<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Archives des SSL - CoffeeBreak Info</title>
	<atom:link href="https://coffeebreak.en-images.info/tag/ssl/feed/" rel="self" type="application/rss+xml" />
	<link>https://coffeebreak.en-images.info/tag/ssl/</link>
	<description>Une petite pause :)</description>
	<lastBuildDate>Fri, 12 Nov 2021 18:30:13 +0000</lastBuildDate>
	<language>fr-FR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://coffeebreak.en-images.info/wp-content/uploads/2021/07/cropped-Tasse_Cafe-scaled-1-32x32.jpg</url>
	<title>Archives des SSL - CoffeeBreak Info</title>
	<link>https://coffeebreak.en-images.info/tag/ssl/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>MODOP &#8211; Générer des certificats SSL – Hôte Idrac DELL</title>
		<link>https://coffeebreak.en-images.info/modop-generer-une-clef-ssl-hote-idrac-dell/</link>
					<comments>https://coffeebreak.en-images.info/modop-generer-une-clef-ssl-hote-idrac-dell/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sat, 12 Jun 2021 17:34:14 +0000</pubDate>
				<category><![CDATA[Matériels]]></category>
		<category><![CDATA[DELL]]></category>
		<category><![CDATA[Serveur]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Système]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=1580</guid>

					<description><![CDATA[<p>Mise en place de Certificat SSL sur l'interface Web IDRAC d'une machine DELL R730.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-generer-une-clef-ssl-hote-idrac-dell/">MODOP &#8211; Générer des certificats SSL – Hôte Idrac DELL</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" width="1383" height="489" class="wp-image-1581" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-378.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-378.png 1383w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-378-300x106.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-378-1024x362.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-378-768x272.png 768w" sizes="(max-width: 1383px) 100vw, 1383px" /></p>
<h4><span style="text-decoration: underline;"><strong>Générer les certificats Privé et Public</strong></span></h4>
<p>Sur les machines DELL Idrac, aucun client n’est disponible pour générer des certificats Public et Privé.<br />
Dans le cas présent, nous allons installer un client openssl (uniquement les binaires) sur un poste Windows ou Linux.</p>
<p><strong>Créer un fichier openssl-esx01.cfg</strong><br />
<em>[ req ]</em><br />
<em>default_bits = 2048</em><br />
<em>default_keyfile = <span style="color: #ff0000;"><strong>esx01.key</strong></span></em><br />
<em>distinguished_name = req_distinguished_name</em><br />
<em>encrypt_key = no</em><br />
<em>prompt = no</em><br />
<em>string_mask = nombstr</em><br />
<em>req_extensions = v3_req</em></p>
<p><em>[ v3_req ]</em><br />
<em>basicConstraints = CA:FALSE</em><br />
<em>keyUsage = digitalSignature, keyEncipherment, dataEncipherment</em><br />
<em>extendedKeyUsage = serverAuth, clientAuth</em><br />
<em>subjectAltName = DNS:<span style="color: #ff0000;">esx01, IP:192.168.1.10, DNS:esx01.house.cpb</span></em></p>
<p><em>[ req_distinguished_name ]</em><br />
<em>countryName =<span style="color: #ff0000;"><strong> FR</strong></span></em><br />
<em>stateOrProvinceName = <span style="color: #ff0000;"><strong>France</strong></span></em><br />
<em>localityName = <span style="color: #ff0000;"><strong>PARIS</strong></span></em><br />
<em>0.organizationName =<span style="color: #ff0000;"><strong> house.cpb</strong></span></em><br />
<em>organizationalUnitName = <span style="color: #ff0000;"><strong>house.cpb</strong></span></em><br />
<em>commonName = <strong><span style="color: #ff0000;">esx01.house.cpb</span></strong></em></p>
<p><strong>Ouvrir un terminal Windows</strong><br />
C:\&gt;cd C:\Program Files\OpenSSL-Win64\bin</p>
<p><strong>Générons la clef public via la commande suivante</strong></p>
<ul>
<li><strong><span style="color: #ff0000;">openssl req -new -nodes -out c:\tmp\esx01.csr -keyout c:\tmp\esx01-tmp.key -config openssl-esx01.cfg</span></strong></li>
</ul>
<p>C:\Program Files\OpenSSL-Win64\bin&gt;<span style="color: #ff0000;"><strong>openssl req -new -nodes -out c:\tmp\esx01.csr -keyout c:\tmp\esx01-tmp.key -config c:\tmp\openssl-esx01.cfg</strong></span></p>
<p><img decoding="async" width="954" height="112" class="wp-image-1584" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-379.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-379.png 954w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-379-300x35.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-379-768x90.png 768w" sizes="(max-width: 954px) 100vw, 954px" /></p>
<p><strong>Générons la clef privé via la commande suivante</strong></p>
<ul>
<li><span style="color: #ff0000;"><strong>openssl rsa -in c:\tmp\mrf-esx01-tmp.key -out c:\tmp\esx01.key</strong></span></li>
</ul>
<p>C:\Program Files\OpenSSL-Win64\bin&gt;<span style="color: #ff0000;"><strong>openssl rsa -in c:\tmp\esx01-tmp.key -out c:\tmp\esx01.key</strong></span></p>
<p><img decoding="async" width="855" height="48" class="wp-image-1586" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-380.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-380.png 855w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-380-300x17.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-380-768x43.png 768w" sizes="(max-width: 855px) 100vw, 855px" /></p>
<p><strong><span style="color: #ff0000;">Le fichier esx01-tmp.key est à supprimer.</span></strong></p>
<p>Nous avons une Clef publique et une clef privée</p>
<ul>
<li>esx01.csr : Clef Publique</li>
<li>esx01.key : Clef Privée</li>
</ul>
<p><img loading="lazy" decoding="async" width="552" height="77" class="wp-image-1587" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-381.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-381.png 552w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-381-300x42.png 300w" sizes="auto, (max-width: 552px) 100vw, 552px" /></p>
<p><strong><span style="color: #ff0000;">Faire certifier votre certificat par votre autorité , ou alors auto signé celui-ci vous-même.</span></strong></p>
<p>C:\Program Files\OpenSSL-Win64\bin&gt;<span style="color: #ff0000;"><strong>openssl x509 -req -days 365 -in c:\tmp\esx01.csr -signkey c:\tmp\esx01.key -out esx01-idrac.cer</strong></span></p>
<h4><span style="text-decoration: underline;"><strong>Upload des Clertificats sur la machine iDRAC</strong></span></h4>
<p>A présent, il faut uploader les deux certificats sur la machine iDRAC</p>
<ul>
<li>Clef Privé : <strong>esx01.key</strong></li>
<li>Clef Signé : <strong>esx01-idrac.cer</strong> (Signé par votre autorité)</li>
</ul>
<p>Pour faire l’Upload des certificats dans les iDRAC , il faut utiliser le logiciel Racadm.</p>
<ul>
<li><a href="https://www.dell.com/support/home/fr-fr/drivers/driversdetails?driverid=9dd9y">https://www.dell.com/support/home/fr-fr/drivers/driversdetails?driverid=9dd9y</a></li>
</ul>
<p><strong>Chargement des certificats Privé (Terminal mode Administrateur)</strong></p>
<p>C:\Program Files\Dell\SysMgt\rac5&gt;<span style="color: #ff0000;"><strong>racadm -r esx01.house.cpb -u admin -p XXXXX sslkeyupload -t 1 -f C:\tmp\CertificatsMRF\iDRAC_ESX01\esx01.key</strong></span></p>
<p><strong>Chargement des certificats Autosignés par l’autorité (Terminal mode Administrateur)</strong></p>
<p>C:\Program Files\Dell\SysMgt\rac5&gt;<strong><span style="color: #ff0000;">racadm -r esx01.house.cpb -u admin -p XXXXXX sslcertupload -t 1 -f C:\tmp\CertificatsMRF\iDRAC_ESX01\Autorite\esx01-idrac.cer</span></strong></p>
<p><strong>Réinitialiser l’iDRAC pour prendre en compte le certificat</strong></p>
<p>C:\Program Files\Dell\SysMgt\rac5&gt;<strong><span style="color: #ff0000;">racadm -r esx01.house.cpb -u admin -p XXXX racreset</span></strong></p>
<p><img loading="lazy" decoding="async" width="1299" height="328" class="wp-image-1589" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-382.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-382.png 1299w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-382-300x76.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-382-1024x259.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-382-768x194.png 768w" sizes="auto, (max-width: 1299px) 100vw, 1299px" /></p>
<p><img loading="lazy" decoding="async" width="1462" height="425" class="wp-image-1592" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-383.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-383.png 1462w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-383-300x87.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-383-1024x298.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-383-768x223.png 768w" sizes="auto, (max-width: 1462px) 100vw, 1462px" /></p>
<p>Views: 19</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-generer-une-clef-ssl-hote-idrac-dell/">MODOP &#8211; Générer des certificats SSL – Hôte Idrac DELL</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-generer-une-clef-ssl-hote-idrac-dell/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MODOP &#8211; Installation Site Apache Virtual Host + SSL</title>
		<link>https://coffeebreak.en-images.info/modop-installation-site-apache-virtual-host-ssl/</link>
					<comments>https://coffeebreak.en-images.info/modop-installation-site-apache-virtual-host-ssl/#respond</comments>
		
		<dc:creator><![CDATA[chris]]></dc:creator>
		<pubDate>Sat, 05 Jun 2021 13:49:16 +0000</pubDate>
				<category><![CDATA[Debian Linux]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Système]]></category>
		<guid isPermaLink="false">https://coffeebreak.en-images.info/?p=995</guid>

					<description><![CDATA[<p>Mise en place d'un virtualHost Apache et Certificat SSL sur une distribution Debian 9.</p>
<p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-site-apache-virtual-host-ssl/">MODOP &#8211; Installation Site Apache Virtual Host + SSL</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Installation d’une Debian 9.0 en mode Console simple</strong></p>
<p><img loading="lazy" decoding="async" width="931" height="311" class="wp-image-998" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-188.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-188.png 931w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-188-300x100.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-188-768x257.png 768w" sizes="auto, (max-width: 931px) 100vw, 931px" /><br />
<img loading="lazy" decoding="async" width="848" height="113" class="wp-image-999" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-189.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-189.png 848w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-189-300x40.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-189-768x102.png 768w" sizes="auto, (max-width: 848px) 100vw, 848px" /></p>
<p>Se connecter en ssh sur cette machine</p>
<p><strong>Installation Apache</strong></p>
<pre>root@deb01:/home/cp219538# <span style="color: #ff0000;"><strong>apt-get update &amp;&amp; apt-get upgrade</strong></span>
root@deb01:/home/cp219538# <strong><span style="color: #ff0000;">apt-get -y install apache2</span></strong></pre>
<p><strong>Test si Apache est fonctionnel =&gt; <a href="http://192.168.1.138/">http://192.168.1.138/</a></strong><br />
<img loading="lazy" decoding="async" width="1241" height="309" class="wp-image-1001" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-190.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-190.png 1241w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-190-300x75.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-190-1024x255.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-190-768x191.png 768w" sizes="auto, (max-width: 1241px) 100vw, 1241px" /></p>
<p>Pour le test Site + SSL nous allons ajouter notre Machine dans le Hosts de notre PC de DEV afin de simuler la résolution DNS.</p>
<p>Deb01.house.cpb =&gt; <a href="http://192.168.1.138/">http://192.168.1.138/</a></p>
<p><strong>Il faut se rendre sur =&gt; C:\Windows\System32\drivers\etc\hosts (en mode administrateur)</strong><br />
<img loading="lazy" decoding="async" width="259" height="78" class="wp-image-1004" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-191.png" /></p>
<p><strong>Test de la résolution</strong><br />
<a href="http://deb01.house.cpb">http://deb01.house.cpb</a></p>
<p><img loading="lazy" decoding="async" width="1357" height="304" class="wp-image-1006" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-192.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-192.png 1357w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-192-300x67.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-192-1024x229.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-192-768x172.png 768w" sizes="auto, (max-width: 1357px) 100vw, 1357px" /></p>
<p><strong>Fichier de conf Apache</strong></p>
<pre>root@deb01:/home/cp219538# <strong><span style="color: #ff0000;">cd /etc/apache2/</span></strong></pre>
<p><img loading="lazy" decoding="async" width="725" height="228" class="wp-image-1007" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-193.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-193.png 725w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-193-300x94.png 300w" sizes="auto, (max-width: 725px) 100vw, 725px" /></p>
<p><strong>Création du fichier de conf site deb01.house.cpb</strong></p>
<pre>root@deb01:/etc/apache2# <strong><span style="color: #ff0000;">cd sites-available/</span></strong></pre>
<pre>root@deb01:/etc/apache2/sites-available# <span style="color: #ff0000;"><strong>vi deb01.conf</strong></span>
<span style="color: #ff0000;"><em>&lt;Virtualhost *:80&gt;</em></span>
<span style="color: #ff0000;"><em> ServerName deb01.house.cpb</em></span>
<span style="color: #ff0000;"><em> DocumentRoot /var/www/deb01</em></span>
<span style="color: #ff0000;"><em>&lt;/Virtualhost&gt;</em></span></pre>
<p><strong>Création du répertoire des pages site</strong></p>
<pre>root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">mkdir -p /var/www/deb01</span></strong>
root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">echo "&lt;h2&gt; Site deb01.house.cpb &lt;/h2&gt;" &gt; /var/www/deb01/index.html</span></strong></pre>
<p><strong>Activer le site OneLine</strong></p>
<pre>root@deb01:/etc/apache2/sites-available# <span style="color: #ff0000;"><strong>a2ensite deb01.conf</strong></span>
<span style="color: #ff0000;"><em>Enabling site deb01.</em></span>
<span style="color: #ff0000;"><em>To activate the new configuration, you need to run:</em></span>
<span style="color: #ff0000;"><em> systemctl reload apache2</em></span></pre>
<pre>root@deb01:/etc/apache2/sites-available# <span style="color: #ff0000;"><strong>systemctl reload apache2</strong></span></pre>
<p><img loading="lazy" decoding="async" width="718" height="129" class="wp-image-1009" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-194.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-194.png 718w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-194-300x54.png 300w" sizes="auto, (max-width: 718px) 100vw, 718px" /></p>
<p><strong>Installation des certificats (Let&rsquo;s Encrypt SSL)</strong><br />
Il faut pour cela posséder un nom de domaine chez un register , dans mon cas en-images.info</p>
<p>Ajouter dans votre Zone DNS une entrée A ou CNAME deb01.en-images.info<br />
<img loading="lazy" decoding="async" width="1182" height="61" class="wp-image-1010" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-195.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-195.png 1182w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-195-300x15.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-195-1024x53.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-195-768x40.png 768w" sizes="auto, (max-width: 1182px) 100vw, 1182px" /></p>
<p>root@deb01:/home/cp219538# <span style="color: #ff0000;"><strong>dig en-images.info dig01.en-images.info A</strong></span><br />
<img loading="lazy" decoding="async" width="852" height="292" class="wp-image-1011" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-196.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-196.png 852w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-196-300x103.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-196-768x263.png 768w" sizes="auto, (max-width: 852px) 100vw, 852px" /></p>
<pre>root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">apt -y install certbot</span></strong>
root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">certbot -d deb01.en-images.info certonly --manual --preferred-challenge dns</span></strong></pre>
<p><img loading="lazy" decoding="async" width="913" height="361" class="wp-image-1013" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-197.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-197.png 913w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-197-300x119.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-197-768x304.png 768w" sizes="auto, (max-width: 913px) 100vw, 913px" /></p>
<p>Ajouter dans votre zone DNS une entrée TXT « _acme-challenge.deb01.en-images.info» avec la KEY « TKg7ZPjDBZGk-xaoZqKUFRt_hobUt3qouh1uJC9uUro»</p>
<p><img loading="lazy" decoding="async" width="478" height="339" class="wp-image-1016" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-198.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-198.png 478w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-198-300x213.png 300w" sizes="auto, (max-width: 478px) 100vw, 478px" /><br />
<img loading="lazy" decoding="async" width="1138" height="108" class="wp-image-1018" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-199.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-199.png 1138w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-199-300x28.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-199-1024x97.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-199-768x73.png 768w" sizes="auto, (max-width: 1138px) 100vw, 1138px" /></p>
<h3><span style="color: #ff0000;">Attendre la propagation de l’entrée TXT.</span></h3>
<p>Pour le test de la zone et connaître si l’entrée TXT est OK</p>
<pre>root@deb01:/home/cp219538# <span style="color: #ff0000;"><strong>dig en-images.info _acme-challenge.deb01.en-images.info TXT</strong></span></pre>
<p><span style="color: #ff0000;"><img loading="lazy" decoding="async" width="957" height="511" class="wp-image-1019" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-200.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-200.png 957w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-200-300x160.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-200-768x410.png 768w" sizes="auto, (max-width: 957px) 100vw, 957px" /></span></p>
<h4><span style="color: #ff0000;">Quand l’entrée est OK appuyer sur « Enter » lors du message « Press Enter to Continue » de la commande certobot.</span></h4>
<p><img loading="lazy" decoding="async" width="731" height="301" class="wp-image-1021" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-201.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-201.png 731w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-201-300x124.png 300w" sizes="auto, (max-width: 731px) 100vw, 731px" /></p>
<p>Les certificats sont désormais disponible sur «/etc/letsencrypt/live/deb01.en-images.info/ »<br />
<img loading="lazy" decoding="async" width="907" height="154" class="wp-image-1024" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-202.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-202.png 907w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-202-300x51.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-202-768x130.png 768w" sizes="auto, (max-width: 907px) 100vw, 907px" /></p>
<ul>
<li>Cert.pem =&gt; le certificat</li>
<li>Privkey.pem =&gt; la key privée</li>
</ul>
<p><strong>Création du site conf 002-deb01-ssl.conf</strong></p>
<pre>root@deb01:/home# <span style="color: #ff0000;"><strong>vi /etc/apache2/site-available/002-deb01.conf</strong></span>
<span style="color: #ff0000;"><em>&lt;Virtualhost *:443&gt;</em></span>
<span style="color: #ff0000;"><em> ServerName deb01.en-images.info</em></span>
<span style="color: #ff0000;"><em> DocumentRoot /var/root/deb01ssl</em></span>
<span style="color: #ff0000;"><em> SSLEngine on</em></span>
<span style="color: #ff0000;"><em> SSLCertificateFile /etc/apache2/certs/deb01.crt</em></span>
<span style="color: #ff0000;"><em> SSLCertificateKeyFile /etc/apache2/certs/deb01.key</em></span>
<span style="color: #ff0000;"><em>&lt;/Virtualhost&gt;</em></span></pre>
<p><strong>Configuration du site SSL</strong></p>
<pre>root@deb01:/home# <span style="color: #ff0000;"><strong>mkdir /etc/apache2/certs/</strong></span>
root@deb01:/home#<strong><span style="color: #ff0000;"> cp /etc/letsencrypt/live/deb01.en-images.info/cert.pem /etc/apache2/certs/deb01.crt</span></strong>
root@deb01:/home#<span style="color: #ff0000;"><strong> cp /etc/letsencrypt/live/deb01.en-images.info/privkey.pem /etc/apache2/certs/deb01.key</strong></span>

root@deb01:/home# <strong><span style="color: #ff0000;">a2enmod ssl</span></strong></pre>
<p><img loading="lazy" decoding="async" width="884" height="167" class="wp-image-1026" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-203.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-203.png 884w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-203-300x57.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-203-768x145.png 768w" sizes="auto, (max-width: 884px) 100vw, 884px" /></p>
<pre>root@deb01:/home# <strong><span style="color: #ff0000;">a2enmod rewrite</span></strong></pre>
<p><img loading="lazy" decoding="async" width="474" height="82" class="wp-image-1027" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-204.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-204.png 474w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-204-300x52.png 300w" sizes="auto, (max-width: 474px) 100vw, 474px" /></p>
<pre>root@deb01:/etc/apache2/sites-available# <span style="color: #ff0000;"><strong>a2ensite 002-deb01.conf</strong></span></pre>
<p><img loading="lazy" decoding="async" width="549" height="75" class="wp-image-1029" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-205.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-205.png 549w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-205-300x41.png 300w" sizes="auto, (max-width: 549px) 100vw, 549px" /></p>
<pre>root@deb01:/etc/apache2/sites-available# <span style="color: #ff0000;"><strong>mkdir -p /var/www/deb01ssl</strong></span>
root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">echo "&lt;h2&gt; Site SSL - deb01.house.cpb &lt;/h2&gt;" &gt; /var/www/deb01ssl/index.html</span></strong>

root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">systemctl reload apache2</span></strong></pre>
<p><strong>Règles Firewall</strong></p>
<pre>root@deb01:/etc/apache2/sites-available# <strong><span style="color: #ff0000;">iptables -A INPUT -p tcp --dport 443 -j ACCEPT</span></strong></pre>
<p>Si vous êtes derrière une box Internet, il faut faire une règle NAT pour transférer les requêtes http 443 vers votre machine deb01.</p>
<p><img loading="lazy" decoding="async" width="722" height="86" class="wp-image-1032" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-206.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-206.png 722w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-206-300x36.png 300w" sizes="auto, (max-width: 722px) 100vw, 722px" /><br />
Sur une box Orange</p>
<p><a href="https://deb01.en-images.info">https://deb01.en-images.info</a></p>
<p><img loading="lazy" decoding="async" width="723" height="117" class="wp-image-1034" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-207.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-207.png 723w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-207-300x49.png 300w" sizes="auto, (max-width: 723px) 100vw, 723px" /><br />
<img loading="lazy" decoding="async" width="1071" height="599" class="wp-image-1035" src="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-208.png" srcset="https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-208.png 1071w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-208-300x168.png 300w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-208-1024x573.png 1024w, https://coffeebreak.en-images.info/wp-content/uploads/2021/06/word-image-208-768x430.png 768w" sizes="auto, (max-width: 1071px) 100vw, 1071px" /></p>
<p>Views: 14</p><p>L’article <a href="https://coffeebreak.en-images.info/modop-installation-site-apache-virtual-host-ssl/">MODOP &#8211; Installation Site Apache Virtual Host + SSL</a> est apparu en premier sur <a href="https://coffeebreak.en-images.info">CoffeeBreak Info</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://coffeebreak.en-images.info/modop-installation-site-apache-virtual-host-ssl/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
