{"id":18021,"date":"2019-02-17T09:41:32","date_gmt":"2019-02-17T00:41:32","guid":{"rendered":"https:\/\/www.e-nekorakuen.net\/?p=18021"},"modified":"2019-02-22T09:42:36","modified_gmt":"2019-02-22T00:42:36","slug":"lets-encrypt%e3%81%a7%e3%83%a1%e3%83%bc%e3%83%ab%e3%82%b5%e3%83%bc%e3%83%90%e3%83%bc%e3%82%82ssl%e5%8c%96%e3%81%99%e3%82%8b%e3%80%82","status":"publish","type":"post","link":"https:\/\/www.e-nekorakuen.net\/?p=18021","title":{"rendered":"Let&#8217;s Encrypt\u3067\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u3082SSL\u5316\u3059\u308b\u3002"},"content":{"rendered":"<p>Let&#8217;s Encrypt\u3067\u306f\u65e2\u5b58\u306eWEB\u30b5\u30fc\u30d0\u30fc\u7528\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\uff08www.xxxxx.com\uff09\u306e\u8a3c\u660e\u66f8\u306b\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u7528\u306e\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\uff08mail.xxxxx.com)\u306e\u8a3c\u660e\u66f8\u3092\u8ffd\u52a0\uff08SAN : Subject Alternative Name\uff09\u3057\u3066\u3001\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u3092SSL\u5316\u3059\u308b\u3053\u3068\u304c\u3067\u304d\u307e\u3059\u3002\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u7528\u306e\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u306f\u53d6\u5f97\u6e08\u307f\u3067\u3042\u308b\u3053\u3068\u3092\u524d\u63d0\u306b\u3001\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u306eSSL\u5316\u306b\u3064\u3044\u3066\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u53c2\u8003\u30b5\u30a4\u30c8\uff1a<a href=\"https:\/\/free-ssl.jp\" target=\"_blank\" rel=\"noopener noreferrer\">Let&#8217;s Encrypt \u7dcf\u5408\u30dd\u30fc\u30bf\u30eb (\u975e\u516c\u5f0f\u89e3\u8aac\u30b5\u30a4\u30c8)<\/a><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-18023\" src=\"https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/le-logo-standard-1.png\" alt=\"\" width=\"192\" height=\"159\" \/>\u3000<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18026\" src=\"https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/apache.png\" alt=\"\" width=\"160\" height=\"160\" srcset=\"https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/apache.png 192w, https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/apache-150x150.png 150w, https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/apache-160x160.png 160w\" sizes=\"auto, (max-width: 160px) 100vw, 160px\" \/><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18024\" src=\"https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/postfix-post-thumbnail.png\" alt=\"\" width=\"201\" height=\"128\" \/>\u3000<img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-18025\" src=\"https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/CkMPpkRr_400x400.png\" alt=\"\" width=\"142\" height=\"142\" srcset=\"https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/CkMPpkRr_400x400.png 200w, https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/CkMPpkRr_400x400-150x150.png 150w, https:\/\/www.e-nekorakuen.net\/wp-content\/uploads\/2019\/02\/CkMPpkRr_400x400-160x160.png 160w\" sizes=\"auto, (max-width: 142px) 100vw, 142px\" \/><\/p>\n<p>1.Apache\u306evhost\u306b\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u306e\u30a8\u30a4\u30ea\u30a2\u30b9\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002(https\u306e\u8a3c\u660e\u66f8\u3068\u5171\u7528\u3059\u308b\u305f\u3081\uff09<br \/>\n\/etc\/apache2\/sites-available\/www.sample.com.conf<br \/>\n<span style=\"color: #0000ff;\">&lt;VirtualHost *:80&gt;<\/span><br \/>\n<span style=\"color: #0000ff;\"># HTTP connection to redirect to HTTPS<\/span><br \/>\n<span style=\"color: #0000ff;\">RewriteEngine On<\/span><br \/>\n<span style=\"color: #0000ff;\">RewriteCond %{HTTPS} off<\/span><br \/>\n<span style=\"color: #0000ff;\">RewriteRule ^(.*)$ https:\/\/%{HTTP_HOST}%{REQUEST_URI} [R=301,L]<\/span><\/p>\n<p># The ServerName directive sets the request scheme, hostname and port that<br \/>\n# the server uses to identify itself. This is used when creating<br \/>\n# redirection URLs. In the context of virtual hosts, the ServerName<br \/>\n# specifies what hostname must appear in the request&#8217;s Host: header to<br \/>\n# match this virtual host. For the default virtual host (this file) this<br \/>\n# value is not decisive as it is used as a last resort host regardless.<br \/>\n# However, you must set it for any further virtual host explicitly.<br \/>\n#ServerName www.sample.com<\/p>\n<p>ServerAdmin webmaster@localhost<br \/>\nServerName sample.com<br \/>\nServerAlias www.sample.com<br \/>\n<span style=\"color: #ff0000;\"># mail Alias added \u2193\u3053\u3053\u306b\u8ffd\u52a0<\/span><br \/>\n<span style=\"color: #ff0000;\">ServerAlias mail.sample.com<\/span><br \/>\nDocumentRoot \/home\/www\/sample<\/p>\n<p>2.Apache\u3092\u505c\u6b62\u3057\u307e\u3059\u3002<br \/>\nservice apache2 stop<br \/>\n3.\u65e2\u5b58\u306e\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u66f8\u306b\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u7528\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002<br \/>\n\u4ee5\u4e0b\u306e\u30b3\u30de\u30f3\u30c9\u3067\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u7528\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u306e\u30b5\u30fc\u30d0\u30fc\u8a3c\u660e\u66f8\u3092\u8ffd\u52a0\u3057\u307e\u3059\u3002\uff08\u5148\u982d\u306b\u65e2\u5b58\u306e\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u3001\u305d\u306e\u6b21\u306b\u4eca\u56de\u8ffd\u52a0\u3059\u308b\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\uff09<br \/>\n<span style=\"color: #ff0000;\">certbot &#8211;authenticator standalone &#8211;installer apache &#8211;expand -d www.sample.com -d mail.sample.com<\/span><br \/>\nThe requested apache plugin does not appear to be installed<br \/>\n\u2192python3\u306ePlug-in\u304c\u8db3\u308a\u306a\u3044\u3068\u8a00\u308f\u308c\u305f\u3089\u3001<br \/>\n<span style=\"color: #ff0000;\">apt install python3-certbot-apache<\/span><br \/>\n\u518d\u5ea6\u5b9f\u884c<br \/>\nWhat would you like to do?<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n1: Attempt to reinstall this existing certificate<br \/>\n2: Renew &amp; replace the cert (limit ~5 per 7 days)<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nSelect the appropriate number [1-2] then [enter] (press &#8216;c&#8217; to cancel): <span style=\"color: #ff0000;\">1<\/span><br \/>\nKeeping the existing certificate<br \/>\nCreated an SSL vhost at \/etc\/apache2\/sites-available\/sample.com-le-ssl.conf<br \/>\nDeploying Certificate to VirtualHost \/etc\/apache2\/sites-available\/sample.com-le-ssl.conf<br \/>\nEnabling available site: \/etc\/apache2\/sites-available\/sample.com-le-ssl.conf<br \/>\nDeploying Certificate to VirtualHost \/etc\/apache2\/sites-available\/sample.com-le-ssl.conf<\/p>\n<p>Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n1: No redirect &#8211; Make no further changes to the webserver configuration.<br \/>\n2: Redirect &#8211; Make all requests redirect to secure HTTPS access. Choose this for<br \/>\nnew sites, or if you&#8217;re confident your site works on HTTPS. You can undo this<br \/>\nchange by editing your web server&#8217;s configuration.<br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\nSelect the appropriate number [1-2] then [enter] (press &#8216;c&#8217; to cancel): <span style=\"color: #ff0000;\">1 \u2190vhost\u5185\u3067\u30ea\u30c0\u30a4\u30ec\u30af\u30c8\u3057\u3066\u3044\u308b\u306e\u30671\u3092\u9078\u629e\u3057\u307e\u3059\u3002<\/span><\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br \/>\n<span style=\"color: #ff0000;\">Congratulations! You have successfully enabled https:\/\/www.sample.com and<\/span><br \/>\n<span style=\"color: #ff0000;\">https:\/\/mail.sample.com \u2190\u6210\u529f\uff01\u306e\u30e1\u30c3\u30bb\u30fc\u30b8<\/span><\/p>\n<p>You should test your configuration at:<br \/>\nhttps:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=www.sample.com<br \/>\n<span style=\"color: #ff0000;\">https:\/\/www.ssllabs.com\/ssltest\/analyze.html?d=mail.sample.com<\/span> <span style=\"color: #ff0000;\">\u2190\u8ffd\u52a0\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/span><br \/>\n&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p>IMPORTANT NOTES:<br \/>\n&#8211; Congratulations! Your certificate and chain have been saved at:<br \/>\n\/etc\/letsencrypt\/live\/www.sample.com\/fullchain.pem<br \/>\nYour key file has been saved at:<br \/>\n\/etc\/letsencrypt\/live\/www.sample.com\/privkey.pem<br \/>\nYour cert will expire on 9999-99-99. To obtain a new or tweaked<br \/>\nversion of this certificate in the future, simply run certbot again<br \/>\nwith the &#8220;certonly&#8221; option. To non-interactively renew *all* of<br \/>\nyour certificates, run &#8220;certbot renew&#8221;<br \/>\n&#8211; Some rewrite rules copied from<br \/>\n\/etc\/apache2\/sites-enabled\/sample.com.conf were disabled in<br \/>\nthe vhost for your HTTPS site located at<br \/>\n\/etc\/apache2\/sites-available\/sample.com-le-ssl.conf because<br \/>\nthey have the potential to create redirection loops.<br \/>\n&#8211; If you like Certbot, please consider supporting our work by:<\/p>\n<p>Donating to ISRG \/ Let&#8217;s Encrypt: https:\/\/letsencrypt.org\/donate<br \/>\nDonating to EFF: https:\/\/eff.org\/donate-le<\/p>\n<p>5.Apache\u3092\u8d77\u52d5\u3057\u307e\u3059\u3002<br \/>\nservice apache2 start<\/p>\n<p>6.iptables\u306b\u30e1\u30fc\u30eb\u7528\u30dd\u30fc\u30c8\u306e\u8a2d\u5b9a\u3092\u3057\u307e\u3059\u3002\uff08\u8a2d\u5b9a\u7528\u30b7\u30a7\u30eb\u304c\u3042\u308b\u5834\u5408\u306f\u3001\u518d\u5b9f\u884c\u3059\u308b\u3002\uff09<br \/>\n# WEB OK(HTTPS)<br \/>\n$IPTABLES -A INPUT -p tcp &#8211;dport 80 -j ACCEPT<br \/>\n<span style=\"color: #0000ff;\">$IPTABLES -A INPUT -p tcp &#8211;dport 443 -j ACCEPT<\/span><\/p>\n<p># SMTP OK(SMTPS)<br \/>\n$IPTABLES -A INPUT -p tcp &#8211;dport 25 -j ACCEPT<br \/>\n<span style=\"color: #ff0000;\">$IPTABLES -A INPUT -p tcp &#8211;dport 465 -j ACCEPT<br \/>\n$IPTABLES -A INPUT -p tcp &#8211;dport 587 -j ACCEPT<\/span><\/p>\n<p><span style=\"color: #333333;\"># SSH Port xxxx OK(FTP NG) xxxx\u306f\u4efb\u610f<\/span><\/p>\n<p>$IPTABLES -A INPUT -p tcp &#8211;dport xxxx -j ACCEP<\/p>\n<p># POP OK (POP3S)<br \/>\n<span style=\"color: #ff0000;\">$IPTABLES -A INPUT -p tcp &#8211;dport 995 -j ACCEPT<\/span><\/p>\n<p>\u203b iptables-persistent\u304c\u8d77\u52d5\u6642\u306b\u8aad\u307f\u8fbc\u3081\u308b\u3088\u3046\u3001rules.ipv4\u3082\u4fee\u6b63\u3057\u307e\u3059\u3002<br \/>\n\u53c2\u8003\u30b5\u30a4\u30c8\uff1a<a href=\"http:\/\/iwashi.co\/2015\/01\/16\/ubuntu-iptables-persistent\" target=\"_blank\" rel=\"noopener noreferrer\">Ubuntu\u3067iptables\u306e\u8a2d\u5b9a\u3092iptables-persistent\u3067\u6c38\u7d9a\u5316\u3059\u308b<\/a><br \/>\n\/etc\/iptables\/rules.ipv4<br \/>\n-A INPUT -p icmp -j ACCEPT<br \/>\n-A INPUT -p tcp -m tcp &#8211;dport 80 -j ACCEPT<br \/>\n-A INPUT -p tcp -m tcp &#8211;dport 443 -j ACCEPT<br \/>\n-A INPUT -p tcp -m tcp &#8211;dport 25 -j ACCEPT<br \/>\n<span style=\"color: #ff0000;\">-A INPUT -p tcp -m tcp &#8211;dport 465 -j ACCEPT<\/span><br \/>\n<span style=\"color: #ff0000;\">-A INPUT -p tcp -m tcp &#8211;dport 587 -j ACCEPT<br \/>\n<\/span>-A INPUT -p tcp -m tcp &#8211;dport xxxx -j ACCEPT<br \/>\n<span style=\"color: #ff0000;\">-A INPUT -p tcp -m tcp &#8211;dport 995 -j ACCEPT<\/span><\/p>\n<p>7.Postfix &amp; Dovecot\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3092\u4fee\u6b63\u3057\u307e\u3059\u3002<br \/>\n\u53c2\u8003\u30b5\u30a4\u30c8\uff1a<a href=\"https:\/\/www.server-world.info\/query?os=Ubuntu_18.04&amp;p=mail&amp;f=6\" target=\"_blank\" rel=\"noopener noreferrer\">Server World\uff08SSL\/TLS \u306e\u8a2d\u5b9a\uff09<\/a><br \/>\n\u203b https\u306e\u8a3c\u660e\u66f8\u3068\u5171\u7528\u3059\u308b\u305f\u3081\u306e\u8a3c\u660e\u66f8\u306e\u6307\u5b9a\u306f\u3001\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<br \/>\n\u203b \u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u306e\u30b5\u30d6\u30c9\u30e1\u30a4\u30f3\u3067\u306f\u306a\u304f\u3001<span style=\"color: #ff0000;\">WEB\u30b5\u30fc\u30d0\u30fc\u7528\u306e\u8a3c\u660e\u66f8<\/span>\u3092\u6307\u5b9a\u3057\u307e\u3059\u3002<br \/>\n\/etc\/postfix\/main.cf<br \/>\n<span style=\"color: #0000ff;\"># SMTP-Auth \u8a2d\u5b9a<\/span><br \/>\n<span style=\"color: #0000ff;\">smtpd_sasl_type = dovecot<\/span><br \/>\n<span style=\"color: #0000ff;\">smtpd_sasl_path = private\/auth<\/span><br \/>\n<span style=\"color: #0000ff;\">smtpd_sasl_auth_enable = yes<\/span><br \/>\n<span style=\"color: #0000ff;\">smtpd_sasl_local_domain = $myhostname<\/span><br \/>\n<span style=\"color: #0000ff;\">smtpd_sasl_security_options = noanonymous<\/span><br \/>\n<span style=\"color: #0000ff;\">smtpd_recipient_restrictions = permit_mynetworks, permit_auth_destination, permit_sasl_authenticated, reject<\/span><\/p>\n<p><span style=\"color: #ff0000;\"># smtps \u8a2d\u5b9a<\/span><br \/>\nsmtpd_use_tls = yes<br \/>\nsmtp_tls_mandatory_protocols = !SSLv2, !SSLv3<br \/>\nsmtpd_tls_mandatory_protocols = !SSLv2, !SSLv3<br \/>\n<span style=\"color: #ff0000;\">smtpd_tls_cert_file = \/etc\/letsencrypt\/live\/www.sample.com\/fullchain.pem<\/span><br \/>\n<span style=\"color: #ff0000;\">smtpd_tls_key_file = \/etc\/letsencrypt\/live\/www.sample.com\/privkey.pem<\/span><br \/>\nsmtpd_tls_session_cache_database = btree:${data_directory}\/smtpd_scache<\/p>\n<p>dovecot<br \/>\n\/etc\/dovecot\/conf.d\/10-ssl.conf<br \/>\n<span style=\"color: #ff0000;\">ssl = yes<\/span><br \/>\n<span style=\"color: #ff0000;\">ssl_cert = &lt;\/etc\/letsencrypt\/live\/www.sample.com\/fullchain.pem<\/span><br \/>\n<span style=\"color: #ff0000;\">ssl_key = &lt;\/etc\/letsencrypt\/live\/www.sample.com\/privkey.pem<\/span><\/p>\n<p>8.Postfix &amp; Dovecot\u3092\u518d\u8d77\u52d5\u3057\u307e\u3059\u3002<br \/>\nservice postfix dovecot restart<\/p>\n<p>9.PC\u306e\u30e1\u30fc\u30eb\u30af\u30e9\u30a4\u30a2\u30f3\u30c8\u3092\u5909\u66f4\u3057\u307e\u3059\u3002<br \/>\n\u53d7\u4fe1\u30dd\u30fc\u30c8:995 \u9001\u4fe1\u30dd\u30fc\u30c8:587\uff0bSSL\u30dd\u30fc\u30c8:465 \uff08\u8a73\u7d30\u306f\u3001<a href=\"https:\/\/www.server-world.info\/query?os=Ubuntu_18.04&amp;p=mail&amp;f=6\" target=\"_blank\" rel=\"noopener noreferrer\">7\u306eURL\u3092\u53c2\u7167<\/a>\uff09<\/p>\n<p>10.\u5916\u90e8\uff08WAN\uff09\u304b\u3089\u30e1\u30fc\u30eb\u306e\u9001\u53d7\u4fe1\u304c\u3067\u304d\u308b\u3088\u3046\u3001\u30eb\u30fc\u30bf\u30fc\u306e\u30dd\u30fc\u30c8\u3092\u958b\u653e\uff08NAT or NAPT\uff09\u3059\u308b\u3053\u3068\u3092\u304a\u5fd8\u308c\u306a\u304f<\/p>\n<p><span style=\"color: #ff0000;\">995(WAN) \u2190\u2192 995(LAN)<br \/>\n<\/span><span style=\"color: #ff0000;\">465(WAN) \u2190\u2192 465(LAN)<br \/>\n<\/span><span style=\"color: #ff0000;\">587(WAN) \u2190\u2192 587(LAN)<\/span><\/p>\n<p><span style=\"display: inline !important; float: none; background-color: #fafafa; color: #333333; cursor: text; font-family: 'Ubuntu',Arial,sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;\">11.\u30e1\u30fc\u30eb\u306e\u9001\u53d7\u4fe1\uff08LAN\u3001WAN\uff09<\/span><span style=\"display: inline !important; float: none; background-color: #fafafa; color: #333333; cursor: text; font-family: 'Ubuntu',Arial,sans-serif; font-size: 16px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px;\">\u304c\u4e0a\u624b\u304f\u884c\u3051\u3070OK<\/span><\/p>\n<p><strong>12.\u8ffd\u8a18\uff08Postfix\u306e\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u3001master.cf\u306b\u3064\u3044\u3066\uff09<\/strong><br \/>\nmaister.cf\u306e\u8a2d\u5b9a\u3067\u3001\u30b3\u30e1\u30f3\u30c8\u3092\u5916\u3059\u969b\u306b<span style=\"color: #0000ff;\">\u4e0a\u90e8\u306esmtp\u3092\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8\u3057\u306a\u3044\u3053\u3068\u3002<\/span>\u7406\u7531\u306f\u3001\u30b5\u30fc\u30d0\u30fc\u9593\u306e\u30e1\u30fc\u30eb\u8ee2\u9001\u306f\u5f93\u6765\u901a\u308aPort 25\u3092\u5229\u7528\u3059\u308b\u305f\u3081\u3002<br \/>\n\u203b\u8a73\u7d30\u8a2d\u5b9a\u3092\u8a18\u8ff0\u3057\u307e\u3059\u3002<br \/>\n\/etc\/postfix\/master.cf<br \/>\n<span style=\"color: #0000ff;\">smtp inet n &#8211; y &#8211; &#8211; smtpd\u3000\u2190\u30b3\u30e1\u30f3\u30c8\u30a2\u30a6\u30c8\u3057\u306a\u3044\u3053\u3068\u3002<br \/>\n<\/span>#smtp inet n &#8211; y &#8211; 1 postscreen<br \/>\n#smtpd pass &#8211; &#8211; y &#8211; &#8211; smtpd<br \/>\n#dnsblog unix &#8211; &#8211; y &#8211; 0 dnsblog<br \/>\n#tlsproxy unix &#8211; &#8211; y &#8211; 0 tlsproxy<br \/>\n# smtps updated 2019\/02\/16<br \/>\n<span style=\"color: #ff0000;\">submission inet n &#8211; y &#8211; &#8211; smtpd\u3000\u2190\u4ee5\u4e0b\u3001\u30b3\u30e1\u30f3\u30c8\u3092\u5916\u3057\u307e\u3059\u3002\uff08SSL,STARTTLS\u3069\u3061\u3089\u306b\u3082\u5bfe\u5fdc\uff09<\/span><br \/>\n# -o syslog_name=postfix\/submission<br \/>\n<span style=\"color: #ff0000;\">-o smtpd_tls_security_level=encrypt<\/span><br \/>\n<span style=\"color: #ff0000;\">-o smtpd_sasl_auth_enable=yes<\/span><br \/>\n# -o smtpd_tls_auth_only=yes<br \/>\n# -o smtpd_reject_unlisted_recipient=no<br \/>\n<span style=\"color: #ff0000;\">-o smtpd_client_restrictions=$mua_client_restrictions<\/span><br \/>\n# -o smtpd_helo_restrictions=$mua_helo_restrictions<br \/>\n# -o smtpd_sender_restrictions=$mua_sender_restrictions<br \/>\n# -o smtpd_recipient_restrictions=<br \/>\n<span style=\"color: #ff0000;\">-o smtpd_relay_restrictions=permit_sasl_authenticated,reject<\/span><br \/>\n# -o milter_macro_daemon_name=ORIGINATING<br \/>\n<span style=\"color: #ff0000;\">smtps inet n &#8211; y &#8211; &#8211; smtpd<\/span><br \/>\n# -o syslog_name=postfix\/smtps<br \/>\n<span style=\"color: #ff0000;\">-o smtpd_tls_wrappermode=yes<\/span><br \/>\n<span style=\"color: #ff0000;\">-o smtpd_sasl_auth_enable=yes<\/span><br \/>\n# -o smtpd_reject_unlisted_recipient=no<br \/>\n# -o smtpd_client_restrictions=$mua_client_restrictions<br \/>\n<span style=\"color: #ff0000;\">-o smtpd_helo_restrictions=$mua_helo_restrictions<\/span><br \/>\n# -o smtpd_sender_restrictions=$mua_sender_restrictions<br \/>\n# -o smtpd_recipient_restrictions=<br \/>\n<span style=\"color: #ff0000;\">-o smtpd_relay_restrictions=permit_sasl_authenticated,reject<\/span><br \/>\n# -o milter_macro_daemon_name=ORIGINATING<br \/>\n#628 inet n &#8211; y &#8211; &#8211; qmqpd<\/p>\n<p><span style=\"color: #0000ff;\"><strong>\u25ce\u30e1\u30fc\u30eb\u30b5\u30fc\u30d0\u30fc\u306eSSL\u5316\u306f\u8a2d\u5b9a\u30f6\u6240\u304c\u591a\u304f\u3068\u306b\u304b\u304f\u624b\u304c\u639b\u304b\u308a\u307e\u3059\u3002\u4f55\u5ea6\u3082\u8e93\u304f\u3068\u601d\u3044\u307e\u3059\u304c\u3001mail.log\u3092\u983c\u308a\u306b\u6700\u5f8c\u307e\u3067\u9811\u5f35\u308b\u3053\u3068\u304c\u5927\u5207\u3067\u3059\u3002<\/strong><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Let&#8217;s Encrypt\u3067\u306f\u65e2\u5b58\u306eWEB\u30b5\u30fc\u30d0\u30fc\u7528\u30b5\u30d6&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":18023,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"sns_share_botton_hide":"","vkExUnit_sns_title":"","_vk_print_noindex":"","_veu_custom_css":"","veu_display_promotion_alert":"","footnotes":""},"categories":[31],"tags":[],"class_list":["post-18021","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux"],"veu_head_title_object":{"title":"","add_site_title":""},"_links":{"self":[{"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=\/wp\/v2\/posts\/18021","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=18021"}],"version-history":[{"count":0,"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=\/wp\/v2\/posts\/18021\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=\/wp\/v2\/media\/18023"}],"wp:attachment":[{"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=18021"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=18021"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.e-nekorakuen.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=18021"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}