\u672d<\/a><\/p>\n<p>1. \u5b89\u88dd Apache Web Server<br \/># <span style=\"color: #ff0000\">apt-get install apache2<\/span><\/p>\n<p>2. \u555f\u7528 SSL \u6a21\u7d44\u4e26\u91cd\u65b0\u555f\u52d5 Apache Web Server<br \/># <span style=\"color: #ff0000\">a2enmod ssl<\/span><br \/>Considering dependency setenvif for ssl:<br \/>Module setenvif already enabled<br \/>Considering dependency mime for ssl:<br \/>Module mime already enabled<br \/>Considering dependency socache_shmcb for ssl:<br \/>Enabling module socache_shmcb.<br \/>Enabling module ssl.<br \/>See \/usr\/share\/doc\/apache2\/README.Debian.gz on how to configure SSL and create self-signed certificates.<br \/>To activate the new configuration, you need to run:<br \/>\u00a0 service apache2 restart<\/p>\n<p># <span style=\"color: #ff0000\">a2ensite default-ssl.conf<\/span><br \/>Enabling site default-ssl.<br \/>To activate the new configuration, you need to run:<br \/>\u00a0 service apache2 reload<\/p>\n<p># <span style=\"color: #ff0000\">\/etc\/init.d\/apache2 restart<\/span><br \/>or<br \/># <span style=\"color: #ff0000\">systemctl restart apache2.service<\/span>[@more@]3. \u5b89\u88dd git \u5957\u4ef6<br \/># <span style=\"color: #ff0000\">apt-get install git<\/span><\/p>\n<p>4. \u4e0b\u8f09 Let\u2019s Encrypt \u7684\u76ee\u9304<br \/># <span style=\"color: #ff0000\">cd \/usr\/local<\/span><br \/># <span style=\"color: #ff0000\">git clone https:\/\/github.com\/letsencrypt\/letsencrypt<\/span><br \/>Cloning into &#8216;letsencrypt&#8217;&#8230;<br \/>remote: Counting objects: 43808, done.<br \/>remote: Compressing objects: 100% (76\/76), done.<br \/>remote: Total 43808 (delta 40), reused 0 (delta 0), pack-reused 43732<br \/>Receiving objects: 100% (43808\/43808), 12.74 MiB | 2.16 MiB\/s, done.<br \/>Resolving deltas: 100% (31283\/31283), done.<br \/>Checking connectivity&#8230; done.<\/p>\n<p>5. \u7522\u751f\u6191\u8b49<br \/># .\/letsencrypt-auto &#8211;apache -d test.ilc.edu.tw -d www.test.ilc.edu.tw<\/p>\n<p>Enter email address (used for urgent renewal and security notices) (Enter &#8216;c&#8217; to<br \/>cancel):<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>Please read the Terms of Service at<br \/>https:\/\/letsencrypt.org\/documents\/LE-SA-v1.1.1-August-1-2016.pdf. You must agree<br \/>in order to register with the ACME server at<br \/>https:\/\/acme-v01.api.letsencrypt.org\/directory<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>(A)gree\/(C)ancel: A<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>Would you be willing to share your email address with the Electronic Frontier<br \/>Foundation, a founding partner of the Let&#8217;s Encrypt project and the non-profit<br \/>organization that develops Certbot? We&#8217;d like to send you email about EFF and<br \/>our work to encrypt the web, protect its users and defend digital rights.<br \/>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>(Y)es\/(N)o: Y<br \/>Obtaining a new certificate<br \/>Performing the following challenges:<br \/>tls-sni-01 challenge for test.ilc.edu.tw<br \/>tls-sni-01 challenge for www.test.ilc.edu.tw<br \/>Waiting for verification&#8230;<br \/>Cleaning up challenges<br \/>Failed authorization procedure. nxi.tces.ilc.edu.tw (tls-sni-01): urn:acme:error:connection :: The server could not connect to the client to verify the domain :: Failed to connect to 192.168.1.1:443 for TLS-SNI-01 challenge<\/p>\n<p>IMPORTANT NOTES:<br \/>\u00a0&#8211; If you lose your account credentials, you can recover through<br \/>\u00a0\u00a0 e-mails sent to t850008@gmail.com.<br \/>\u00a0&#8211; The following errors were reported by the server:<\/p>\n<p>\u00a0\u00a0 Domain: www.test.ilc.edu.tw<br \/>\u00a0\u00a0 Type:\u00a0\u00a0 connection<br \/>\u00a0\u00a0 Detail: Failed to connect to 192.168.1.1:443 for TLS-SNI-01<br \/>\u00a0\u00a0 challenge<\/p>\n<p>\u00a0\u00a0 To fix these errors, please make sure that your domain name was<br \/>\u00a0\u00a0 entered correctly and the DNS A record(s) for that domain<br \/>\u00a0\u00a0 contain(s) the right IP address. Additionally, please check that<br \/>\u00a0\u00a0 your computer has a publicly routable IP address and that no<br \/>\u00a0\u00a0 firewalls are preventing the server from communicating with the<br \/>\u00a0\u00a0 client. If you&#8217;re using the webroot plugin, you should also verify<br \/>\u00a0\u00a0 that you are serving files from the webroot path you provided.<br \/>\u00a0&#8211; Your account credentials have been saved in your Certbot<br \/>\u00a0\u00a0 configuration directory at \/etc\/letsencrypt. You should make a<br \/>\u00a0\u00a0 secure backup of this folder now. This configuration directory will<br \/>\u00a0\u00a0 also contain certificates and private keys obtained by Certbot so<br \/>\u00a0\u00a0 making regular backups of this folder is ideal.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u53c3\u8003\u7db2\u7ad9\uff1aDebian \/ Ubuntu \u5b89\u88dd Let\u2019s Encrypt \u5230 Apache \u2013 Linux &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/2blog.ilc.edu.tw\/25793\/2017\/09\/01\/debian-ubuntu-%e5%ae%89%e8%a3%9d-lets-encrypt-%e5%88%b0-apache\/\" class=\"more-link\">\u95b1\u8b80\u5168\u6587<span class=\"screen-reader-text\">\u3008Debian \/ Ubuntu \u5b89\u88dd Let\u2019s Encrypt \u5230 Apache\u3009<\/span><\/a><\/p>\n","protected":false},"author":55,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[179,119,137],"tags":[],"class_list":["post-19688","post","type-post","status-publish","format-standard","hentry","category-c-87877","category-c-78464","category-c-78482"],"meta_key":{"_pingme":["1"],"_encloseme":["1"],"lt_post_id":["686876"]},"_links":{"self":[{"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/posts\/19688"}],"collection":[{"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/comments?post=19688"}],"version-history":[{"count":1,"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/posts\/19688\/revisions"}],"predecessor-version":[{"id":21184,"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/posts\/19688\/revisions\/21184"}],"wp:attachment":[{"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/media?parent=19688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/categories?post=19688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/2blog.ilc.edu.tw\/25793\/wp-json\/wp\/v2\/tags?post=19688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}