snap list
No snaps are installed yet. Try 'snap install hello-world'.
snap install hello-world
2021-04-29T15:04:41+09:00 INFO Waiting for automatic snapd restart...
hello-world 6.4 from Canonical? installed
You must
agree in order to register with the ACME server. Do you agree?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: y
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Would you be willing, once your first certificate is successfully issued, to
share your email address with the Electronic Frontier Foundation, a founding
partner of the Let's Encrypt project and the non-profit organization that
develops Certbot? We'd like to send you email about our work encrypting the web,
EFF news, campaigns, and ways to support digital freedom.
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
(Y)es/(N)o: y
Account registered.
Requesting a certificate for test01.tech-memo.net
Performing the following challenges:
http-01 challenge for test01.tech-memo.net
Using the webroot path /var/www/test01.tech-memo.net for all unmatched domains.
Waiting for verification...
Challenge failed for domain test01.tech-memo.net
http-01 challenge for test01.tech-memo.net
Cleaning up challenges
Some challenges have failed.
IMPORTANT NOTES:
- The following errors were reported by the server:
Domain: test01.tech-memo.net
Type: unauthorized
Detail: Invalid response from
http://test01.tech-memo.net/.well-known/acme-challenge/oitx1M2wHMoe_jDy4FPqECTF-oOVyE55mdSt97Bt_CY
[153.127.43.67]: "<!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML
2.0//EN\">\n<html><head>\n<title>404 Not
Found</title>\n</head><body>\n<h1>Not Found</h1>\n<p"
To fix these errors, please make sure that your domain name was
entered correctly and the DNS A/AAAA record(s) for that domain
contain(s) the right IP address.
Apacheを停止して再度実行。
service httpd stop
Redirecting to /bin/systemctl stop httpd.service
うまくいった。
certbot certonly --webroot -w /var/www/test01.tech-memo.net -d test01.tech-memo.net
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator webroot, Installer None
Requesting a certificate for test01.tech-memo.net
Performing the following challenges:
http-01 challenge for test01.tech-memo.net
Using the webroot path /var/www/html for all unmatched domains.
Waiting for verification...
Cleaning up challenges
Subscribe to the EFF mailing list (email: webmaster@tech-memo.net).
We were unable to subscribe you the EFF mailing list because your e-mail address appears to be invalid. You can try again later by visiting https://act.eff.org.
IMPORTANT NOTES:
- Congratulations! Your certificate and chain have been saved at:
/etc/letsencrypt/live/test01.tech-memo.net/fullchain.pem
Your key file has been saved at:
/etc/letsencrypt/live/test01.tech-memo.net/privkey.pem
Your certificate will expire on 2021-07-28. To obtain a new or
tweaked version of this certificate in the future, simply run
certbot again. To non-interactively renew *all* of your
certificates, run "certbot renew"
- If you like Certbot, please consider supporting our work by:
Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate
Donating to EFF: https://eff.org/donate-le
以下のコマンドで自動更新が行われるか確認し、Apacheを起動。
残りはmod_sslのインストールとApache側の設定。
systemctl status snap.certbot.renew.timer
● snap.certbot.renew.timer - Timer renew for snap application certbot.renew
Loaded: loaded (/etc/systemd/system/snap.certbot.renew.timer; enabled; vendor preset: disabled)
Active: active (waiting) since Thu 2021-04-29 15:10:39 JST; 2h 57min ago
Trigger: Fri 2021-04-30 02:35:00 JST; 8h left
Apr 29 15:10:39 ik1-419-41813.vs.sakura.ne.jp systemd[1]: Started Timer renew for snap application certbot.renew.
systemctl cat snap.certbot.renew.timer
/etc/systemd/system/snap.certbot.renew.timer
[Unit]
# Auto-generated, DO NOT EDIT
Description=Timer renew for snap application certbot.renew
Requires=var-lib-snapd-snap-certbot-1093.mount
After=var-lib-snapd-snap-certbot-1093.mount
X-Snappy=yes
[Timer]
Unit=snap.certbot.renew.service
OnCalendar=*-*-* 02:35
OnCalendar=*-*-* 16:52
[Install]
WantedBy=timers.target
apachectl configtest
AH00526: Syntax error on line 85 of /etc/httpd/conf.d/ssl.conf:
SSLCertificateFile: file '/etc/pki/tls/certs/localhost.crt' does not exist or is empty
コメント