๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๊ฐœ๋ฐœ๊ธฐ/OS & Server

[Linux] Certbot๋ฅผ ์ด์šฉํ•œ Let's encrypt SSL์ธ์ฆ์„œ ๋„๋ฉ”์ธ ์ถ”๊ฐ€๋ฐฉ๋ฒ•

by ๋™ ๋”” 2025. 2. 24.

โœ… ์‹ ๊ทœ ๋„๋ฉ”์ธ ์ƒ์„ฑ ๋ช…๋ น์–ด

certbot --apache -d mainservice.kr -d j.mainservice .kr -d c.mainservice.kr -d i.mainservice.kr

์ฒซ๋ฒˆ์งธ ์ ์€ ๋„๋ฉ”์ธ mainservice.kr์€ ์ฒด์ธ๋ช…์œผ๋กœ ์ง€์ •๋œ๋‹ค.

๋„๋ฉ”์ธ ๋“ฑ๋ก ํ›„ /etc/letsencrypt/live ์ ‘์† ์‹œ ์ฒด์ธ๋ช…์œผ๋กœ ํŒŒ์ผ์ด ์ƒ์„ฑ๋œ๋‹ค

d ์„œ๋ธŒ๋„๋ฉ”์ธ1 -d ์„œ๋ธŒ๋„๋ฉ”์ธ2 ํ˜•ํƒœ๋กœ ๋“ฑ๋ก

 

 


โœ… ๊ธฐ์กด ๋„๋ฉ”์ธ์— ๋„๋ฉ”์ธ ์ถ”๊ฐ€

certbot –cert-name mainservice.kr –d j.mainservice kr –d c.mainservice.kr –d i.mainservice.kr –d p.mainservice .kr

 

update ์„ ํƒํ•˜์—ฌ ๋„๋ฉ”์ธ ์ถ”๊ฐ€ ๋“ฑ๋ก

๋ช…๋ น์–ด ์ž…๋ ฅ ์‹œ ์‚ญ์ œํ•˜๊ณ  ์‹ถ์€ ๋„๋ฉ”์ธ์€ ์ œ์™ธํ•˜๋ฉด ๋œ๋‹ค.

ex) c.mainservice.kr ๋ฅผ ์‚ญ์ œํ•˜๊ณ   p.mainservice .kr ๋ฅผ ์ถ”๊ฐ€ํ•œ๋‹ค๋ฉด

certbot –cert-name mainservice.kr –d j.mainservice kr –d c.mainservice.kr –d i.mainservice.kr –d p.mainservice.kr

 


(SERVER 72) port8080 ์„œ๋น„์Šค(I) :  i.mainservice.kr

(SERVER 72) port30xx ์„œ๋น„์Šค(P) : p.mainservice.kr

(SERVER 32) ๋ฉ”์ธ์„œ๋ฒ„ : mainservice.kr

 

๐Ÿ’ก (SERVER 32) httpd.conf

=> con.fํด๋”์˜ *.confํŒŒ์ผ๋“ค์„ ํ•จ๊ป˜ ์ฐธ์กฐ

 

๐Ÿ’ก (SERVER 32) conf.d ํŒŒ์ผ๋“ค

 

๐Ÿ’ก (SERVER 32) vhost.conf ํŒŒ์ผ ์ผ๋ถ€

=> port80, servername i.mainservice.kr ๋กœ ์ ‘์† ์‹œ port443์œผ๋กœ  rewrite

 

๐Ÿ’ก (SERVER 32) vhost-le-ssl.conf ํŒŒ์ผ ์ผ๋ถ€

=> port443, servername i.mainservice.kr ๋กœ ์ ‘์† ์‹œ proxy์„ค์ •