-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathssl-letsencrypt.html
More file actions
912 lines (554 loc) · 39.9 KB
/
Copy pathssl-letsencrypt.html
File metadata and controls
912 lines (554 loc) · 39.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
<!DOCTYPE html>
<html>
<head>
<!-- Document Settings -->
<meta charset="utf-8" />
<meta http-equiv="X-UA-Compatible" content="IE=edge" />
<!-- Base Meta -->
<!-- dynamically fixing the title for tag/author pages -->
<title>Letsencrypt + Nginx SSL인증서(HTTPS) 적용</title>
<meta name="HandheldFriendly" content="True" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
<!-- Styles'n'Scripts -->
<link rel="stylesheet" type="text/css" href="/assets/built/screen.css" />
<link rel="stylesheet" type="text/css" href="/assets/built/screen.edited.css" />
<link rel="stylesheet" type="text/css" href="/assets/built/syntax.css" />
<!-- custom.css -->
<link rel="stylesheet" type="text/css" href="/assets/built/custom.css" />
<!-- Font Awesome -->
<link rel="stylesheet" href="https://maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css">
<!-- 웹폰트 추가 -->
<link rel="stylesheet" href="https://fonts.googleapis.com/earlyaccess/nanumgothic.css">
<!-- highlight.js -->
<link rel="stylesheet" href="//cdnjs.cloudflare.com/ajax/libs/highlight.js/9.12.0/styles/default.min.css">
<style>.hljs { background: none; }</style>
<!--[if IE]>
<style>
p, ol, ul{
width: 100%;
}
blockquote{
width: 100%;
}
</style>
<![endif]-->
<!-- This tag outputs SEO meta+structured data and other important settings -->
<meta name="description" content="기술 블로그" />
<link rel="shortcut icon" href="https://simplehanlab.github.io/assets/built/images/favicon.jpg" type="image/png" />
<link rel="canonical" href="https://simplehanlab.github.io/ssl-letsencrypt" />
<meta name="referrer" content="no-referrer-when-downgrade" />
<!--title below is coming from _includes/dynamic_title-->
<meta property="og:site_name" content="SimpleHan Lab" />
<meta property="og:type" content="website" />
<meta property="og:title" content="Letsencrypt + Nginx SSL인증서(HTTPS) 적용" />
<meta property="og:description" content="환경 Ubuntu 18.04 apt-get 을 통해 설치한 Nginx 도메인 ( 이번 과정에서는 도메인이 없는 경우를 대비 ngrok 을 이용한 임시 도메인 사용 ) Let’s Encrypt 웹 사이트에 HTTPS (SSL / TLS)를 사용하기 위해 필요한 디지털 인증서를 무료로 제공 만료 기간이 90일, 만료 기간전에 수동으로 인증서를 갱신 또는 crontab, certbot auto" />
<meta property="og:url" content="https://simplehanlab.github.io/ssl-letsencrypt" />
<meta property="og:image" content="https://simplehanlab.github.io/assets/built/images/nginx-tomcat/nginx-logo.png" />
<meta property="article:publisher" content="https://www.facebook.com/" />
<meta property="article:author" content="https://www.facebook.com/" />
<meta property="article:published_time" content="2019-07-30T11:00:00+00:00" />
<meta property="article:modified_time" content="2019-07-30T11:00:00+00:00" />
<meta property="article:tag" content="https" />
<meta name="twitter:card" content="summary_large_image" />
<meta name="twitter:title" content="Letsencrypt + Nginx SSL인증서(HTTPS) 적용" />
<meta name="twitter:description" content="환경 Ubuntu 18.04 apt-get 을 통해 설치한 Nginx 도메인 ( 이번 과정에서는 도메인이 없는 경우를 대비 ngrok 을 이용한 임시 도메인 사용 ) Let’s Encrypt 웹 사이트에 HTTPS (SSL / TLS)를 사용하기 위해 필요한 디지털 인증서를 무료로 제공 만료 기간이 90일, 만료 기간전에 수동으로 인증서를 갱신 또는 crontab, certbot auto" />
<meta name="twitter:url" content="https://simplehanlab.github.io/" />
<meta name="twitter:image" content="https://simplehanlab.github.io/assets/built/images/nginx-tomcat/nginx-logo.png" />
<meta name="twitter:label1" content="Written by" />
<meta name="twitter:data1" content="SimpleHan Lab" />
<meta name="twitter:label2" content="Filed under" />
<meta name="twitter:data2" content="https" />
<meta name="twitter:site" content="@" />
<meta name="twitter:creator" content="@" />
<meta property="og:image:width" content="1400" />
<meta property="og:image:height" content="933" />
<script type="application/ld+json">
{
"@context": "https://schema.org",
"@type": "Website",
"publisher": {
"@type": "Organization",
"name": "SimpleHan Lab",
"logo": "https://simplehanlab.github.io/"
},
"url": "https://simplehanlab.github.io/ssl-letsencrypt",
"image": {
"@type": "ImageObject",
"url": "https://simplehanlab.github.io/assets/built/images/nginx-tomcat/nginx-logo.png",
"width": 2000,
"height": 666
},
"mainEntityOfPage": {
"@type": "WebPage",
"@id": "https://simplehanlab.github.io/ssl-letsencrypt"
},
"description": "환경 Ubuntu 18.04 apt-get 을 통해 설치한 Nginx 도메인 ( 이번 과정에서는 도메인이 없는 경우를 대비 ngrok 을 이용한 임시 도메인 사용 ) Let’s Encrypt 웹 사이트에 HTTPS (SSL / TLS)를 사용하기 위해 필요한 디지털 인증서를 무료로 제공 만료 기간이 90일, 만료 기간전에 수동으로 인증서를 갱신 또는 crontab, certbot auto"
}
</script>
<!-- <script type="text/javascript" src="https://demo.ghost.io/public/ghost-sdk.min.js?v=724281a32e"></script>
<script type="text/javascript">
ghost.init({
clientId: "ghost-frontend",
clientSecret: "f84a07a72b17"
});
</script> -->
<meta name="generator" content="Jekyll 3.6.2" />
<link rel="alternate" type="application/rss+xml" title="Letsencrypt + Nginx SSL인증서(HTTPS) 적용" href="/feed.xml" />
</head>
<body class="post-template">
<div class="site-wrapper">
<!-- All the main content gets inserted here, index.hbs, post.hbs, etc -->
<!-- default -->
<!-- The tag above means: insert everything in this file
into the {body} of the default.hbs template -->
<header class="site-header outer">
<div class="inner">
<nav class="site-nav">
<div class="site-nav-left">
<a class="site-nav-logo" href="https://simplehanlab.github.io/">SimpleHan Lab</a>
<ul class="nav" role="menu">
<li class="nav-about" role="menuitem"><a href="/about/">About</a></li>
<li class="nav-jekyll" role="menuitem"><a href="/category/react/">react</a></li>
<li class="nav-python" role="menuitem"><a href="/category/spring/">spring</a></li>
<li class="nav-java" role="menuitem"><a href="/category/ios/">ios</a></li>
<li class="nav-jekyll" role="menuitem"><a href="/category/jekyll/">jekyll</a></li>
<li class="nav-python" role="menuitem"><a href="/category/minimal-mistakes/">minimal-mistakes</a></li>
<li class="nav-python" role="menuitem"><a href="/category/ssl/">ssl</a></li>
<li class="nav-python" role="menuitem"><a href="/category/tensorflow/">tensorflow</a></li>
<li class="nav-python" role="menuitem"><a href="/category/ssh/">ssh</a></li>
<li class="nav-archive" role="menuitem">
<a href="/archive.html">All Posts</a>
</li>
<li class="nav-archive" role="menuitem">
<a href="/categories.html">카테고리별 Posts</a>
</li>
<li class="nav-archive" role="menuitem">
<a href="/author_archive.html">Tag별 Posts</a>
</li>
</ul>
</div>
<div class="site-nav-right">
<div class="social-links">
</div>
<a class="subscribe-button" href="#subscribe">Search</a>
</div>
</nav>
</div>
</header>
<!-- Everything inside the #post tags pulls data from the post -->
<!-- #post -->
<main id="site-main" class="site-main outer" role="main">
<div class="inner">
<article class="post-full tag-https tag-ssl tag-letsencrypt ">
<header class="post-full-header">
<section class="post-full-meta">
<time class="post-full-meta-date" datetime="30 July 2019">30 July 2019</time>
<span class="date-divider">/</span>
<a href='/category/ssl/'>SSL</a>
</section>
<h1 class="post-full-title">Letsencrypt + Nginx SSL인증서(HTTPS) 적용</h1>
</header>
<!--
<figure class="post-full-image" style="background-image: url(/assets/built/images/nginx-tomcat/nginx-logo.png)">
</figure>
-->
<section class="post-full-content">
<div class="kg-card-markdown">
<h3 id="환경">환경</h3>
<ul>
<li>Ubuntu 18.04</li>
<li>apt-get 을 통해 설치한 Nginx</li>
<li>도메인 ( 이번 과정에서는 도메인이 없는 경우를 대비 ngrok 을 이용한 임시 도메인 사용 )</li>
</ul>
<h2 id="lets-encrypt">Let’s Encrypt</h2>
<ul>
<li>웹 사이트에 HTTPS (SSL / TLS)를 사용하기 위해 필요한 디지털 인증서를 무료로 제공</li>
<li>만료 기간이 90일, 만료 기간전에 수동으로 인증서를 갱신 또는 crontab, certbot auto 를 활용한 자동 갱신</li>
<li>자세한 내용은 <a href="https://letsencrypt.org/about/"> Let’s Encrypt 공식 사이트</a> 에서 확인</li>
</ul>
<h2 id="nginx-설치">Nginx 설치</h2>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>apt-get <span class="nb">install </span>nginx
</code></pre></div></div>
<p>80 포트를 사용하는 또다른 서비스가 존재한다면 서비스를 중지하거나 삭제 한 후 nginx 설치</p>
<p>설치완료 후 서버 포트 번호로 웹 브라우저에서 접속 시 nginx 화면이 나오는지 확인한다.</p>
<p><img src="\assets\built\images\letsencrypt\start-nginx.jpg" alt="img" /></p>
<p>Nginx 화면이 나오지 않을 시에는</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>service nginx restart
</code></pre></div></div>
<p>명령어로 nginx 를 재시작 해본 뒤 다시 웹 브라우저에서 접속시도 nginx index 화면이 제대로 나온다면 이제 Let’s Encrypt 를 이용하여 SSL 인증서를 받아보자</p>
<h2 id="certbot--설치">certbot 설치</h2>
<p>apt-get 에 certbot 저장소 추가</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>add-apt-repository ppa:certbot/certbot
</code></pre></div></div>
<p>패키지 목록을 업데이트 한 후에 certbot 을 설치</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>apt-get update
<span class="nv">$ </span><span class="nb">sudo </span>apt-get <span class="nb">install </span>python-certbot-nginx
</code></pre></div></div>
<p>SSL 인증을 하기에 앞서 구매한 도메인이 없다면, certbot 에서 해당 서버에 접근을 할 수가 없어 인증이 되지 않는다. 잠시 테스트용으로 ngrok 을 사용하여 임시 도메인을 사용해 테스트를 해보자</p>
<h2 id="ngrok-설치-및-실행">Ngrok 설치 및 실행</h2>
<p><a href="https://dashboard.ngrok.com/get-started">ngrok 홈페이지</a>에 들어가 간단한 회원가입 절차를 진행한 후에 운영체제에 맞는 ngrok 을 다운 받은 뒤 매뉴얼에 따라 ngrok을 실행해 보자 (이번 포스트 환경은 ubuntu 64bit 이므로 linux 를 다운로드한다.)</p>
<p><img src="\assets\built\images\letsencrypt\download-ngrok.jpg" alt="img" /></p>
<p>③ 번 까지 진행을 했다면 ngrok을 압춘을 푼 폴더에서</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo</span> ./ngrok http http://localhost
</code></pre></div></div>
<p>를 실행 해보자 그러면 이러한 화면이 나올 것이다.</p>
<p><img src="\assets\built\images\letsencrypt\exec-ngrok.jpg" alt="img" /></p>
<p>Fowarding 부분에 있는 http 주소를 복사( CTRL + C 는 ngrok을 중지시키는 단축키이므로 GUI 가 있는 운영체제라면 마우스 오른쪽 클릭을 활용하거나 직접 주소를 타이핑 하자!!!) 하여 웹 브라우저에서 들어가보면 nginx index 창이 뜨는걸 확인할 수 있다.</p>
<p>이제 ngrok을 실행 시켜 놓은 상태에서 새로운 터미널 창을 연뒤 certbot 을 이용해 인증서를 발급해 보도록 하자</p>
<h2 id="lets-encrypt-인증서-발급">Let’s Encrypt 인증서 발급</h2>
<p>설치한 certbot 을 이용하여 인증서를 발급 받을 것이다. 여기에선 인증서만 필요하므로 certonly 형식으로 인증서만 서버에 받아 오도록 진행 해보자</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>certbot certonly <span class="nt">--nginx</span> <span class="nt">-d</span> <span class="o">[</span>도메인 주소]
</code></pre></div></div>
<p>저 도메인 주소에 ngrok 으로 생성한 도메인을 넣어 주도록 하자</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>certbot certonly <span class="nt">--nginx</span> <span class="nt">-d</span> 8e7dcf95.ngrok.io
</code></pre></div></div>
<p>도메인 주소 부분에 http 또는 ‘ / ‘ 가 포함되지 않도록 주의 하자</p>
<p>명령어를 실행하면 서버 인증이 실행 되고</p>
<p><img src="\assets\built\images\letsencrypt\ssl-certbot.jpg" alt="img" /></p>
<p>Congratulation! 이라는 단어와 함께 인증이 완료되었다고 나올 것이다.</p>
<p>인증 완료 문구에서 보면</p>
<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code>/etc/letsencrypt/live/8e7dcf95.ngrok.io/fullchain.pem
/etc/letsencrypt/live/8e7dcf95.ngrok.io/privkey.pem
</code></pre></div></div>
<p>같은 경로가 보일 텐데 이 경로가 인증서가 저장되어진 경로이다. 해당 경로로 들어가 인증 된 파일을 확인해 보자</p>
<p><img src="\assets\built\images\letsencrypt\certfile.jpg" alt="img" /></p>
<p>총 4가지의 파일이 존재 할 것이다. 이중 fullchain.pem 과 privkey.pem 두가지만 nginx SSL 설정에 사용할 것이다.</p>
<h2 id="nginx-ssl-설정">Nginx SSL 설정</h2>
<p>Nginx 의 설정 파일을 수정 ( 여기서는 /etc/nginx/site-available/default 파일을 수정)</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>vim /etc/nginx/site-available/default
</code></pre></div></div>
<p>파일 내부를 확인해 보면 80 port 설정에 대한 server 블록이 존재할 것이다. 그 server 블록 아래에 443(SSL) port 에 대한 server 블록을 추가해 주자</p>
<div class="language-shell highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="c"># 80 포트의 대한 설정은 수정 하지 않는다. </span>
server <span class="o">{</span>
...
listen 80<span class="p">;</span>
listen <span class="o">[</span>::]:80<span class="p">;</span>
root /var/www/html<span class="p">;</span>
index index.html index.htm index.nginx-debian.html<span class="p">;</span>
server_name _<span class="p">;</span>
charset utf-8<span class="p">;</span>
location / <span class="o">{</span>
<span class="c"># First attempt to serve request as file, then</span>
<span class="c"># as directory, then fall back to displaying a 404.</span>
try_files <span class="nv">$uri</span> <span class="nv">$uri</span>/ <span class="o">=</span>404<span class="p">;</span>
<span class="o">}</span>
...
<span class="o">}</span>
<span class="c"># 443 포트를 설정하기 위한 server 블록 추가</span>
server <span class="o">{</span>
listen 443<span class="p">;</span>
listen <span class="o">[</span>::]:443<span class="p">;</span>
ssl on<span class="p">;</span> // ssl 을 활성화
server_name _<span class="p">;</span>
ssl_certificate /etc/letsencrypt/live/8e7dcf95.ngrok.io/fullchain.pem<span class="p">;</span>
ssl_certificate_key /etc/letsencrypt/live/8e7dcf95.ngrok.io/privkey.pem<span class="p">;</span>
location / <span class="o">{</span>
<span class="c"># First attempt to serve request as file, then</span>
<span class="c"># as directory, then fall back to displaying a 404.</span>
try_files <span class="nv">$uri</span> <span class="nv">$uri</span>/ <span class="o">=</span>404<span class="p">;</span>
<span class="o">}</span>
<span class="o">}</span>
</code></pre></div></div>
<p>ssl on 을 통해 SSL 을 활성화 시키고</p>
<p>ssl_certificate 에 발급받은 인증서 중 fullchain.pem 이 위치한 경로를 지정해 주고</p>
<p>ssl_certificate_key 에 발급받은 인증서 중 privkey.pem 이 위치한 경로를 지정해 준다.</p>
<p>파일을 저장 하고 나온 뒤 nginx 서버를 재시작 하자!</p>
<div class="language-bash highlighter-rouge"><div class="highlight"><pre class="highlight"><code><span class="nv">$ </span><span class="nb">sudo </span>service nginx restart
</code></pre></div></div>
<p>서버 재시작이 정상적으로 완료 되면 ngrok 에서 발급 받은 주소가 아닌 서버 포트 번호를 통해 HTTPS 보안 접속을 시도해 보자</p>
<p><img src="\assets\built\images\letsencrypt\connect-https-port.jpg" alt="img" /></p>
<p>연결이 비공개로 설정 되어 있다는 화면이 나올 것이다. 당황하지 말고 하단 고급탭을 선택 후 “192.168.107.128(안전하지 않음)(으)로 이동” 을 클릭해 보자</p>
<p><img src="\assets\built\images\letsencrypt\connect-https-port-result.jpg" alt="img" /></p>
<p>nginx index 화면이 정상적으로 나올 것이다.</p>
<p>여기서 인증서가 적용이 잘 되었는지 확인을 하기 위해 웹 브라우저 주소검색줄 부분 왼쪽을 보면 주의요함 이라는 글씨가 보일 것이다. 이부분을 클릭한뒤 나오는 메뉴 중에서 인증서 탭을 선택해 보자</p>
<p><img src="\assets\built\images\letsencrypt\check-cert.jpg" alt="img" /></p>
<p>인증서 정보가 나오게 될 텐데 여기서 발급 대상은 ngrok을 통해 생성한 도메인 주소가, 발급자는 Let’s Encrypt 가 유효기간은 90일이 설정되어 보일 것이다.</p>
<p><img src="\assets\built\images\letsencrypt\check-cert2.jpg" alt="img" /></p>
<p>다음 게시글에서는 SSL 설정이 완료된 Nginx 에 Tomcat 을 연동하는 방법을 설명해 보겠다.</p>
<p>바로가기: <a href="https://simplehanlab.github.io/ssl/ssl-nginx-tomcat/">Nginx + Tomcat8 연동</a></p>
</div>
</section>
<a href='/tag/https/'>HTTPS</a>,
<a href='/tag/ssl/'>SSL</a>,
<a href='/tag/letsencrypt/'>LETSENCRYPT</a>
<!-- Email subscribe form at the bottom of the page -->
<!--
<section class="subscribe-form">
<h3 class="subscribe-form-title">Subscribe to SimpleHan Lab</h3>
<p>Get the latest posts delivered right to your inbox</p>
<span id="searchform" method="post" action="/subscribe/" class="">
<input class="confirm" type="hidden" name="confirm" />
<input class="location" type="hidden" name="location" />
<input class="referrer" type="hidden" name="referrer" />
<div class="form-group">
<input class="subscribe-email" onkeyup="myFunc()"
id="searchtext" type="text" name="searchtext"
placeholder="Search..." />
</div>
<script type="text/javascript">
function myFunc() {
if(event.keyCode == 13) {
var url = encodeURIComponent($("#searchtext").val());
location.href = "/search.html?query=" + url;
}
}
</script>
</span>
</section>
-->
<footer class="post-full-footer">
<!-- Everything inside the #author tags pulls data from the author -->
<!-- #author-->
<section class="author-card">
<img class="author-profile-image" src="/assets/built/images/author-logo.jpg" alt="Simplehan" />
<section class="author-card-content">
<h4 class="author-card-name"><a href="/author/Simplehan">Simplehan</a></h4>
<p>We are amazing developers.</p>
</section>
</section>
<div class="post-full-footer-right">
<a class="author-card-button" href="/author/Simplehan">Read More</a>
</div>
<!-- /author -->
</footer>
<!-- If you use Disqus comments, just uncomment this block.
The only thing you need to change is "test-apkdzgmqhj" - which
should be replaced with your own Disqus site-id. -->
<section class="post-full-comments">
<div id="disqus_thread"></div>
<script>
var disqus_config = function () {
var this_page_url = 'https://simplehanlab.github.io/ssl-letsencrypt';
var this_page_identifier = '/ssl-letsencrypt';
var this_page_title = 'Letsencrypt + Nginx SSL인증서(HTTPS) 적용';
};
(function() {
var d = document, s = d.createElement('script');
s.src = 'https://simplehanlab.disqus.com/embed.js';
s.setAttribute('data-timestamp', +new Date());
(d.head || d.body).appendChild(s);
})();
</script>
</section>
</article>
</div>
</main>
<!-- Links to Previous/Next posts -->
<aside class="read-next outer">
<div class="inner">
<div class="read-next-feed">
<article class="read-next-card"
style="background-image: url(/assets/built/images/blog-cover1.png)"
>
<header class="read-next-card-header">
<small class="read-next-card-header-sitetitle">— SimpleHan Lab —</small>
<h3 class="read-next-card-header-title"><a href="/tag/https/">Https</a></h3>
</header>
<div class="read-next-divider"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M13 14.5s2 3 5 3 5.5-2.463 5.5-5.5S21 6.5 18 6.5c-5 0-7 11-12 11C2.962 17.5.5 15.037.5 12S3 6.5 6 6.5s4.5 3.5 4.5 3.5"/></svg>
</div>
<div class="read-next-card-content">
<ul>
<li><a href="/ssl-nginx-tomcat">Nginx + Tomcat8 연동</a></li>
</ul>
</div>
<footer class="read-next-card-footer">
<a href="/tag/https/">
See all 1 posts →
</a>
</footer>
</article>
<!-- If there's a next post, display it using the same markup included from - partials/post-card.hbs -->
<article class="post-card post-template">
<a class="post-card-image-link" href="/ssl-nginx-tomcat">
<div class="post-card-image" style="background-image: url(/assets/built/images/nginx-tomcat/nginx-logo.png)"></div>
</a>
<div class="post-card-content">
<a class="post-card-content-link" href="/ssl-nginx-tomcat">
<header class="post-card-header">
<span class="post-card-tags">Https</span>
<span class="post-card-tags">Ssl</span>
<span class="post-card-tags">Letsencrypt</span>
<span class="post-card-tags">Secure</span>
<h2 class="post-card-title">Nginx + Tomcat8 연동</h2>
</header>
<section class="post-card-excerpt">
<p>지난 시간에는 nginx 에 let’s encrypt 를 이용하여 무료 SSL 인증서를 적용해 보았다. 이번 시간에는 SSL 인증서로 https 접속이 가능해진 nginx 에 톰캣을 연결해 보도록 할 것이다.
</p>
</section>
</a>
<footer class="post-card-meta">
<img class="author-profile-image" src="/assets/built/images/author-logo.jpg" alt="Simplehan" />
<span class="post-card-author">
<a href="/author/Simplehan/">Simplehan</a>
</span>
<span class="reading-time">
1 min read
</span>
</footer>
</div>
</article>
<!-- If there's a previous post, display it using the same markup included from - partials/post-card.hbs -->
</div>
</div>
</aside>
<!-- Floating header which appears on-scroll, included from includes/floating-header.hbs -->
<div class="floating-header">
<div class="floating-header-logo">
<a href="https://simplehanlab.github.io/">
<span>SimpleHan Lab</span>
</a>
</div>
<span class="floating-header-divider">—</span>
<div class="floating-header-title">Letsencrypt + Nginx SSL인증서(HTTPS) 적용</div>
<div class="floating-header-share">
<div class="floating-header-share-label">Share this <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
<path d="M7.5 15.5V4a1.5 1.5 0 1 1 3 0v4.5h2a1 1 0 0 1 1 1h2a1 1 0 0 1 1 1H18a1.5 1.5 0 0 1 1.5 1.5v3.099c0 .929-.13 1.854-.385 2.748L17.5 23.5h-9c-1.5-2-5.417-8.673-5.417-8.673a1.2 1.2 0 0 1 1.76-1.605L7.5 15.5zm6-6v2m-3-3.5v3.5m6-1v2"/>
</svg>
</div>
<a class="floating-header-share-tw" href="https://twitter.com/share?text=Letsencrypt+%2B+Nginx+SSL%EC%9D%B8%EC%A6%9D%EC%84%9C%28HTTPS%29+%EC%A0%81%EC%9A%A9&url=https://simplehanlab.github.io/ssl-letsencrypt"
onclick="window.open(this.href, 'share-twitter', 'width=550,height=235');return false;">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 32 32"><path d="M30.063 7.313c-.813 1.125-1.75 2.125-2.875 2.938v.75c0 1.563-.188 3.125-.688 4.625a15.088 15.088 0 0 1-2.063 4.438c-.875 1.438-2 2.688-3.25 3.813a15.015 15.015 0 0 1-4.625 2.563c-1.813.688-3.75 1-5.75 1-3.25 0-6.188-.875-8.875-2.625.438.063.875.125 1.375.125 2.688 0 5.063-.875 7.188-2.5-1.25 0-2.375-.375-3.375-1.125s-1.688-1.688-2.063-2.875c.438.063.813.125 1.125.125.5 0 1-.063 1.5-.25-1.313-.25-2.438-.938-3.313-1.938a5.673 5.673 0 0 1-1.313-3.688v-.063c.813.438 1.688.688 2.625.688a5.228 5.228 0 0 1-1.875-2c-.5-.875-.688-1.813-.688-2.75 0-1.063.25-2.063.75-2.938 1.438 1.75 3.188 3.188 5.25 4.25s4.313 1.688 6.688 1.813a5.579 5.579 0 0 1 1.5-5.438c1.125-1.125 2.5-1.688 4.125-1.688s3.063.625 4.188 1.813a11.48 11.48 0 0 0 3.688-1.375c-.438 1.375-1.313 2.438-2.563 3.188 1.125-.125 2.188-.438 3.313-.875z"/></svg>
</a>
<a class="floating-header-share-fb" href="https://www.facebook.com/sharer/sharer.php?u=https://simplehanlab.github.io/ssl-letsencrypt"
onclick="window.open(this.href, 'share-facebook','width=580,height=296');return false;">
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 32 32"><path d="M19 6h5V0h-5c-3.86 0-7 3.14-7 7v3H8v6h4v16h6V16h5l1-6h-6V7c0-.542.458-1 1-1z"/></svg>
</a>
</div>
<progress class="progress" value="0">
<div class="progress-container">
<span class="progress-bar"></span>
</div>
</progress>
</div>
<!-- /post -->
<!-- The #contentFor helper here will send everything inside it up to the matching #block helper found in default.hbs -->
<!-- Previous/next page links - displayed on every page -->
<!-- The footer at the very bottom of the screen -->
<footer class="site-footer outer">
<div class="site-footer-content inner">
<section class="copyright"><a href="https://simplehanlab.github.io/">SimpleHan Lab</a> © 2021</section>
<section class="poweredby">Proudly published with <a href="https://jekyllrb.com/">Jekyll</a> &
<a href="https://pages.github.com/" target="_blank" rel="noopener">GitHub Pages</a> using
<a href="https://github.com/jekyllt/jasper2" target="_blank" rel="noopener">Jasper2</a></section>
<nav class="site-footer-nav">
<a href="/">Latest Posts</a>
<a href="https://ghost.org" target="_blank" rel="noopener">Ghost</a>
</nav>
</div>
</footer>
</div>
<!-- The big email subscribe modal content -->
<div id="subscribe" class="subscribe-overlay">
<a class="subscribe-overlay-close" href="#"></a>
<div class="subscribe-overlay-content">
<h1 class="subscribe-overlay-title">Search SimpleHan Lab</h1>
<p class="subscribe-overlay-description">
lunr.js를 이용한 posts 검색 </p>
<span id="searchform" method="post" action="/subscribe/" class="">
<input class="confirm" type="hidden" name="confirm" />
<input class="location" type="hidden" name="location" />
<input class="referrer" type="hidden" name="referrer" />
<div class="form-group">
<input class="subscribe-email" onkeyup="myFunc()"
id="searchtext" type="text" name="searchtext"
placeholder="Search..." />
</div>
<script type="text/javascript">
function myFunc() {
if(event.keyCode == 13) {
var url = encodeURIComponent($("#searchtext").val());
location.href = "/search.html?query=" + url;
}
}
</script>
</span>
</div>
</div>
<!-- highlight.js -->
<script src="https://cdnjs.cloudflare.com/ajax/libs/prism/1.10.0/components/prism-abap.min.js"></script>
<script>$(document).ready(function() {
$('pre code').each(function(i, block) {
hljs.highlightBlock(block);
});
});</script>
<!-- jQuery + Fitvids, which makes all video embeds responsive -->
<script
src="https://code.jquery.com/jquery-3.2.1.min.js"
integrity="sha256-hwg4gsxgFZhOsEEamdOYGBf13FyQuiTwlAQgxVSNgt4="
crossorigin="anonymous">
</script>
<script type="text/javascript" src="/assets/js/jquery.fitvids.js"></script>
<script type="text/javascript" src="https://demo.ghost.io/assets/js/jquery.fitvids.js?v=724281a32e"></script>
<!-- Paginator increased to "infinit" in _config.yml -->
<!-- if paginator.posts -->
<!-- <script>
var maxPages = parseInt('');
</script>
<script src="/assets/js/infinitescroll.js"></script> -->
<!-- /endif -->
<!-- Add Google Analytics -->
<!-- Google Analytics Tracking code -->
<script>
(function(i,s,o,g,r,a,m){i['GoogleAnalyticsObject']=r;i[r]=i[r]||function(){
(i[r].q=i[r].q||[]).push(arguments)},i[r].l=1*new Date();a=s.createElement(o),
m=s.getElementsByTagName(o)[0];a.async=1;a.src=g;m.parentNode.insertBefore(a,m)
})(window,document,'script','//www.google-analytics.com/analytics.js','ga');
ga('create', 'UA-xxxxxxxx-x', 'auto');
ga('send', 'pageview');
</script>
<!-- The #block helper will pull in data from the #contentFor other template files. In this case, there's some JavaScript which we only want to use in post.hbs, but it needs to be included down here, after jQuery has already loaded. -->
<script>
// NOTE: Scroll performance is poor in Safari
// - this appears to be due to the events firing much more slowly in Safari.
// Dropping the scroll event and using only a raf loop results in smoother
// scrolling but continuous processing even when not scrolling
$(document).ready(function () {
// Start fitVids
var $postContent = $(".post-full-content");
$postContent.fitVids();
// End fitVids
var progressBar = document.querySelector('progress');
var header = document.querySelector('.floating-header');
var title = document.querySelector('.post-full-title');
var lastScrollY = window.scrollY;
var lastWindowHeight = window.innerHeight;
var lastDocumentHeight = $(document).height();
var ticking = false;
function onScroll() {
lastScrollY = window.scrollY;
requestTick();
}
function onResize() {
lastWindowHeight = window.innerHeight;
lastDocumentHeight = $(document).height();
requestTick();
}
function requestTick() {
if (!ticking) {
requestAnimationFrame(update);
}
ticking = true;
}
function update() {
var trigger = title.getBoundingClientRect().top + window.scrollY;
var triggerOffset = title.offsetHeight + 35;
var progressMax = lastDocumentHeight - lastWindowHeight;
// show/hide floating header
if (lastScrollY >= trigger + triggerOffset) {
header.classList.add('floating-active');
} else {
header.classList.remove('floating-active');
}
progressBar.setAttribute('max', progressMax);
progressBar.setAttribute('value', lastScrollY);
ticking = false;
}
window.addEventListener('scroll', onScroll, {passive: true});
window.addEventListener('resize', onResize, false);
update();
});
</script>
<!-- Ghost outputs important scripts and data with this tag - it should always be the very last thing before the closing body tag -->
<!-- ghost_foot -->
</body>
</html>