{"id":231,"date":"2022-12-14T13:31:04","date_gmt":"2023-06-14T16:01:32","guid":{"rendered":"https:\/\/www.silicloud.com\/ja\/blog\/index.php\/2023\/11\/30\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/"},"modified":"2025-07-31T21:50:01","modified_gmt":"2025-07-31T12:50:01","slug":"rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95","status":"publish","type":"post","link":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/","title":{"rendered":"Rocky Linux 9\u3067Let&#8217;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5"},"content":{"rendered":"<h3>\u306f\u3058\u3081\u306b<\/h3>\n<p>Let\u2019s Encrypt\u306f\u3001\u7121\u6599\u306eTLS\/SSL\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u304a\u3088\u3073\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u624b\u6bb5\u3092\u63d0\u4f9b\u3059\u308b\u8a3c\u660e\u66f8\u767a\u884c\u6a5f\u95a2\uff08CA\uff09\u3067\u3042\u308a\u3001\u305d\u308c\u306b\u3088\u308a\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u6697\u53f7\u5316\u3055\u308c\u305fHTTPS\u3092\u5b9f\u73fe\u3057\u307e\u3059\u3002Certbot\u3068\u547c\u3070\u308c\u308b\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3092\u63d0\u4f9b\u3059\u308b\u3053\u3068\u3067\u3001\u5fc5\u8981\u306a\u624b\u9806\u306e\u307b\u3068\u3093\u3069\uff08\u3082\u3057\u304f\u306f\u3059\u3079\u3066\uff09\u3092\u81ea\u52d5\u5316\u3057\u3001\u30d7\u30ed\u30bb\u30b9\u3092\u7c21\u7565\u5316\u3057\u3066\u3044\u307e\u3059\u3002\u73fe\u5728\u3001\u8a3c\u660e\u66f8\u306e\u53d6\u5f97\u304a\u3088\u3073\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u624b\u7d9a\u304d\u306f\u3001Apache\u3068Nginx\u306e\u4e21\u65b9\u3067\u5b8c\u5168\u306b\u81ea\u52d5\u5316\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u306f\u3001Rocky Linux 9\u4e0a\u306eNginx\u306b\u7121\u6599\u306eSSL\u8a3c\u660e\u66f8\u3092\u5165\u624b\u3057\u3001\u8a3c\u660e\u66f8\u3092\u81ea\u52d5\u7684\u306b\u66f4\u65b0\u3059\u308b\u65b9\u6cd5\u3092Certbot\u3092\u4f7f\u7528\u3057\u3066\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u306f\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u4ee3\u308f\u308a\u306b\u5225\u306eNginx\u30b5\u30fc\u30d0\u30fc\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u4f7f\u7528\u3057\u307e\u3059\u3002\u5404\u30c9\u30e1\u30a4\u30f3\u3054\u3068\u306b\u65b0\u3057\u3044Nginx\u30b5\u30fc\u30d0\u30fc\u30d6\u30ed\u30c3\u30af\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u308c\u306b\u3088\u308a\u3001\u4e00\u822c\u7684\u306a\u30df\u30b9\u3092\u907f\u3051\u308b\u3053\u3068\u304c\u3067\u304d\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u30d5\u30a9\u30fc\u30eb\u30d0\u30c3\u30af\u8a2d\u5b9a\u3068\u3057\u3066\u4fdd\u6301\u3055\u308c\u307e\u3059\u3002<\/p>\n<h2>\u524d\u63d0\u6761\u4ef6<\/h2>\n<p>\u3053\u306e\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3092\u5b9f\u884c\u3059\u308b\u306b\u306f\u3001\u6b21\u306e\u3082\u306e\u304c\u5fc5\u8981\u3067\u3059\uff1a<\/p>\n<ul class=\"post-ul\">\n<li>One Rocky Linux 9 server set up by following this initial server setup for Rocky Linux 9 tutorial, including a sudo-enabled non-root user and a firewall.<\/li>\n<li>A registered domain name. This tutorial will use example.com throughout. You can purchase a domain name from Namecheap, get one for free with Freenom, or use the domain registrar of your choice.<\/li>\n<li>Both of the following DNS records set up for your server. If you are using Silicon Cloud, please see our DNS documentation for details on how to add them.An A record with example.com pointing to your server\u2019s public IP address.<br \/>\nAn A record with www.example.com pointing to your server\u2019s public IP address.<\/li>\n<li>Nginx installed by following How To Install Nginx on Rocky Linux 9. Be sure that you have a server block for your domain. This tutorial will use \/etc\/nginx\/sites-available\/example.com as an example.<\/li>\n<\/ul>\n<h2>\u30b9\u30c6\u30c3\u30d71 \u2014 Certbot\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h2>\n<p>\u6700\u521d\u306b\u3001certbot\u30bd\u30d5\u30c8\u30a6\u30a7\u30a2\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u975e\u30eb\u30fc\u30c8\u30e6\u30fc\u30b6\u30fc\u3068\u3057\u3066Rocky Linux 8\u30de\u30b7\u30f3\u306b\u30ed\u30b0\u30a4\u30f3\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">ssh<\/span> <mark>sammy<\/mark>@<mark>your_server_ip<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30c7\u30d5\u30a9\u30eb\u30c8\u3067\u306f\u3001\u30d1\u30c3\u30b1\u30fc\u30b8\u30de\u30cd\u30fc\u30b8\u30e3\u30fc\u3092\u901a\u3058\u3066Certbot\u30d1\u30c3\u30b1\u30fc\u30b8\u306f\u5229\u7528\u3067\u304d\u307e\u305b\u3093\u3002Certbot\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u306b\u306f\u3001EPEL\u30ea\u30dd\u30b8\u30c8\u30ea\u3092\u6709\u52b9\u306b\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>Rocky Linux 9\u306eEPEL\u30ea\u30dd\u30b8\u30c8\u30ea\u3092\u8ffd\u52a0\u3059\u308b\u306b\u306f\u3001\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> dnf <span class=\"token function\">install<\/span> epel-release<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u78ba\u8a8d\u3092\u6c42\u3081\u3089\u308c\u305f\u3089\u3001y\u3068\u30bf\u30a4\u30d7\u3057\u3066\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u8ffd\u52a0\u306e\u30ea\u30dd\u30b8\u30c8\u30ea\u3078\u306e\u30a2\u30af\u30bb\u30b9\u304c\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u3063\u305f\u306e\u3067\u3001\u5fc5\u8981\u306a\u30d1\u30c3\u30b1\u30fc\u30b8\u3092\u3059\u3079\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> dnf <span class=\"token function\">install<\/span> certbot python3-certbot-nginx<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u4ee5\u4e0b\u306f\u3001\u30d7\u30ed\u30b0\u30e9\u30e0\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u306b\u5fc5\u8981\u306aCertbot\u81ea\u4f53\u3068\u3001Certbot\u306eNginx\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u307e\u3059\u3002<\/p>\n<p>\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u306e\u30d7\u30ed\u30bb\u30b9\u4e2d\u306b\u3001GPG\u30ad\u30fc\u306e\u30a4\u30f3\u30dd\u30fc\u30c8\u306b\u3064\u3044\u3066\u5c0b\u306d\u3089\u308c\u307e\u3059\u306e\u3067\u3001\u305d\u308c\u3092\u78ba\u8a8d\u3057\u3066\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3092\u5b8c\u4e86\u3055\u305b\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>Certbot\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u305f\u306e\u3067\u3001\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3059\u308b\u305f\u3081\u306b\u5b9f\u884c\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n<h2>\u30b9\u30c6\u30c3\u30d72\uff1aNginx\u306e\u8a2d\u5b9a\u3092\u78ba\u8a8d\u3059\u308b\u3002<\/h2>\n<p>Certbot\u306f\u3001\u81ea\u52d5\u7684\u306bSSL\u3092\u8a2d\u5b9a\u3059\u308b\u305f\u3081\u306b\u3001Nginx\u306e\u8a2d\u5b9a\u306b\u304a\u3044\u3066\u6b63\u3057\u3044\u30b5\u30fc\u30d0\u30fc\u30d6\u30ed\u30c3\u30af\u3092\u898b\u3064\u3051\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u5177\u4f53\u7684\u306b\u306f\u3001\u8981\u6c42\u3059\u308b\u30c9\u30e1\u30a4\u30f3\u306b\u4e00\u81f4\u3059\u308bserver_name\u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u3092\u63a2\u3057\u307e\u3059\u3002<\/p>\n<p>\u3082\u3057Nginx\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3067\u30b5\u30fc\u30d0\u30fc\u30d6\u30ed\u30c3\u30af\u306e\u8a2d\u5b9a\u624b\u9806\u306b\u5f93\u3063\u305f\u5834\u5408\u3001\/etc\/nginx\/conf.d\/example.com\u306b\u30c9\u30e1\u30a4\u30f3\u306e\u305f\u3081\u306e\u30b5\u30fc\u30d0\u30fc\u30d6\u30ed\u30c3\u30af\u304c\u3042\u308a\u3001server_name\u30c7\u30a3\u30ec\u30af\u30c6\u30a3\u30d6\u3082\u9069\u5207\u306b\u8a2d\u5b9a\u3055\u308c\u3066\u3044\u308b\u306f\u305a\u3067\u3059\u3002<\/p>\n<p>\u78ba\u8a8d\u3059\u308b\u305f\u3081\u306b\u3001nano\u3084\u304a\u6c17\u306b\u5165\u308a\u306e\u30c6\u30ad\u30b9\u30c8\u30a8\u30c7\u30a3\u30bf\u3092\u4f7f\u3063\u3066\u3001\u30c9\u30e1\u30a4\u30f3\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u958b\u3044\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">nano<\/span> \/etc\/nginx\/conf.d\/<mark>example.com<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u65e2\u5b58\u306eserver_name\u306e\u884c\u3092\u898b\u3064\u3051\u3066\u304f\u3060\u3055\u3044\u3002\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u898b\u3048\u308b\u306f\u305a\u3067\u3059\uff1a<\/p>\n<div>\/etc\/nginx\/conf.d\/example.com \u306e\u5185\u5bb9\u3092\u65e5\u672c\u8a9e\u3067\u8ff0\u3079\u308b\u3068\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002<\/div>\n<pre class=\"post-pre\"><code>...\r\n<span class=\"token directive\"><span class=\"token keyword\">server_name<\/span> <mark>example.com<\/mark> www.<mark>example.com<\/mark><\/span><span class=\"token punctuation\">;<\/span>\r\n...\r\n<\/code><\/pre>\n<p>\u3082\u3057\u8a72\u5f53\u3059\u308b\u5834\u5408\u306f\u3001\u30a8\u30c7\u30a3\u30bf\u30fc\u3092\u7d42\u4e86\u3057\u3001\u6b21\u306e\u30b9\u30c6\u30c3\u30d7\u306b\u9032\u3093\u3067\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u3082\u3057\u9069\u7528\u3055\u308c\u3066\u3044\u306a\u3051\u308c\u3070\u3001\u305d\u308c\u306b\u5408\u308f\u305b\u3066\u66f4\u65b0\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u305d\u306e\u5f8c\u3001\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3001\u30a8\u30c7\u30a3\u30bf\u3092\u7d42\u4e86\u3057\u3001\u8a2d\u5b9a\u306e\u7de8\u96c6\u304c\u6b63\u3057\u3044\u69cb\u6587\u304b\u3069\u3046\u304b\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> nginx <span class=\"token parameter variable\">-t<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30a8\u30e9\u30fc\u304c\u767a\u751f\u3057\u305f\u5834\u5408\u306b\u306f\u3001\u30b5\u30fc\u30d0\u30fc\u30d6\u30ed\u30c3\u30af\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u518d\u5ea6\u958b\u304d\u3001\u30bf\u30a4\u30d7\u30df\u30b9\u3084\u6b20\u3051\u3066\u3044\u308b\u6587\u5b57\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u306e\u69cb\u6587\u304c\u6b63\u3057\u3044\u5834\u5408\u306f\u3001Nginx\u3092\u518d\u8aad\u307f\u8fbc\u307f\u3057\u3066\u65b0\u3057\u3044\u8a2d\u5b9a\u3092\u30ed\u30fc\u30c9\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> systemctl reload nginx<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>Certbot\u306f\u81ea\u52d5\u7684\u306b\u6b63\u3057\u3044\u30b5\u30fc\u30d0\u30fc\u30d6\u30ed\u30c3\u30af\u3092\u898b\u3064\u3051\u3066\u66f4\u65b0\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<p>\u6b21\u306b\u3001\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u3092\u66f4\u65b0\u3057\u3066HTTPS\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u8a31\u53ef\u3057\u307e\u3057\u3087\u3046\u3002<\/p>\n<h2>\u30b9\u30c6\u30c3\u30d73\uff1a\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u30eb\u30fc\u30eb\u3092\u30a2\u30c3\u30d7\u30c7\u30fc\u30c8\u3059\u308b\u3002<\/h2>\n<p>\u30cd\u30a4\u30c6\u30a3\u30d6\u306e\u65e5\u672c\u8a9e\u3067\u4ee5\u4e0b\u306e\u6587\u3092\u8a00\u3044\u63db\u3048\u307e\u3059\u30021\u3064\u306e\u30aa\u30d7\u30b7\u30e7\u30f3\u3060\u3051\u5fc5\u8981\u3067\u3059\u3002<br \/>\n\u300c\u524d\u63d0\u306e\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u306b\u3088\u3063\u3066firewalld\u304c\u6709\u52b9\u306b\u306a\u3063\u3066\u3044\u308b\u305f\u3081\u3001Nginx\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u3067\u5916\u90e8\u63a5\u7d9a\u3092\u8a31\u53ef\u3059\u308b\u305f\u3081\u306b\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u306e\u8a2d\u5b9a\u3092\u8abf\u6574\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002\u300d<\/p>\n<p>\u65e2\u306b\u6709\u52b9\u306b\u306a\u3063\u3066\u3044\u308b\u30b5\u30fc\u30d3\u30b9\u3092\u78ba\u8a8d\u3059\u308b\u306b\u306f\u3001\u6b21\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> firewall-cmd <span class=\"token parameter variable\">&#8211;permanent<\/span> &#8211;list-all<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u3053\u3046\u3044\u3046\u51fa\u529b\u304c\u53d7\u3051\u53d6\u308c\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">Output<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>public target: default icmp-block-inversion: no interfaces: sources: services: cockpit dhcpv6-client <mark>http<\/mark> ssh ports: protocols: masquerade: no forward-ports: source-ports: icmp-blocks: rich rules:<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u300c\u3082\u3057\u30b5\u30fc\u30d3\u30b9\u30ea\u30b9\u30c8\u306bhttp\u304c\u8868\u793a\u3055\u308c\u3066\u3044\u306a\u3044\u5834\u5408\u306f\u3001\u5b9f\u884c\u3057\u3066\u6709\u52b9\u306b\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u300d<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> firewall-cmd <span class=\"token parameter variable\">&#8211;permanent<\/span> &#8211;add-service<span class=\"token operator\">=<\/span>http<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>https\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u8a31\u53ef\u3059\u308b\u305f\u3081\u306b\u3001\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> firewall-cmd <span class=\"token parameter variable\">&#8211;permanent<\/span> &#8211;add-service<span class=\"token operator\">=<\/span>https<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u5909\u66f4\u3092\u9069\u7528\u3059\u308b\u305f\u3081\u306b\u3001\u30d5\u30a1\u30a4\u30a2\u30a6\u30a9\u30fc\u30eb\u30b5\u30fc\u30d3\u30b9\u3092\u30ea\u30ed\u30fc\u30c9\u3059\u308b\u5fc5\u8981\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> firewall-cmd <span class=\"token parameter variable\">&#8211;reload<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u30b5\u30fc\u30d0\u30fc\u3067https\u30c8\u30e9\u30d5\u30a3\u30c3\u30af\u3092\u958b\u59cb\u3057\u305f\u306e\u3067\u3001Certbot\u3092\u5b9f\u884c\u3057\u3066\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3059\u308b\u6e96\u5099\u304c\u6574\u3044\u307e\u3057\u305f\u3002<\/p>\n<h2>\u30b9\u30c6\u30c3\u30d74 &#8211; SSL\u8a3c\u660e\u66f8\u306e\u53d6\u5f97<\/h2>\n<p>Certbot\u306f\u3001\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u4ecb\u3057\u3066\u3055\u307e\u3056\u307e\u306a\u65b9\u6cd5\u3067SSL\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002Nginx\u30d7\u30e9\u30b0\u30a4\u30f3\u306f\u3001\u5fc5\u8981\u306a\u5834\u5408\u306bNginx\u3092\u518d\u69cb\u6210\u3057\u3066\u8a2d\u5b9a\u3092\u518d\u8aad\u307f\u8fbc\u307f\u3057\u307e\u3059\u3002\u3053\u306e\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u4f7f\u7528\u3059\u308b\u306b\u306f\u3001\u4ee5\u4e0b\u3092\u5165\u529b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> certbot <span class=\"token parameter variable\">&#8211;nginx<\/span> <span class=\"token parameter variable\">-d<\/span> <mark>example.com<\/mark> <span class=\"token parameter variable\">-d<\/span> <mark>www.example.com<\/mark><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u4ee5\u4e0b\u306e\u65e5\u672c\u8a9e\u3067\u306e\u6587\u8a00\u3092\u30cd\u30a4\u30c6\u30a3\u30d6\u306e\u8868\u73fe\u3067\u4e00\u3064\u306e\u30aa\u30d7\u30b7\u30e7\u30f3\u3067\u8a00\u3044\u63db\u3048\u307e\u3059\uff1a<br \/>\ncertbot\u3092&#8211;nginx\u30d7\u30e9\u30b0\u30a4\u30f3\u3092\u4f7f\u7528\u3057\u3066\u5b9f\u884c\u3057\u3001-d\u3092\u4f7f\u3063\u3066\u8a3c\u660e\u66f8\u306e\u6709\u52b9\u306a\u30c9\u30e1\u30a4\u30f3\u540d\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<\/p>\n<p>\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3068\u3001\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9\u306e\u5165\u529b\u3068\u5229\u7528\u898f\u7d04\u3078\u306e\u540c\u610f\u304c\u6c42\u3081\u3089\u308c\u307e\u3059\u3002\u305d\u308c\u3092\u5b8c\u4e86\u3057\u305f\u5f8c\u3001\u51e6\u7406\u304c\u6210\u529f\u3057\u305f\u3053\u3068\u3068\u3001\u8a3c\u660e\u66f8\u304c\u4fdd\u5b58\u3055\u308c\u3066\u3044\u308b\u5834\u6240\u3092\u793a\u3059\u30e1\u30c3\u30bb\u30fc\u30b8\u304c\u8868\u793a\u3055\u308c\u308b\u306f\u305a\u3067\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">Output<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>Successfully received certificate. Certificate is saved at: \/etc\/letsencrypt\/live\/<mark>your_domain<\/mark>\/fullchain.pem Key is saved at: \/etc\/letsencrypt\/live\/<mark>your_domain<\/mark>\/privkey.pem This certificate expires on 2022-12-15. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background. Deploying certificate Successfully deployed certificate for <mark>your_domain<\/mark> to \/etc\/nginx\/conf.d\/your_domain.conf Successfully deployed certificate for www.<mark>your_domain<\/mark> to \/etc\/nginx\/conf.d\/your_domain.conf Congratulations! You have successfully enabled HTTPS on https:\/\/<mark>your_domain<\/mark> and https:\/\/www.<mark>your_domain<\/mark> \u2026<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u3042\u306a\u305f\u306e\u8a3c\u660e\u66f8\u306f\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3055\u308c\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3001\u8aad\u307f\u8fbc\u307e\u308c\u307e\u3057\u305f\u3002\u305d\u3057\u3066\u3001\u3042\u306a\u305f\u306eNginx\u306e\u8a2d\u5b9a\u306b\u3088\u308a\u3001\u30a6\u30a7\u30d6\u306e\u30ea\u30af\u30a8\u30b9\u30c8\u306f\u81ea\u52d5\u7684\u306bhttps:\/\/\u3078\u306e\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u304c\u884c\u308f\u308c\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3059\u3002\u30a6\u30a7\u30d6\u30b5\u30a4\u30c8\u3092\u518d\u8aad\u307f\u8fbc\u307f\u3057\u3001\u30d6\u30e9\u30a6\u30b6\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30a4\u30f3\u30b8\u30b1\u30fc\u30bf\u3092\u78ba\u8a8d\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u901a\u5e38\u3001\u30ed\u30c3\u30af\u30a2\u30a4\u30b3\u30f3\u304c\u8868\u793a\u3055\u308c\u3001\u30b5\u30a4\u30c8\u304c\u9069\u5207\u306b\u4fdd\u8b77\u3055\u308c\u3066\u3044\u308b\u3053\u3068\u304c\u793a\u3055\u308c\u307e\u3059\u3002\u3082\u3057SSL Labs Server Test\u3067\u30b5\u30fc\u30d0\u3092\u30c6\u30b9\u30c8\u3059\u308b\u3068\u3001A\u306e\u8a55\u4fa1\u3092\u53d7\u3051\u308b\u306f\u305a\u3067\u3059\u3002<\/p>\n<p>\u66f4\u65b0\u30d7\u30ed\u30bb\u30b9\u306e\u30c6\u30b9\u30c8\u3092\u7d42\u3048\u307e\u3057\u3087\u3046\u3002<\/p>\n<h2>\u30b9\u30c6\u30c3\u30d75 &#8211; Certbot\u81ea\u52d5\u66f4\u65b0\u306e\u691c\u8a3c<\/h2>\n<p>Let&#8217;s Encrypt\u306e\u8a3c\u660e\u66f8\u306f90\u65e5\u9593\u6709\u52b9\u3067\u3059\u304c\u3001\u8aa4\u5dee\u3092\u8003\u616e\u3059\u308b\u305f\u3081\u306b\u8a3c\u660e\u66f8\u309260\u65e5\u3054\u3068\u306b\u66f4\u65b0\u3059\u308b\u3053\u3068\u3092\u63a8\u5968\u3057\u307e\u3059\u3002Certbot Let&#8217;s Encrypt\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u306b\u306f\u3001\u81ea\u52d5\u7684\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u3066\u3044\u308b\u8a3c\u660e\u66f8\u3092\u78ba\u8a8d\u3057\u3001\u6709\u52b9\u671f\u9650\u304c30\u65e5\u672a\u6e80\u306e\u5834\u5408\u306b\u306f\u81ea\u52d5\u7684\u306b\u66f4\u65b0\u3092\u8a66\u307f\u308b\u300crenew\u300d\u30b3\u30de\u30f3\u30c9\u304c\u3042\u308a\u307e\u3059\u3002<\/p>\n<p>\u3053\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308b\u3053\u3068\u3067\u3001\u8a3c\u660e\u66f8\u306e\u81ea\u52d5\u66f4\u65b0\u3092\u30c6\u30b9\u30c8\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> certbot renew &#8211;dry-run<\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u51fa\u529b\u306f\u3053\u308c\u306b\u4f3c\u3066\u3044\u308b\u3067\u3057\u3087\u3046\u3002 (Shutsuryoku wa kore ni nite iru deshou.)<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<div class=\"secondary-code-label\" title=\"Output\">Output<\/div>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>Saving debug log to \/var\/log\/letsencrypt\/letsencrypt.log &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; Processing \/etc\/letsencrypt\/renewal\/<mark>your_domain<\/mark>.conf &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; Cert not due for renewal, but simulating renewal for dry run Plugins selected: Authenticator nginx, Installer nginx Renewing an existing certificate Performing the following challenges: http-01 challenge for monitoring.pp.ua Waiting for verification&#8230; Cleaning up challenges &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; new certificate deployed with reload of nginx server; fullchain is \/etc\/letsencrypt\/live\/<mark>your_domain<\/mark>\/fullchain.pem &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; ** DRY RUN: simulating &#8216;certbot renew&#8217; close to cert expiry ** (The test certificates below have not been saved.) Congratulations, all renewals succeeded. The following certs have been renewed: \/etc\/letsencrypt\/live\/<mark>your_domain<\/mark>\/fullchain.pem (success) &#8230;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u8907\u6570\u306e\u30c9\u30e1\u30a4\u30f3\u3092\u542b\u3080\u675f\u306d\u3089\u308c\u305f\u8a3c\u660e\u66f8\u3092\u4f5c\u6210\u3057\u305f\u5834\u5408\u3001\u51fa\u529b\u3067\u306f\u57fa\u672c\u306e\u30c9\u30e1\u30a4\u30f3\u540d\u306e\u307f\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002\u305f\u3060\u3057\u3001\u305d\u306e\u8a3c\u660e\u66f8\u306b\u542b\u307e\u308c\u308b\u5168\u3066\u306e\u30c9\u30e1\u30a4\u30f3\u306b\u5bfe\u3057\u3066\u66f4\u65b0\u306f\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<p>\u8a3c\u660e\u66f8\u304c\u53e4\u304f\u306a\u308b\u3053\u3068\u3092\u9632\u3050\u5b9f\u7528\u7684\u306a\u65b9\u6cd5\u306f\u3001\u5b9a\u671f\u7684\u306b\u81ea\u52d5\u66f4\u65b0\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3059\u308bcron\u30b8\u30e7\u30d6\u3092\u4f5c\u6210\u3059\u308b\u3053\u3068\u3067\u3059\u3002\u66f4\u65b0\u306f\u3001\u307e\u305a\u6709\u52b9\u671f\u9650\u3092\u78ba\u8a8d\u3057\u3001\u8a3c\u660e\u66f8\u304c\u6709\u52b9\u671f\u9650\u307e\u306730\u65e5\u672a\u6e80\u306e\u5834\u5408\u306b\u306e\u307f\u66f4\u65b0\u3092\u5b9f\u884c\u3059\u308b\u305f\u3081\u3001\u6bce\u9031\u307e\u305f\u306f\u6bce\u65e5\u5b9f\u884c\u3055\u308c\u308bcron\u30b8\u30e7\u30d6\u3092\u4f5c\u6210\u3057\u3066\u3082\u5b89\u5168\u3067\u3059\u3002<\/p>\n<p>1\u3064\u306e\u30aa\u30d7\u30b7\u30e7\u30f3\u3067\u4ee5\u4e0b\u306e\u6587\u3092\u65e5\u672c\u8a9e\u3067\u8a00\u3044\u63db\u3048\u3066\u304f\u3060\u3055\u3044\uff1a<br \/>\n\u30af\u30ed\u30f3\u30bf\u30d6\u3092\u7de8\u96c6\u3057\u3066\u30011\u65e5\u306b2\u56de\u66f4\u65b0\u304c\u5b9f\u884c\u3055\u308c\u308b\u65b0\u3057\u3044\u30b8\u30e7\u30d6\u3092\u4f5c\u6210\u3057\u3066\u304f\u3060\u3055\u3044\u3002root\u30e6\u30fc\u30b6\u30fc\u306e\u305f\u3081\u306e\u30af\u30ed\u30f3\u30bf\u30d6\u3092\u7de8\u96c6\u3059\u308b\u306b\u306f\u3001\u6b21\u3092\u5b9f\u884c\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<ol>\n<li data-prefix=\"$\"><span class=\"token function\">sudo<\/span> <span class=\"token function\">crontab<\/span> <span class=\"token parameter variable\">-e<\/span><\/li>\n<\/ol>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre class=\"post-pre\"><code><\/code><\/pre>\n<p>\u3042\u306a\u305f\u306e\u30c6\u30ad\u30b9\u30c8\u30a8\u30c7\u30a3\u30bf\u306f\u3001\u30c7\u30d5\u30a9\u30eb\u30c8\u306e\u30af\u30ed\u30f3\u30bf\u30d6\u3092\u958b\u304d\u307e\u3059\u3002\u3053\u306e\u6642\u70b9\u3067\u306f\u7a7a\u306e\u30c6\u30ad\u30b9\u30c8\u30d5\u30a1\u30a4\u30eb\u3067\u3059\u3002i\u30ad\u30fc\u3092\u62bc\u3057\u3066\u633f\u5165\u30e2\u30fc\u30c9\u306b\u5165\u308a\u3001\u6b21\u306e\u884c\u3092\u8ffd\u52a0\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<div>\u30af\u30ed\u30f3\u30bf\u30d6<\/div>\n<pre class=\"post-pre\"><code>0 0,12 * * * python -c 'import random; import time; time.sleep(random.random() * 3600)' &amp;&amp; certbot renew --quiet\r\n<\/code><\/pre>\n<p>\u7d42\u4e86\u3057\u305f\u3089\u3001\u633f\u5165\u30e2\u30fc\u30c9\u3092\u7d42\u4e86\u3059\u308b\u305f\u3081\u306bESC\u30ad\u30fc\u3092\u62bc\u3057\u3001\u305d\u306e\u5f8c:wq\u3068\u5165\u529b\u3057\u3066ENTER\u30ad\u30fc\u3092\u62bc\u3057\u3066\u30d5\u30a1\u30a4\u30eb\u3092\u4fdd\u5b58\u3057\u3066\u7d42\u4e86\u3057\u3066\u304f\u3060\u3055\u3044\u3002\u3082\u3057\u3001\u30c6\u30ad\u30b9\u30c8\u30a8\u30c7\u30a3\u30bfVi\u3068\u305d\u306e\u5f8c\u7d99\u3067\u3042\u308bVim\u306b\u3064\u3044\u3066\u3082\u3063\u3068\u5b66\u3073\u305f\u3044\u306e\u3067\u3042\u308c\u3070\u3001\u5f53\u793e\u306e\u30af\u30e9\u30a6\u30c9\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u306eVim\u30c6\u30ad\u30b9\u30c8\u30a8\u30c7\u30a3\u30bf\u306e\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3068\u4f7f\u7528\u65b9\u6cd5\u30c1\u30e5\u30fc\u30c8\u30ea\u30a2\u30eb\u3092\u3054\u89a7\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u6bce\u65e5\u6b63\u5348\u3068\u6df1\u591c\u306b\u5b9f\u884c\u3055\u308c\u308b\u65b0\u3057\u3044cron\u30b8\u30e7\u30d6\u304c\u4f5c\u6210\u3055\u308c\u307e\u3059\u3002 python -c &#8216;import random; import time; time.sleep(random.random() * 3600)&#8217;\u306f\u3001\u66f4\u65b0\u30bf\u30b9\u30af\u306e\u305f\u3081\u306b1\u6642\u9593\u5185\u306e\u30e9\u30f3\u30c0\u30e0\u306a\u5206\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/p>\n<p>Certbot\u306e\u66f4\u65b0\u30b3\u30de\u30f3\u30c9\u306f\u3001\u30b7\u30b9\u30c6\u30e0\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u305f\u3059\u3079\u3066\u306e\u8a3c\u660e\u66f8\u3092\u78ba\u8a8d\u3057\u300130\u65e5\u4ee5\u5185\u306b\u671f\u9650\u304c\u5207\u308c\u308b\u3082\u306e\u3092\u66f4\u65b0\u3057\u307e\u3059\u3002&#8211;quiet\u306fCertbot\u306b\u60c5\u5831\u3092\u51fa\u529b\u305b\u305a\u3001\u30e6\u30fc\u30b6\u30fc\u5165\u529b\u3092\u5f85\u305f\u306a\u3044\u3088\u3046\u306b\u6307\u793a\u3057\u307e\u3059\u3002<\/p>\n<p>Certbot\u306e\u30c9\u30ad\u30e5\u30e1\u30f3\u30c6\u30fc\u30b7\u30e7\u30f3\u306b\u306f\u3001\u30ea\u30cb\u30e5\u30fc\u30a2\u30eb\u306b\u95a2\u3059\u308b\u3088\u308a\u8a73\u7d30\u306a\u60c5\u5831\u304c\u8a18\u8f09\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<h2>\u7d50\u8ad6<\/h2>\n<p>\u3053\u306e\u30ac\u30a4\u30c9\u3067\u306f\u3001Let&#8217;s Encrypt\u306e\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3067\u3042\u308bCertbot\u3092\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3057\u3001\u30c9\u30e1\u30a4\u30f3\u306eSSL\u8a3c\u660e\u66f8\u3092\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3057\u3001\u81ea\u52d5\u7684\u306a\u8a3c\u660e\u66f8\u306e\u66f4\u65b0\u3092\u8a2d\u5b9a\u3057\u307e\u3057\u305f\u3002Certbot\u306e\u4f7f\u7528\u65b9\u6cd5\u306b\u95a2\u3059\u308b\u8cea\u554f\u304c\u3042\u308b\u5834\u5408\u306f\u3001\u516c\u5f0f\u306eCertbot\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8\u3092\u53c2\u7167\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>\u6642\u3005\u3001\u91cd\u8981\u306a\u66f4\u65b0\u60c5\u5831\u3092\u5f97\u308b\u305f\u3081\u306b\u3001\u516c\u5f0f\u306eLet\u2019s Encrypt\u30d6\u30ed\u30b0\u3082\u30c1\u30a7\u30c3\u30af\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u306f\u3058\u3081\u306b Let\u2019s Encrypt\u306f\u3001\u7121\u6599\u306eTLS\/SSL\u8a3c\u660e\u66f8\u3092\u53d6\u5f97\u304a\u3088\u3073\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u624b\u6bb5\u3092\u63d0\u4f9b\u3059\u308b\u8a3c\u660e\u66f8\u767a\u884c\u6a5f\u95a2\uff08CA\uff09\u3067\u3042\u308a\u3001\u305d\u308c\u306b\u3088\u308a\u30a6\u30a7\u30d6\u30b5\u30fc\u30d0\u30fc\u4e0a\u3067\u6697\u53f7\u5316\u3055\u308c\u305fHTTPS\u3092\u5b9f\u73fe\u3057\u307e\u3059\u3002Certbot\u3068\u547c [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[58,26],"class_list":["post-231","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-linux","tag-26"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v21.5 (Yoast SEO v21.5) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Rocky Linux 9\u3067Let&#039;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5 - Blog - Silicon Cloud<\/title>\n<meta name=\"description\" content=\"Rocky Linux 9\u3067Let&#039;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9\u3067lets-encrypt\u3092\u4f7f\u7528\u3057\u3066nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u3059\u308b\u65b9\u6cd5\/\" \/>\n<meta property=\"og:locale\" content=\"ja_JP\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Rocky Linux 9\u3067Let&#039;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\" \/>\n<meta property=\"og:description\" content=\"Rocky Linux 9\u3067Let&#039;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9\u3067lets-encrypt\u3092\u4f7f\u7528\u3057\u3066nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u3059\u308b\u65b9\u6cd5\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog - Silicon Cloud\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-14T16:01:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-07-31T12:50:01+00:00\" \/>\n<meta name=\"author\" content=\"\u685c, \u6625\u6a39\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u57f7\u7b46\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"\u685c, \u6625\u6a39\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593\" \/>\n\t<meta name=\"twitter:data2\" content=\"18\u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/\",\"url\":\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/\",\"name\":\"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5 - Blog - Silicon Cloud\",\"isPartOf\":{\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#website\"},\"datePublished\":\"2023-06-14T16:01:32+00:00\",\"dateModified\":\"2025-07-31T12:50:01+00:00\",\"author\":{\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/ff22288af1a5455571aff7586b0fb341\"},\"description\":\"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002\",\"breadcrumb\":{\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/#breadcrumb\"},\"inLanguage\":\"ja\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.silicloud.com\/ja\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Rocky Linux 9\u3067Let&#8217;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#website\",\"url\":\"https:\/\/www.silicloud.com\/ja\/blog\/\",\"name\":\"Blog - Silicon Cloud\",\"description\":\"\",\"inLanguage\":\"ja\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/ff22288af1a5455571aff7586b0fb341\",\"name\":\"\u685c, \u6625\u6a39\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/cee48863f3d4fd7fef222498f3e71b82312aee42b7257a2dbde56394ca4e19de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/cee48863f3d4fd7fef222498f3e71b82312aee42b7257a2dbde56394ca4e19de?s=96&d=mm&r=g\",\"caption\":\"\u685c, \u6625\u6a39\"},\"url\":\"https:\/\/www.silicloud.com\/ja\/blog\/author\/sakuraharuki\/\"},{\"@type\":\"ImageObject\",\"inLanguage\":\"ja\",\"@id\":\"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/#local-main-organization-logo\",\"url\":\"\",\"contentUrl\":\"\",\"caption\":\"Blog - Silicon Cloud\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5 - Blog - Silicon Cloud","description":"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9\u3067lets-encrypt\u3092\u4f7f\u7528\u3057\u3066nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u3059\u308b\u65b9\u6cd5\/","og_locale":"ja_JP","og_type":"article","og_title":"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5","og_description":"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002","og_url":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9\u3067lets-encrypt\u3092\u4f7f\u7528\u3057\u3066nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u3059\u308b\u65b9\u6cd5\/","og_site_name":"Blog - Silicon Cloud","article_published_time":"2023-06-14T16:01:32+00:00","article_modified_time":"2025-07-31T12:50:01+00:00","author":"\u685c, \u6625\u6a39","twitter_card":"summary_large_image","twitter_misc":{"\u57f7\u7b46\u8005":"\u685c, \u6625\u6a39","\u63a8\u5b9a\u8aad\u307f\u53d6\u308a\u6642\u9593":"18\u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/","url":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/","name":"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5 - Blog - Silicon Cloud","isPartOf":{"@id":"https:\/\/www.silicloud.com\/ja\/blog\/#website"},"datePublished":"2023-06-14T16:01:32+00:00","dateModified":"2025-07-31T12:50:01+00:00","author":{"@id":"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/ff22288af1a5455571aff7586b0fb341"},"description":"Rocky Linux 9\u3067Let's Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5\u3092\u5206\u304b\u308a\u3084\u3059\u304f\u89e3\u8aac\u3002\u5b9f\u8df5\u7684\u306a\u4f8b\u3068\u30b3\u30fc\u30c9\u3001\u6ce8\u610f\u70b9\u3092\u542b\u3081\u3066\u521d\u5fc3\u8005\u306b\u3082\u7406\u89e3\u3067\u304d\u308b\u3088\u3046\u8aac\u660e\u3057\u307e\u3059\u3002","breadcrumb":{"@id":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/#breadcrumb"},"inLanguage":"ja","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.silicloud.com\/ja\/blog\/"},{"@type":"ListItem","position":2,"name":"Rocky Linux 9\u3067Let&#8217;s Encrypt\u3092\u4f7f\u7528\u3057\u3066Nginx\u3092\u5b89\u5168\u306b\u4fdd\u8b77\u306e\u65b9\u6cd5"}]},{"@type":"WebSite","@id":"https:\/\/www.silicloud.com\/ja\/blog\/#website","url":"https:\/\/www.silicloud.com\/ja\/blog\/","name":"Blog - Silicon Cloud","description":"","inLanguage":"ja"},{"@type":"Person","@id":"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/ff22288af1a5455571aff7586b0fb341","name":"\u685c, \u6625\u6a39","image":{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/www.silicloud.com\/ja\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/cee48863f3d4fd7fef222498f3e71b82312aee42b7257a2dbde56394ca4e19de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/cee48863f3d4fd7fef222498f3e71b82312aee42b7257a2dbde56394ca4e19de?s=96&d=mm&r=g","caption":"\u685c, \u6625\u6a39"},"url":"https:\/\/www.silicloud.com\/ja\/blog\/author\/sakuraharuki\/"},{"@type":"ImageObject","inLanguage":"ja","@id":"https:\/\/www.silicloud.com\/ja\/blog\/rocky-linux-9%e3%81%a7lets-encrypt%e3%82%92%e4%bd%bf%e7%94%a8%e3%81%97%e3%81%a6nginx%e3%82%92%e5%ae%89%e5%85%a8%e3%81%ab%e4%bf%9d%e8%ad%b7%e3%81%99%e3%82%8b%e6%96%b9%e6%b3%95\/#local-main-organization-logo","url":"","contentUrl":"","caption":"Blog - Silicon Cloud"}]}},"_links":{"self":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts\/231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/comments?post=231"}],"version-history":[{"count":2,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts\/231\/revisions"}],"predecessor-version":[{"id":325758,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/posts\/231\/revisions\/325758"}],"wp:attachment":[{"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/media?parent=231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/categories?post=231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.silicloud.com\/ja\/blog\/wp-json\/wp\/v2\/tags?post=231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}