<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>2015/05/01 on Yano&#39;s digital garage</title>
    <link>https://www.bravotouring.com/~yano/archives/2015/05/01/</link>
    <description>Recent content in 2015/05/01 on Yano&#39;s digital garage</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 01 May 2015 23:35:02 +0900</lastBuildDate>
    <atom:link href="https://www.bravotouring.com/~yano/archives/2015/05/01/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>StartSSL更新</title>
      <link>https://www.bravotouring.com/~yano/diary/it/20150501startssl.htm</link>
      <pubDate>Fri, 01 May 2015 23:35:02 +0900</pubDate>
      <guid>https://www.bravotouring.com/~yano/diary/it/20150501startssl.htm</guid>
      <description>&lt;p&gt;4月26日に&lt;blockquote&gt;This mail is intended for the person who owns a digital certificate issued by the StartSSL™ Certification Authority (http://www.startssl.com/).&lt;br/&gt;&lt;br/&gt;The Class 1, server certificate for mail.bravotouring.com and serial number 10XYZ29 (106XYZ) is about to expire in about two weeks. Please log into the StartSSL Control Panel at https://www.startssl.com/?app=12 and get a new certificate for this purpose.&lt;/blockquote&gt;というメールが着信。&lt;/p&gt;&#xA;&lt;table align=&#34;right&#34; class=&#34;Landscape&#34;&gt;&#xA;&lt;tr&gt;&#xA;&lt;td&gt;&lt;img alt=&#34;プール開き&#34; src=&#34;https://www.bravotouring.com/~yano/images/2015/20150501.jpg&#34;/&gt;&lt;/td&gt;&#xA;&lt;/tr&gt;&#xA;&lt;tr&gt;&#xA;&lt;td class=&#34;PhotoMemo&#34;&gt;大掃除の後はプール開き&lt;/td&gt;&#xA;&lt;/tr&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.startssl.com/&#34;&gt;StartSSL&lt;/a&gt;から、&lt;a href=&#34;https://www.bravotouring.com/~yano/diary/it/20150501startssl.htm&#34;&gt;昨年5月に導入&lt;/a&gt;した証明書が2週間後に切れるよ～という事だ。&lt;a href=&#34;https://www.bravotouring.com/~yano/diary/it/20141120letsencrypt.htm&#34;&gt;Let&#39;s Encrypt プロジェクト&lt;/a&gt;の「2015 年の第二四半期の運用開始」が前倒しになる事を期待していたのだが、取り敢えず&lt;a href=&#34;http://yanmoo.blogspot.jp/2013/04/startssl.html&#34;&gt;StartSSL更新を行う&lt;/a&gt;を参考に&lt;a href=&#34;https://www.startssl.com/&#34;&gt;StartSSL&lt;/a&gt;で証明書を更新してみた。&lt;/p&gt;&#xA;&lt;p&gt;クライアント証明書とサーバ秘密鍵＆証明書の更新を無事に終えたら、&lt;a href=&#34;https://www.bravotouring.com/~yano/diary/it/20120508vps.htm&#34;&gt;さくらのVPS&lt;/a&gt;での設定変更。&lt;a href=&#34;https://www.startssl.com/&#34;&gt;StartSSL&lt;/a&gt;で発行した秘密鍵を&lt;span class=&#34;Path&#34;&gt;/etc/ssl/private/2015.mail.bravotouring.com.key&lt;/span&gt;、サーバ証明書を&lt;span class=&#34;Path&#34;&gt;/etc/ssl/certs/2015.ssl-cert-mail.bravotouring.com.pem&lt;/span&gt;としてファイル化する。&lt;/p&gt;&#xA;&lt;p&gt;続いて&lt;span class=&#34;Software&#34;&gt;apache&lt;/span&gt;の設定は&lt;span class=&#34;Path&#34;&gt;/etc/apache2/sites-available/mail.bravotouring.com.conf&lt;/span&gt;の&lt;blockquote cite=&#34;/etc/apache2/sites-available/mail.bravotouring.com.conf&#34; class=&#34;Log&#34;&gt; &lt;span class=&#34;Strong&#34;&gt;SSLCertificateFile&lt;/span&gt; &lt;span class=&#34;Path&#34;&gt;/etc/ssl/certs/2015.ssl-cert-mail.bravotouring.com.pem&lt;/span&gt;&lt;br/&gt; &lt;span class=&#34;Strong&#34;&gt;SSLCertificateKeyFile&lt;/span&gt; &lt;span class=&#34;Path&#34;&gt;/etc/ssl/private/2015.mail.bravotouring.com.key&lt;/span&gt;&lt;/blockquote&gt;が該当する。&lt;/p&gt;&#xA;&lt;p&gt;SMTPな&lt;span class=&#34;Software&#34;&gt;postfix&lt;/span&gt;の設定が&lt;span class=&#34;Path&#34;&gt;/etc/postfix/main.cf&lt;/span&gt;で、POP3な&lt;span class=&#34;Software&#34;&gt;dovecot&lt;/span&gt;の設定が&lt;span class=&#34;Path&#34;&gt;/etc/dovecot/conf.d/01-dovecot-postfix.conf&lt;/span&gt;だが、証明書類のファイルパスは共通なので&#xA;&lt;blockquote class=&#34;Log&#34;&gt;&#xA;root@vps:/etc/ssl/private$ ll /etc/ssl/certs/ssl-cert-mail.pem /etc/ssl/private/ssl-mail.key&lt;br/&gt;&#xA;lrwxrwxrwx 1 root root 66 May  1 23:30 /etc/ssl/certs/ssl-cert-mail.pem -&gt; /usr/share/ca-certificates/startssl/2015.mail.bravotouring.com.pem&lt;br/&gt;&#xA;lrwxrwxrwx 1 root root 30 May  1 23:28 /etc/ssl/private/ssl-mail.key -&gt; 2015.mail.bravotouring.com.key&#xA;&lt;/blockquote&gt;としてシンボリックリンクを張り替えた後、&lt;blockquote class=&#34;Log&#34;&gt;$ sudo service postfix restart&lt;br/&gt;$ sudo service dovecot restart&lt;/blockquote&gt;でOK。&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
