{"id":752,"date":"2026-08-07T11:21:55","date_gmt":"2026-08-07T02:21:55","guid":{"rendered":"https:\/\/support.three-meister.com\/techwiki\/?p=752"},"modified":"2026-08-07T11:21:55","modified_gmt":"2026-08-07T02:21:55","slug":"%e3%80%90linux%e5%85%b1%e9%80%9a%e3%80%91lets-encrypt-%e7%99%ba%e8%a1%8c%e6%96%b9%e6%b3%95dns%e8%aa%8d%e8%a8%bc","status":"publish","type":"post","link":"https:\/\/support.three-meister.com\/techwiki\/?p=752","title":{"rendered":"\u3010Linux\u5171\u901a\u3011Let\u2019s Encrypt \u767a\u884c\u65b9\u6cd5(DNS\u8a8d\u8a3c)"},"content":{"rendered":"<p>\u672c\u7a3f\u3067\u306fLet\u2019s Encrypt\u3067\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u66f8\u3092\u767a\u884c\u3059\u308b\u624b\u9806\u3092\u8a18\u8f09\u3057\u307e\u3059\u3002<\/p>\n<h2 class=\"styled_h2\">DNS\u8a8d\u8a3c\u3067\u306e\u8a3c\u660e\u66f8\u306e\u767a\u884c<\/h2>\n<p>Tera Term\u3067\u8a72\u5f53\u30b5\u30fc\u30d0\u30fc\u306bSSH\u3067\u30ed\u30b0\u30a4\u30f3\u3057\u307e\u3059\u3002<br \/>\n\u30ed\u30b0\u30a4\u30f3\u3057\u305f\u3089\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<div>\n<div class=\"well2\">\n<div><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\">sudo certbot certonly <\/span><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\">\u00a0&#8211;manual\u00a0<\/span><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\"> &#8211;preferred-challenges dns\u00a0<\/span><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\"> -d zabbix.three-meister.com<\/span><\/div>\n<\/div>\n<\/div>\n<div>\n<p>\u6539\u884c\u3059\u308b\u5834\u5408\uff1a\u6539\u884c\u306e\u524d\u306b\u300c\\\u300d\u3092\u5165\u308c\u308b<\/p>\n<div>\n<div class=\"well2\">\n<div><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\">sudo certbot certonly \\<\/span><\/div>\n<div><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\"> &#8211;manual \\<\/span><\/div>\n<div><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\"> &#8211;preferred-challenges dns \\<\/span><\/div>\n<div><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\"> -d zabbix.three-meister.com<\/span><\/div>\n<\/div>\n<\/div>\n<p>\u5b9f\u884c\u3059\u308b\u3068\u4ee5\u4e0b\u304c\u8868\u793a\u3055\u308c\u307e\u3059\u3002<\/p>\n<div class=\"well2\">\n<p>[tmcadmin@TMCZXSV01 etc]$ sudo certbot certonly \\<br \/>\n&#8211;manual \\<br \/>\n&#8211;preferred-challenges dns \\<br \/>\n-d zabbix.three-meister.com<br \/>\nSaving debug log to \/var\/log\/letsencrypt\/letsencrypt.log<br \/>\nRequesting a certificate for zabbix.three-meister.com<\/p>\n<p>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<br \/>\nPlease deploy a DNS TXT record under the name:<\/p>\n<p>_acme-challenge.zabbix.three-meister.com.<\/p>\n<p>with the following value:<\/p>\n<p><span style=\"color: #ff0000;\">PnKFeEf2OE7f8qrHNk0abdPmS0UHo8s4dqXJLllcpM4<\/span><\/p>\n<p>Before continuing, verify the TXT record has been deployed. Depending on the DNS<br \/>\nprovider, this may take some time, from a few seconds to multiple minutes. You can<br \/>\ncheck if it has finished deploying with aid of online tools, such as the Google<br \/>\nAdmin Toolbox: https:\/\/toolbox.googleapps.com\/apps\/dig\/#TXT\/_acme-challenge.zabbix.three-meister.com.<br \/>\nLook for one or more bolded line(s) below the line &#8216;;ANSWER&#8217;. It should show the<br \/>\nvalue(s) you&#8217;ve just added.<\/p>\n<p>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<br \/>\nPress Enter to Continue<\/p>\n<\/div>\n<p>\u3053\u3053\u307e\u3067\u8868\u793a\u3055\u308c\u305f\u3089\u3001\u304a\u540d\u524d\u30c9\u30c3\u30c8\u30b3\u30e0\u306b\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3001DNS\u306b\u4ee5\u4e0b\u3092\u767b\u9332\u3057\u307e\u3059\u3002<\/p>\n<div><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\"><span attribution=\"{&quot;id&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;name&quot;:&quot;Copilot&quot;,&quot;oid&quot;:&quot;E64C3D4F-5E12-4514-AD9B-893A6FAFD00C&quot;,&quot;timestamp&quot;:1786066800000,&quot;dataSource&quot;:0}\">\u30bf\u30a4\u30d7\uff1aTXT<br \/>\n\u30db\u30b9\u30c8\u540d\uff1a_acme-challenge.zabbix<br \/>\nTTL:300<br \/>\n\u5024\uff1a<span style=\"color: #ff0000;\">PnKFeEf2OE7f8qrHNk0abdPmS0UHo8s4dqXJLllcpM4<\/span><br \/>\n\u203b\u5024\u306f\u4e0a\u8a18\u306b\u8868\u793a\u3055\u308c\u3066\u3044\u308b\u30ad\u30fc\u3092\u8a2d\u5b9a<\/span><\/span>\u203b\u53cd\u6620\u307e\u30675\u5206\u304b\u304b\u308b\u305f\u3081\u300110\u5206\u7a0b\u5ea6\u653e\u7f6e\u3059\u308b<\/p>\n<p>10\u5206\u5f85\u3063\u305f\u5f8c\u3001\u30a8\u30f3\u30bf\u30fc\u30ad\u30fc\u3092\u62bc\u3057\u307e\u3059\u3002<\/p>\n<\/div>\n<div class=\"well2\">\n<p>Successfully received certificate.<br \/>\nCertificate is saved at: \/etc\/letsencrypt\/live\/zabbix.three-meister.com\/fullchain.pem<br \/>\nKey is saved at: \/etc\/letsencrypt\/live\/zabbix.three-meister.com\/privkey.pem<br \/>\nThis certificate expires on 2026-11-05.<br \/>\nThese files will be updated when the certificate renews.<\/p>\n<p>NEXT STEPS:<br \/>\n&#8211; This certificate will not be renewed automatically. Autorenewal of &#8211;manual certificates requires the use of an authentication hook script (&#8211;manual-auth-hook) but one was not provided. To renew this certificate, repeat this same certbot command before the certificate&#8217;s expiry date.<\/p>\n<p>&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<br \/>\nIf you like Certbot, please consider supporting our work by:<br \/>\n* Donating to ISRG \/ Let&#8217;s Encrypt: https:\/\/letsencrypt.org\/donate<br \/>\n* Donating to EFF: https:\/\/eff.org\/donate-le<br \/>\n&#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211; &#8211;<\/p>\n<\/div>\n<\/div>\n<div>\n<div>\n<p>\u8a3c\u660e\u66f8\u306e\u767a\u884c\u78ba\u8a8d\u3067\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<div class=\"well2\">[tmcadmin@TMCZXSV01 etc]$ sudo ls -l \/etc\/letsencrypt\/live\/zabbix.three-meister.com\/<\/div>\n<\/div>\n<div>\u4ee5\u4e0b\u304c\u8868\u793a\u3055\u308c\u308c\u3070OK\u3067\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">\u5408\u8a08 4<br \/>\n-rw-r&#8211;r&#8211;. 1 root root 692 8\u6708 7 10:40 README<br \/>\nlrwxrwxrwx. 1 root root 48 8\u6708 7 10:40 cert.pem -&gt; ..\/..\/archive\/zabbix.three-meister.com\/cert1.pem<br \/>\nlrwxrwxrwx. 1 root root 49 8\u6708 7 10:40 chain.pem -&gt; ..\/..\/archive\/zabbix.three-meister.com\/chain1.pem<br \/>\nlrwxrwxrwx. 1 root root 53 8\u6708 7 10:40 fullchain.pem -&gt; ..\/..\/archive\/zabbix.three-meister.com\/fullchain1.pem<br \/>\nlrwxrwxrwx. 1 root root 51 8\u6708 7 10:40 privkey.pem -&gt; ..\/..\/archive\/zabbix.three-meister.com\/privkey1.pem<\/div>\n<\/div>\n<div>\n<h2 class=\"styled_h2\">\u8a3c\u660e\u66f8\u306e\u9069\u7528<\/h2>\n<p>\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066ssl\u306e\u8a2d\u5b9a\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002<\/p>\n<div class=\"well2\">[tmcadmin@TMCZXSV01 etc]$ sudo vi \/etc\/httpd\/conf.d\/ssl.conf<\/div>\n<\/div>\n<\/div>\n<div>\u8868\u793a\u3055\u308c\u305f\u3089\u4ee5\u4e0b\u306e\u8d64\u6587\u5b57\u306e\u7b87\u6240\u3092\u5909\u66f4\u3057\u307e\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">\n<p>[tmcadmin@TMCZXSV01 etc]$ sudo cat \/etc\/httpd\/conf.d\/ssl.conf<br \/>\n[sudo] tmcadmin \u306e\u30d1\u30b9\u30ef\u30fc\u30c9:<br \/>\n#<br \/>\n# When we also provide SSL we have to listen to the<br \/>\n# standard HTTPS port in addition.<br \/>\n#<br \/>\nListen 443 https<\/p>\n<p>##<br \/>\n## SSL Global Context<br \/>\n##<br \/>\n## All SSL configuration in this context applies both to<br \/>\n## the main server and all SSL-enabled virtual hosts.<br \/>\n##<\/p>\n<p># Pass Phrase Dialog:<br \/>\n# Configure the pass phrase gathering process.<br \/>\n# The filtering dialog program (`builtin&#8217; is a internal<br \/>\n# terminal dialog) has to provide the pass phrase on stdout.<br \/>\nSSLPassPhraseDialog exec:\/usr\/libexec\/httpd-ssl-pass-dialog<\/p>\n<p># Inter-Process Session Cache:<br \/>\n# Configure the SSL Session Cache: First the mechanism<br \/>\n# to use and second the expiring timeout (in seconds).<br \/>\nSSLSessionCache shmcb:\/run\/httpd\/sslcache(512000)<br \/>\nSSLSessionCacheTimeout 300<\/p>\n<p>#<br \/>\n# Use &#8220;SSLCryptoDevice&#8221; to enable any supported hardware<br \/>\n# accelerators. Use &#8220;openssl engine -v&#8221; to list supported<br \/>\n# engine names. NOTE: If you enable an accelerator and the<br \/>\n# server does not start, consult the error logs and ensure<br \/>\n# your accelerator is functioning properly.<br \/>\n#<br \/>\nSSLCryptoDevice builtin<br \/>\n#SSLCryptoDevice ubsec<\/p>\n<p>##<br \/>\n## SSL Virtual Host Context<br \/>\n##<\/p>\n<p>&lt;VirtualHost _default_:443&gt;<\/p>\n<p># General setup for the virtual host, inherited from global configuration<br \/>\n#DocumentRoot &#8220;\/var\/www\/html&#8221;<br \/>\n<span style=\"color: #ff0000;\">ServerName zabbix.three-meister.com<br \/>\n\u203b\u30b3\u30e1\u30f3\u30c8\u3092\u5916\u3057\u3066\u3001\u30b5\u30fc\u30d0\u30fc\u540d\u3092\u5909\u66f4<\/span><\/p>\n<p># Use separate log files for the SSL virtual host; note that LogLevel<br \/>\n# is not inherited from httpd.conf.<br \/>\nErrorLog logs\/ssl_error_log<br \/>\nTransferLog logs\/ssl_access_log<br \/>\nLogLevel warn<\/p>\n<p># SSL Engine Switch:<br \/>\n# Enable\/Disable SSL for this virtual host.<br \/>\nSSLEngine on<\/p>\n<p># List the protocol versions which clients are allowed to connect with.<br \/>\n# The OpenSSL system profile is used by default. See<br \/>\n# update-crypto-policies(8) for more details.<br \/>\n#SSLProtocol all -SSLv3<br \/>\n#SSLProxyProtocol all -SSLv3<\/p>\n<p># User agents such as web browsers are not configured for the user&#8217;s<br \/>\n# own preference of either security or performance, therefore this<br \/>\n# must be the prerogative of the web server administrator who manages<br \/>\n# cpu load versus confidentiality, so enforce the server&#8217;s cipher order.<br \/>\nSSLHonorCipherOrder on<\/p>\n<p># SSL Cipher Suite:<br \/>\n# List the ciphers that the client is permitted to negotiate.<br \/>\n# See the mod_ssl documentation for a complete list.<br \/>\n# The OpenSSL system profile is configured by default. See<br \/>\n# update-crypto-policies(8) for more details.<br \/>\nSSLCipherSuite PROFILE=SYSTEM<br \/>\nSSLProxyCipherSuite PROFILE=SYSTEM<\/p>\n<p># Point SSLCertificateFile at a PEM encoded certificate. If<br \/>\n# the certificate is encrypted, then you will be prompted for a<br \/>\n# pass phrase. Note that restarting httpd will prompt again. Keep<br \/>\n# in mind that if you have both an RSA and a DSA certificate you<br \/>\n# can configure both in parallel (to also allow the use of DSA<br \/>\n# ciphers, etc.)<br \/>\n# Some ECC cipher suites (http:\/\/www.ietf.org\/rfc\/rfc4492.txt)<br \/>\n# require an ECC certificate which can also be configured in<br \/>\n# parallel.<br \/>\nSSLCertificateFile <span style=\"color: #ff0000;\">\/etc\/letsencrypt\/live\/zabbix.three-meister.com\/fullchain.pem<br \/>\n\u203b\u5148\u307b\u3069\u767a\u884c\u3057\u305f\u8a3c\u660e\u66f8\u3092\u8a2d\u5b9a<br \/>\n<\/span><\/p>\n<p># Server Private Key:<br \/>\n# If the key is not combined with the certificate, use this<br \/>\n# directive to point at the key file. Keep in mind that if<br \/>\n# you&#8217;ve both a RSA and a DSA private key you can configure<br \/>\n# both in parallel (to also allow the use of DSA ciphers, etc.)<br \/>\n# ECC keys, when in use, can also be configured in parallel<br \/>\nSSLCertificateKeyFile <span style=\"color: #ff0000;\">\/etc\/letsencrypt\/live\/zabbix.three-meister.com\/privkey.pem<br \/>\n\u203b\u5148\u307b\u3069\u767a\u884c\u3057\u305f\u8a3c\u660e\u66f8Key<\/span><span style=\"color: #ff0000;\">\u3092\u8a2d\u5b9a<br \/>\n<\/span><\/p>\n<p># Server Certificate Chain:<br \/>\n# Point SSLCertificateChainFile at a file containing the<br \/>\n# concatenation of PEM encoded CA certificates which form the<br \/>\n# certificate chain for the server certificate. Alternatively<br \/>\n# the referenced file can be the same as SSLCertificateFile<br \/>\n# when the CA certificates are directly appended to the server<br \/>\n# certificate for convenience.<br \/>\n#SSLCertificateChainFile \/etc\/pki\/tls\/certs\/server-chain.crt<\/p>\n<p># Certificate Authority (CA):<br \/>\n# Set the CA certificate verification path where to find CA<br \/>\n# certificates for client authentication or alternatively one<br \/>\n# huge file containing all of them (file must be PEM encoded)<br \/>\n#SSLCACertificateFile \/etc\/pki\/tls\/certs\/ca-bundle.crt<\/p>\n<p># Client Authentication (Type):<br \/>\n# Client certificate verification type and depth. Types are<br \/>\n# none, optional, require and optional_no_ca. Depth is a<br \/>\n# number which specifies how deeply to verify the certificate<br \/>\n# issuer chain before deciding the certificate is not valid.<br \/>\n#SSLVerifyClient require<br \/>\n#SSLVerifyDepth 10<\/p>\n<p># Access Control:<br \/>\n# With SSLRequire you can do per-directory access control based<br \/>\n# on arbitrary complex boolean expressions containing server<br \/>\n# variable checks and other lookup directives. The syntax is a<br \/>\n# mixture between C and Perl. See the mod_ssl documentation<br \/>\n# for more details.<br \/>\n#&lt;Location \/&gt;<br \/>\n#SSLRequire ( %{SSL_CIPHER} !~ m\/^(EXP|NULL)\/ \\<br \/>\n# and %{SSL_CLIENT_S_DN_O} eq &#8220;Snake Oil, Ltd.&#8221; \\<br \/>\n# and %{SSL_CLIENT_S_DN_OU} in {&#8220;Staff&#8221;, &#8220;CA&#8221;, &#8220;Dev&#8221;} \\<br \/>\n# and %{TIME_WDAY} &gt;= 1 and %{TIME_WDAY} &lt;= 5 \\<br \/>\n# and %{TIME_HOUR} &gt;= 8 and %{TIME_HOUR} &lt;= 20 ) \\<br \/>\n# or %{REMOTE_ADDR} =~ m\/^192\\.76\\.162\\.[0-9]+$\/<br \/>\n#&lt;\/Location&gt;<\/p>\n<p># SSL Engine Options:<br \/>\n# Set various options for the SSL engine.<br \/>\n# o FakeBasicAuth:<br \/>\n# Translate the client X.509 into a Basic Authorisation. This means that<br \/>\n# the standard Auth\/DBMAuth methods can be used for access control. The<br \/>\n# user name is the `one line&#8217; version of the client&#8217;s X.509 certificate.<br \/>\n# Note that no password is obtained from the user. Every entry in the user<br \/>\n# file needs this password: `xxj31ZMTZzkVA&#8217;.<br \/>\n# o ExportCertData:<br \/>\n# This exports two additional environment variables: SSL_CLIENT_CERT and<br \/>\n# SSL_SERVER_CERT. These contain the PEM-encoded certificates of the<br \/>\n# server (always existing) and the client (only existing when client<br \/>\n# authentication is used). This can be used to import the certificates<br \/>\n# into CGI scripts.<br \/>\n# o StdEnvVars:<br \/>\n# This exports the standard SSL\/TLS related `SSL_*&#8217; environment variables.<br \/>\n# Per default this exportation is switched off for performance reasons,<br \/>\n# because the extraction step is an expensive operation and is usually<br \/>\n# useless for serving static content. So one usually enables the<br \/>\n# exportation for CGI and SSI requests only.<br \/>\n# o StrictRequire:<br \/>\n# This denies access when &#8220;SSLRequireSSL&#8221; or &#8220;SSLRequire&#8221; applied even<br \/>\n# under a &#8220;Satisfy any&#8221; situation, i.e. when it applies access is denied<br \/>\n# and no other module can change it.<br \/>\n# o OptRenegotiate:<br \/>\n# This enables optimized SSL connection renegotiation handling when SSL<br \/>\n# directives are used in per-directory context.<br \/>\n#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire<br \/>\n&lt;FilesMatch &#8220;\\.(cgi|shtml|phtml|php)$&#8221;&gt;<br \/>\nSSLOptions +StdEnvVars<br \/>\n&lt;\/FilesMatch&gt;<br \/>\n&lt;Directory &#8220;\/var\/www\/cgi-bin&#8221;&gt;<br \/>\nSSLOptions +StdEnvVars<br \/>\n&lt;\/Directory&gt;<\/p>\n<p># SSL Protocol Adjustments:<br \/>\n# The safe and default but still SSL\/TLS standard compliant shutdown<br \/>\n# approach is that mod_ssl sends the close notify alert but doesn&#8217;t wait for<br \/>\n# the close notify alert from client. When you need a different shutdown<br \/>\n# approach you can use one of the following variables:<br \/>\n# o ssl-unclean-shutdown:<br \/>\n# This forces an unclean shutdown when the connection is closed, i.e. no<br \/>\n# SSL close notify alert is sent or allowed to be received. This violates<br \/>\n# the SSL\/TLS standard but is needed for some brain-dead browsers. Use<br \/>\n# this when you receive I\/O errors because of the standard approach where<br \/>\n# mod_ssl sends the close notify alert.<br \/>\n# o ssl-accurate-shutdown:<br \/>\n# This forces an accurate shutdown when the connection is closed, i.e. a<br \/>\n# SSL close notify alert is sent and mod_ssl waits for the close notify<br \/>\n# alert of the client. This is 100% SSL\/TLS standard compliant, but in<br \/>\n# practice often causes hanging connections with brain-dead browsers. Use<br \/>\n# this only for browsers where you know that their SSL implementation<br \/>\n# works correctly.<br \/>\n# Notice: Most problems of broken clients are also related to the HTTP<br \/>\n# keep-alive facility, so you usually additionally want to disable<br \/>\n# keep-alive for those clients, too. Use variable &#8220;nokeepalive&#8221; for this.<br \/>\n# Similarly, one has to force some clients to use HTTP\/1.0 to workaround<br \/>\n# their broken HTTP\/1.1 implementation. Use variables &#8220;downgrade-1.0&#8221; and<br \/>\n# &#8220;force-response-1.0&#8221; for this.<br \/>\nBrowserMatch &#8220;MSIE [2-5]&#8221; \\<br \/>\nnokeepalive ssl-unclean-shutdown \\<br \/>\ndowngrade-1.0 force-response-1.0<\/p>\n<p># Per-Server Logging:<br \/>\n# The home of a custom SSL log file. Use this when you want a<br \/>\n# compact non-error SSL logfile on a virtual host basis.<br \/>\nCustomLog logs\/ssl_request_log \\<br \/>\n&#8220;%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \\&#8221;%r\\&#8221; %b&#8221;<\/p>\n<p>&lt;\/VirtualHost&gt;<\/p>\n<\/div>\n<\/div>\n<div>\u8a2d\u5b9a\u304c\u5b8c\u4e86\u3057\u305f\u3089\u3001\u300c:wq\u300d\u3068\u5165\u529b\u3057\u3066\u4fdd\u5b58\u3057\u307e\u3059\u3002<\/div>\n<div><\/div>\n<div>\u6b21\u306b\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u3066\u8a2d\u5b9a\u304c\u554f\u984c\u306a\u3044\u304b\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">sudo httpd -t<\/div>\n<div>\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u306a\u308c\u3070OK\u3067\u3059\u3002\u4e0b\u8a18\u8d64\u6587\u5b57\u306e\u7b87\u6240\u3092\u78ba\u8a8d\u3057\u3066\u300cOK\u300d\u3067\u3042\u308b\u3053\u3068\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">[tmcadmin@TMCZXSV01 etc]$ sudo httpd -t<br \/>\nAH00558: httpd: Could not reliably determine the server&#8217;s fully qualified domain name, using fe80::250:56ff:fea7:68e7%ens33. Set the &#8216;ServerName&#8217; directive globally to suppress this message<br \/>\n<span style=\"color: #ff0000;\">Syntax OK<\/span><\/div>\n<div>\u6b21\u306b\u30b5\u30fc\u30d3\u30b9\u3092\u518d\u8d77\u52d5\u3057\u307e\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">sudo systemctl restart httpd<\/div>\n<div>\u30b5\u30fc\u30d3\u30b9\u72b6\u6cc1\u3092\u78ba\u8a8d\u3057\u307e\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">sudo ss -tlnp | grep 443<\/div>\n<div>\u4ee5\u4e0b\u306e\u3088\u3046\u306b\u300c*:443\u300d\u304c\u52d5\u3044\u3066\u3044\u308c\u3070OK\u3067\u3059\u3002<\/div>\n<div>\n<div class=\"well2\">LISTEN 0 511 <span style=\"color: #ff0000;\">*:443<\/span> *:* users:((&#8220;httpd&#8221;,pid=1951525,fd=6),(&#8220;httpd&#8221;,pid=1951328,fd=6),(&#8220;httpd&#8221;,pid=1951287,fd=6),(&#8220;httpd&#8221;,pid=1951286,fd=6),(&#8220;httpd&#8221;,pid=1951284,fd=6))<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"\u672c\u7a3f\u3067\u306fLet\u2019s Encrypt\u3067\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u66f8\u3092\u767a\u884c\u3059\u308b\u624b\u9806\u3092\u8a18\u8f09\u3057\u307e\u3059\u3002 DNS\u8a8d\u8a3c\u3067\u306e\u8a3c\u660e\u66f8\u306e\u767a\u884c Tera Term\u3067\u8a72\u5f53\u30b5\u30fc\u30d0\u30fc\u306bSSH\u3067\u30ed\u30b0\u30a4\u30f3\u3057\u307e\u3059\u3002 \u30ed\u30b0\u30a4\u30f3\u3057\u305f\u3089\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3092\u5b9f\u884c\u3057\u307e\u3059\u3002 sudo [&hellip;]","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75],"tags":[],"class_list":["post-752","post","type-post","status-publish","format-standard","hentry","category-75"],"_links":{"self":[{"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=\/wp\/v2\/posts\/752","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=752"}],"version-history":[{"count":3,"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=\/wp\/v2\/posts\/752\/revisions"}],"predecessor-version":[{"id":755,"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=\/wp\/v2\/posts\/752\/revisions\/755"}],"wp:attachment":[{"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=752"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=752"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/support.three-meister.com\/techwiki\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=752"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}