{"id":4333,"date":"2012-08-18T09:41:59","date_gmt":"2012-08-18T00:41:59","guid":{"rendered":"http:\/\/www.morisoba.jp\/?p=4333"},"modified":"2021-01-06T17:09:11","modified_gmt":"2021-01-06T08:09:11","slug":"ssl%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e8%a8%bc%e6%98%8e","status":"publish","type":"post","link":"https:\/\/www.morisoba.jp\/?p=4333","title":{"rendered":"SSL\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e"},"content":{"rendered":"<p>\u4ee5\u524diPhone4S\u8cb7\u3063\u305f\u6642\u306b\u3001\u5916\u90e8\u304b\u3089\u81ea\u5b85\u306e\u30e1\u30fc\u30eb\u3092\u8aad\u3080\u306e\u306bSSL\u3092\u5c0e\u5165\u3057\u305f\u3002<br \/>\n\u81ea\u5206\u3067\u3057\u304b\u4f7f\u308f\u306a\u3044\u306e\u3068\u3001\u7d50\u69cb\u306a\u91d1\u984d\u304c\u639b\u304b\u3063\u3061\u3083\u3046\u3068\u601d\u3063\u3066\u3044\u305f\u306e\u3067\u3001\u81ea\u5df1\u8a8d\u8a3c\u5c40\uff08\u3044\u308f\u3086\u308b\u30aa\u30ec\u30aa\u30ec\u8a8d\u8a3c\uff09\u3067\u6e08\u307e\u305b\u3066\u3044\u305f\u3002<\/p>\n<blockquote>\n<h3>\u3061\u3087\u3063\u3068\u89e3\u8aac<\/h3>\n<p>SSL\u3063\u3066\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3044\u308b\u30b5\u30a4\u30c8\u304c\u300c\u30a2\u30e4\u30b7\u30a4\u8005\u3067\u306f\u306a\u3044\u3067\u3059\uff01\u300d\u3063\u3066\u3044\u3046\u306e\u3092\u8ab0\u304b\uff08\u8a8d\u8a3c\u5c40\uff09\u306b\u8a8d\u3081\u3066\u8cb0\u3046\u4ed5\u7d44\u307f\u304c\u3042\u3063\u3066\u3001\u4fe1\u983c\u306e\u7f6e\u3051\u308b\u8a8d\u8a3c\u5c40\u306f\u30d6\u30e9\u30a6\u30b6\u3068\u304b\u306b\u6700\u521d\u304b\u3089\u30ea\u30b9\u30c8\u30a2\u30c3\u30d7\u3055\u308c\u3066\u308b\u8a33\u3067\u3059\u3002<br \/>\n\u8981\u306f\u304a\u91d1\u3092\u6255\u3063\u3066\u3001\u30d6\u30e9\u30a6\u30b6\u306b\u30ea\u30b9\u30c8\u30a2\u30c3\u30d7\u3055\u308c\u3066\u3044\u308b\u8a8d\u8a3c\u5c40\u306b\u300c\u30a2\u30e4\u30b7\u30a4\u8005\u3067\u306f\u306a\u3044\u300d\u78ba\u8a8d\u3092\u3057\u3066\u3082\u3089\u3044\u3001\u8a3c\u660e\u66f8\u3092\u767a\u884c\u3057\u3066\u3082\u3089\u3046\u8a33\u3067\u3059\u304c\u3001\u3044\u308f\u3086\u308b\u300c\u30aa\u30ec\u30aa\u30ec\u8a8d\u8a3c\u300d\u3068\u8a00\u3063\u3066\u3044\u308b\u306e\u306f\u3053\u306e\u8a8d\u8a3c\u5c40\u3082\u81ea\u5206\u3067\u3084\u3063\u3066\u3057\u307e\u3046\u8a33\u3067\u3059\u3002<br \/>\n\u30a2\u30af\u30bb\u30b9\u3059\u308b\u30d6\u30e9\u30a6\u30b6\u5074\u304b\u3089\u3059\u308b\u3068\u3001\u5168\u304f\u77e5\u3089\u306a\u3044\u4eba\u304b\u3089<br \/>\n\u300c\u30b3\u30a4\u30c4\u5927\u4e08\u592b\u3067\u3059\u30bc\u3002(\uff92\u25bc\u25bc)y-.\uff61o\u25cb\u300d<br \/>\n\u3068\u304b\u602a\u3057\u3055\u5168\u958b\u306a\u30b3\u30c8\u8a00\u308f\u308c\u308b\u3093\u3067\u3001\u3053\u3093\u306a\u753b\u9762\u3068\u304b\u51fa\u3057\u3066\u8b66\u544a\u3059\u308b\u8a33\u3067\u3059\u3002<br \/>\n<a href=\"https:\/\/www.morisoba.jp\/wp-content\/uploads\/2012\/08\/oreore.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.morisoba.jp\/wp-content\/uploads\/2012\/08\/oreore-200x122.jpg\" alt=\"\" title=\"\u30aa\u30ec\u30aa\u30ec\u8a8d\u8a3c\" width=\"200\" height=\"122\" class=\"alignnone size-thumbnail wp-image-4342\" srcset=\"https:\/\/www.morisoba.jp\/wp-content\/uploads\/2012\/08\/oreore-200x122.jpg 200w, https:\/\/www.morisoba.jp\/wp-content\/uploads\/2012\/08\/oreore-300x184.jpg 300w, https:\/\/www.morisoba.jp\/wp-content\/uploads\/2012\/08\/oreore-600x368.jpg 600w, https:\/\/www.morisoba.jp\/wp-content\/uploads\/2012\/08\/oreore.jpg 710w\" sizes=\"auto, (max-width: 200px) 100vw, 200px\" \/><\/a><br \/>\n\u307e\u3041\u3001\u30a2\u30af\u30bb\u30b9\u3057\u3066\u3044\u308b\u306e\u3082\u81ea\u5206\u306a\u306e\u3067\u81ea\u4f5c\u81ea\u6f14\u306a\u306e\u3067\u3059\u304c\u3001\u4f55\u6545\u305d\u3053\u307e\u3067\u3059\u308b\u306e\u304b\u3068\u8a00\u3046\u3068\u3001\u901a\u4fe1\u304c\u6697\u53f7\u5316\u3055\u308c\u308b\u304b\u3089\u3067\u3059\u306a\u3002\n<\/p><\/blockquote>\n<p>\u3067\u306d\u3001\u6700\u8fd1\u3061\u3087\u3063\u3068\u8abf\u3079\u3066\u3044\u305f\u3089\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u3063\u3066\u5b89\u3044\u306e\u306f\u5e74\u5343\u5186\u3068\u304b\u3067\u53d6\u308c\u3061\u3083\u3046\u306e\u3088\u306d\u3002\u3002\u3002<br \/>\n\u6628\u65e5\u306e\u663c\u98ef\uff08\u306a\u305c\u304b\u73cd\u3057\u304f\u8c6a\u904a\u3057\u3066\u3046\u306a\u304e\u3092\u98df\u3063\u305f(\uff9f\u0434\uff9f)\uff09\u3088\u308a\u5b89\u3044\u3058\u3083\u3093\u3002<br \/>\n\u3061\u3087\u3063\u3068\u524d\u307e\u3067\u6570\u4e07\u5186\u639b\u304b\u308b\u3068\u601d\u3063\u3066\u305f\u3088\u3002<br \/>\n\u500b\u4eba\u4f7f\u7528\u3067\u81ea\u30b5\u30fc\u30d0\u30fc\u3067\u5546\u58f2\u3068\u304b\u3059\u308b\u3064\u3082\u308a\u3082\u306a\u3044\u306e\u3067\u3001\u5b89\u3044\u306e\u3067\u5341\u5206\u3063\u3059\u3002\uff08\u30aa\u30ec\u30aa\u30ec\u3067\u3082\u5341\u5206\u3068\u3044\u3046\u5642\u3082\u3042\u308b\u304c\uff57\uff09<br \/>\n\u3068\u3044\u3046\u8a33\u3067\u3068\u308a\u3042\u3048\u305a\uff11\u5e74\u5206\u901f\u653b\u3067\u7533\u3057\u8fbc\u3093\u3060\u3002<br \/>\n\u7533\u8fbc\u5148\u306f<a href=\"http:\/\/define.co.jp\/\">Define<\/a>\u306eRapidSSL\u3002<\/p>\n<p>\u6700\u521d\u306b\u81ea\u5206\u306e\u30b5\u30fc\u30d0\u30fc\u306e\u79d8\u5bc6\u9375\u3068CSR\u3092\u4f5c\u6210\u3002<br \/>\n\u5fc5\u8981\u306a\u30bd\u30d5\u30c8\u306f<a href=\"http:\/\/www.jp.netbsd.org\/ja\/JP\/index.html\">NetBSD<\/a>\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u6e08\u307f\u3002<\/p>\n<p><code><br \/>\n# \/usr\/pkg\/bin\/openssl md5 \/var\/log\/maillog > rand.dat<br \/>\n# \/usr\/pkg\/bin\/openssl genrsa -rand rand.dat -des3 2048 > morisoba_2012.key<br \/>\nGenerating RSA private key, 2048 bit long modulus<br \/>\n....................................+++<br \/>\n.........+++<br \/>\ne is 65537 (0x10001)<br \/>\nEnter pass phrase for morisoba_2012.key: \uff08\u79d8\u5bc6\u306e\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba(n\u2018\u2200\u2018)\u03b7\uff9f\uff65*:.\uff61. .\uff61.:*\uff65\u309c\uff09<br \/>\nVerifying - Enter pass phrase for morisoba_2012.key: \uff08\u79d8\u5bc6\u306e\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba(n\u2018\u2200\u2018)\u03b7\uff9f\uff65*:.\uff61. .\uff61.:*\uff65\u309c\uff09<br \/>\n#<br \/>\n# \/usr\/pkg\/bin\/openssl req -new -key morisoba_2012.key -out morisoba_2012.csr<br \/>\nEnter pass phrase for morisoba_2012.key: \uff08\u79d8\u5bc6\u306e\u30d1\u30b9\u30d5\u30ec\u30fc\u30ba(n\u2018\u2200\u2018)\u03b7\uff9f\uff65*:.\uff61. .\uff61.:*\uff65\u309c\uff09<br \/>\nYou are about to be asked to enter information that will be incorporated<br \/>\ninto your certificate request.<br \/>\nWhat you are about to enter is what is called a Distinguished Name or a DN.<br \/>\nThere are quite a few fields but you can leave some blank<br \/>\nFor some fields there will be a default value,<br \/>\nIf you enter '.', the field will be left blank.<br \/>\n-----<br \/>\nCountry Name (2 letter code) [JP]:JP<br \/>\nState or Province Name (full name) [Kanagawa]:Kanagawa<br \/>\nLocality Name (eg, city) [Fujisawa]:Fujisawa<br \/>\nOrganization Name (eg, company) []:********** (whois\u306eregistrant\u3092\u5165\u529b)<br \/>\nOrganizational Unit Name (eg, section) [Admin]: (\u9069\u5f53\u3067\u3044\u3044\u3063\u307d\u3044)<br \/>\nCommon Name (eg, your name or your server's hostname) []:www.morisoba.jp (\u8a3c\u660e\u3057\u3066\u3082\u3089\u3046FQDN)<br \/>\nEmail Address []:admin@\u3082\u308a\u305d\u3070.\uff4a\uff50 (\u30c9\u30e1\u30a4\u30f3\u7ba1\u7406\u8005\u306e\u30e1\u30fc\u30eb\u30a2\u30c9\u30ec\u30b9)<\/p>\n<p>Please enter the following 'extra' attributes<br \/>\nto be sent with your certificate request<br \/>\nA challenge password []: (\u7a7a)<br \/>\nAn optional company name []: (\u7a7a)<br \/>\n#<br \/>\n<\/code><br \/>\n\u3053\u3093\u306a\u611f\u3058\u3067\u79d8\u5bc6\u9375\u3068CSR\u30d5\u30a1\u30a4\u30eb\u3092\u4f5c\u6210\u3059\u308b\u3002<\/p>\n<p>\u3067\u3001RapidSSL\u3092\u7533\u3057\u8fbc\u307f\u3001PayPal\u3067\u652f\u6255\u3046\u3068\u3057\u3070\u3089\u304f\u3057\u3066\u7533\u3057\u8fbc\u307f\u30d5\u30a9\u30fc\u30e0\u3078\u306eURI\u304c\u66f8\u304b\u308c\u3066\u3044\u308b\u30e1\u30fc\u30eb\u304c\u6765\u308b\u3002<br \/>\n\u305d\u306eURI\u306b\u98db\u3093\u3067\u3001\u30d5\u30a9\u30fc\u30e0\u306bCSR\u306e\u30d5\u30a1\u30a4\u30eb\u306e\u4e2d\u8eab\u3092cat\u3057\u3066\u30b3\u30d4\u30da\u3059\u308b\u3002<br \/>\n\u6b8b\u308a\u306e\u9805\u76ee\u306f\u5618\u507d\u308a\u306a\u304f\u8a18\u5165\u3002<br \/>\n\u3061\u306a\u307f\u306bwhois\u306f\u60c5\u5831\u4ee3\u884c\u3057\u3066\u3042\u308b\u3051\u3069\u3001\u305d\u306e\u307e\u307e\u3067\u5927\u4e08\u592b\u3067\u3057\u305f\u3002<br \/>\n\uff11\u5206\u5f8c\u304f\u3089\u3044\u306b\u306f\u30e1\u30fc\u30eb\u3067\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u304c\u9001\u3089\u308c\u3066\u304d\u305f\u3002\u901f\u3048\u3047\u3002\u3002\u3002<br \/>\n\u9001\u3089\u308c\u3066\u304d\u305f\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u3068\u3001\u30e1\u30fc\u30eb\u306e\u30ea\u30f3\u30af\u306b\u4ed8\u3044\u3066\u304f\u308b\u4e2d\u9593\u8a8d\u8a3c\u5c40\u8a3c\u660e\u3092\u30b5\u30fc\u30d0\u30fc\u306b\u30c6\u30ad\u30b9\u30c8\u3067\u4fdd\u5b58\u3059\u308b\u3002<br \/>\n\u3000\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u3000\u3000\u2192\u3000morisoba_2012.crt<br \/>\n\u3000\u4e2d\u9593\u8a8d\u8a3c\u5c40\u8a3c\u660e\u3000\u2192\u3000RapidSSL_CA_bundle.pem<\/p>\n<p>\u6700\u7d42\u7684\u306b\u30b5\u30fc\u30d0\u30fc\u3067\u5fc5\u8981\u306a\u306e\u306f<br \/>\n\u3000\u30fb\u6700\u521d\u306b\u4f5c\u3063\u305f\u30b5\u30fc\u30d0\u30fc\u306e\u79d8\u5bc6\u9375(morisoba_2012.key)<br \/>\n\u3000\u30fb\u30e1\u30fc\u30eb\u3067\u9001\u3089\u308c\u3066\u304d\u305f\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e(morisoba_2012.crt)<br \/>\n\u3000\u30fb\u30e1\u30fc\u30eb\u306e\u30ea\u30f3\u30af\u306b\u3042\u308b\u4e2d\u9593\u8a8d\u8a3c\u5c40\u8a3c\u660e(RapidSSL_CA_bundle.pem)<br \/>\n\u3053\u3044\u3064\u3089\u3092SSL\u901a\u4fe1\u3057\u305f\u3044\u30b5\u30fc\u30d0\u30fc\u306b\u30bb\u30c3\u30c8\u30a2\u30c3\u30d7\u3059\u308b\u3002<\/p>\n<h4>apache2+mod_ssl<\/h4>\n<p>\/usr\/pkg\/etc\/httpd\/httpd-ssl.conf \u3092\u7de8\u96c6<br \/>\n<code><br \/>\nSSLEngine on<br \/>\nSSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL<br \/>\nSSLCertificateFile \/\u30d1\u30b9\/morisoba_2012.crt<br \/>\nSSLCertificateKeyFile \/\u30d1\u30b9\/morisoba_2012.key<br \/>\nSSLCertificateChainFile \/\u30d1\u30b9\/RapidSSL_CA_bundle.pem<br \/>\n<\/code><\/p>\n<h4>courierimap<\/h4>\n<p>\u8a3c\u660e\u66f8\u3092\u675f\u306d\u308b\u5fc5\u8981\u304c\u3042\u308b\u3063\u307d\u3044\u3002<br \/>\n<code><br \/>\n# cat morisoba_2012.key morisoba_2012.crt RapidSSL_CA_bundle.pem > courierimapd.pem<br \/>\n<\/code><br \/>\n\/usr\/pkg\/etc\/courier\/imapd-ssl \u3092\u7de8\u96c6<br \/>\n<code><br \/>\nTLS_CERTFILE=\/\u30d1\u30b9\/courierimapd.pem<br \/>\n<\/code><\/p>\n<h4>ProFTPD<\/h4>\n<p>\/usr\/pkg\/proftpd.conf \u3092\u7de8\u96c6<br \/>\n<code><br \/>\n&lt;IfModule mod_tls.c&gt;<br \/>\nTLSEngine on<br \/>\nTLSLog \/var\/log\/proftpd_ssl.log<br \/>\nTLSProtocol SSLv23<br \/>\nTLSCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP<\/p>\n<p># Are clients required to use FTP over TLS when talking to this server?<br \/>\nTLSRequired off<\/p>\n<p># Server's certificate<br \/>\nTLSRSACertificateFile \/\u30d1\u30b9\/morisoba_2012.crt<br \/>\nTLSRSACertificateKeyFile \/\u30d1\u30b9\/morisoba_2012.key<\/p>\n<p># CA the server trusts<br \/>\nTLSCACertificateFile \/\u30d1\u30b9\/RapidSSL_CA_bundle.pem<\/p>\n<p># Authenticate clients that want to use FTP over TLS?<br \/>\nTLSVerifyClient off<br \/>\n&lt;\/IfModule&gt;<br \/>\n<\/code><\/p>\n<p>\u8a73\u3057\u304f\u306f\u4ed6\u306eweb\u3067\uff57<\/p>\n<p>\u3042\u3068\u306f\u5404\u30b5\u30fc\u30d0\u30fc\u306a\u308ainetd\u306a\u308a\u3092\u518d\u8d77\u52d5\u3002<br \/>\n\u30aa\u30ec\u30aa\u30ec\u8a8d\u8a3c\u3082\u64b2\u6ec5\u3067\u3059\u3002<\/p>\n<p>\u30c6\u30ad\u30b9\u30c8\u3060\u3089\u3051\u3067\u610f\u5916\u3068\u9577\u304f\u306a\u3063\u3066\u3082\u3046\u305f\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u4ee5\u524diPhone4S\u8cb7\u3063\u305f\u6642\u306b\u3001\u5916\u90e8\u304b\u3089\u81ea\u5b85\u306e\u30e1\u30fc\u30eb\u3092\u8aad\u3080\u306e\u306bSSL\u3092\u5c0e\u5165\u3057\u305f\u3002 \u81ea\u5206\u3067\u3057\u304b\u4f7f\u308f\u306a\u3044\u306e\u3068\u3001\u7d50\u69cb\u306a\u91d1\u984d\u304c\u639b\u304b\u3063\u3061\u3083\u3046\u3068\u601d\u3063\u3066\u3044\u305f\u306e\u3067\u3001\u81ea\u5df1\u8a8d\u8a3c\u5c40\uff08\u3044\u308f\u3086\u308b\u30aa\u30ec\u30aa\u30ec\u8a8d\u8a3c\uff09\u3067\u6e08\u307e\u305b\u3066\u3044\u305f\u3002 \u3061\u3087\u3063\u3068\u89e3\u8aac SSL [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-4333","post","type-post","status-publish","format-standard","hentry","category-computer"],"_links":{"self":[{"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=\/wp\/v2\/posts\/4333","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4333"}],"version-history":[{"count":42,"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=\/wp\/v2\/posts\/4333\/revisions"}],"predecessor-version":[{"id":7186,"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=\/wp\/v2\/posts\/4333\/revisions\/7186"}],"wp:attachment":[{"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4333"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4333"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.morisoba.jp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4333"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}