๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ’ป๊ฐœ๋ฐœ

AWS Lightsail์—์„œ SSL ์ธ์ฆ์„œ ์„ค์ • ๋ฐ ๊ด€๋ฆฌํ•˜๊ธฐ: Certbot๊ณผ Apache ํ™œ์šฉ๋ฒ•

by ๋ˆˆ๋ˆ„ :) 2024. 1. 2.

 

 

 

AWS Lightsail์€ ๊ด€๋ฆฌ๊ฐ€ ์šฉ์ดํ•œ ๊ฐ€์ƒ ํ”„๋ผ์ด๋จธ๋ฆฌ ์„œ๋ฒ„๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ธ€์—์„œ๋Š” AWS Lightsail์—์„œ Certbot๊ณผ Apache๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ SSL/TLS ์ธ์ฆ์„œ๋ฅผ ์„ค์ •ํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•ˆ๋‚ดํ•ฉ๋‹ˆ๋‹ค.

 

 

 

Certbot๊ณผ SSL/TLS ์ธ์ฆ์„œ


SSL/TLS ์ธ์ฆ์„œ๋Š” ์›น์‚ฌ์ดํŠธ์˜ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ณ  ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๋ฐ ํ•„์ˆ˜์ ์ž…๋‹ˆ๋‹ค.

Let's Encrypt๋Š” ๋ฌด๋ฃŒ๋กœ SSL/TLS ์ธ์ฆ์„œ๋ฅผ ์ œ๊ณตํ•˜๋ฉฐ, Certbot์€ ์ด ์ธ์ฆ์„œ๋ฅผ ์‰ฝ๊ฒŒ ์„ค์น˜ํ•˜๊ณ  ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๋„๊ตฌ์ž…๋‹ˆ๋‹ค.

 

 

 

1๋‹จ๊ณ„: Certbot ์„ค์น˜ ๋ฐ ์ธ์ฆ์„œ ๋ฐœ๊ธ‰


Certbot ์„ค์น˜:
AWS Lightsail LAMP ์„œ๋ฒ„์— SSH๋กœ ์ ‘์†ํ•œ ํ›„ sudo apt-get install certbot ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Certbot์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

์ธ์ฆ์„œ ๋ฐœ๊ธ‰:
์›น ์„œ๋ฒ„๋ฅผ ์ค‘์ง€ํ•œ ํ›„ sudo certbot certonly --standalone -d yourdomain.com ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰๋ฐ›์Šต๋‹ˆ๋‹ค.

 

 

2๋‹จ๊ณ„: Apache ์„ค์ • ๋ณ€๊ฒฝ


์ธ์ฆ์„œ๊ฐ€ ์„ฑ๊ณต์ ์œผ๋กœ ๋ฐœ๊ธ‰๋˜๋ฉด, Apache์˜ ์„ค์ •์„ ์—…๋ฐ์ดํŠธํ•˜์—ฌ ์ธ์ฆ์„œ๋ฅผ ์ ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ผ๋ฐ˜์ ์œผ๋กœ ์ธ์ฆ์„œ์™€ ํ‚ค ํŒŒ์ผ์€ /etc/letsencrypt/live/yourdomain.com/์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค.

Apache ์„ค์ • ํŒŒ์ผ(์˜ˆ: bitnami.conf ๋˜๋Š” 000-default-le-ssl.conf)์—์„œ SSLCertificateFile๊ณผ SSLCertificateKeyFile ์ง€์‹œ์–ด๋ฅผ ํ•ด๋‹น ๊ฒฝ๋กœ๋กœ ์—…๋ฐ์ดํŠธํ•ฉ๋‹ˆ๋‹ค.

 

 

3๋‹จ๊ณ„: HTTPS ๋ฆฌ๋‹ค์ด๋ ‰์…˜ ์„ค์ •


.htaccess ํŒŒ์ผ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ชจ๋“  HTTP ์š”์ฒญ์„ HTTPS๋กœ ๋ฆฌ๋‹ค์ด๋ ‰ํŠธํ•˜๋„๋ก ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ์•ˆ์ „ํ•œ ์—ฐ๊ฒฐ์„ ํ†ตํ•ด ์›น์‚ฌ์ดํŠธ์— ์•ก์„ธ์Šคํ•˜๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค.

 

 

4๋‹จ๊ณ„: ์ธ์ฆ์„œ ๊ฐฑ์‹  ํ™•์ธ


Let's Encrypt์˜ ์ธ์ฆ์„œ๋Š” 90์ผ๋งˆ๋‹ค ๊ฐฑ์‹ ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

certbot renew ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ธ์ฆ์„œ์˜ ์ž๋™ ๊ฐฑ์‹ ์„ ์„ค์ •ํ•˜๊ณ , ์›น ์„œ๋ฒ„๊ฐ€ ์ด๋ฅผ ์ง€์›ํ•˜๋„๋ก ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

 

 

๊ฒฐ๋ก 

 

AWS Lightsail๊ณผ Certbot์„ ์‚ฌ์šฉํ•˜์—ฌ SSL/TLS ์ธ์ฆ์„œ๋ฅผ ๊ด€๋ฆฌํ•˜๋ฉด, ์›น์‚ฌ์ดํŠธ์˜ ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ณ  ์‚ฌ์šฉ์ž ์‹ ๋ขฐ๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ •ํ™•ํ•œ ์„ค์ •๊ณผ ์ฃผ๊ธฐ์ ์ธ ๊ด€๋ฆฌ๋กœ, ์›น์‚ฌ์ดํŠธ๋Š” ์•ˆ์ „ํ•˜๊ณ  ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ์ƒํƒœ๋ฅผ ์œ ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

 

 

์ฐธ๊ณ  ์ž๋ฃŒ

Let's Encrypt Documentation
Apache Web Server Configuration Files

 

๋ฌธ์„œ - Let's Encrypt - ๋ฌด๋ฃŒ SSL/TLS ์ธ์ฆ์„œ

 

letsencrypt.org

 

์„ค์ •ํŒŒ์ผ - Apache HTTP Server Version 2.4

์„ค์ •ํŒŒ์ผ ์ด ๋ฌธ์„œ๋Š” ์ตœ์‹ ํŒ ๋ฒˆ์—ญ์ด ์•„๋‹™๋‹ˆ๋‹ค. ์ตœ๊ทผ์— ๋ณ€๊ฒฝ๋œ ๋‚ด์šฉ์€ ์˜์–ด ๋ฌธ์„œ๋ฅผ ์ฐธ๊ณ ํ•˜์„ธ์š”. ์ด ๋ฌธ์„œ๋Š” ์•„ํŒŒ์น˜ ์›น์„œ๋ฒ„๋ฅผ ์„ค์ •ํ•˜๋Š” ํŒŒ์ผ๋“ค์„ ์„ค๋ช…ํ•œ๋‹ค. ์ผ๋ฐ˜ ๋ฌธ์„œ ํŒŒ์ผ์ธ ์„ค์ •ํŒŒ์ผ์— ์ง€์‹œ์–ด๋ฅผ

httpd.apache.org

 

 

 

/opt/bitnami/apache2/conf/bitnami/bitnami-ssl.conf

 

SSLCertificateFile "/etc/letsencrypt/live/domain.com/fullchain.pem"
SSLCertificateKeyFile "/etc/letsencrypt/live/ domain.com /privkey.pem"