๐Ÿ‘จ‍๐Ÿ’ป Dev/Web

[OMV NAS] Nextcloud ์ธ์ฆ์„œ ์ ์šฉํ•˜๊ธฐ

Scian 2022. 12. 26. 01:21
๋ฐ˜์‘ํ˜•

letsencrypt์™€ ๊ฐ™์€ ์„œ๋น„์Šค๋ฅผ ์ด์šฉํ•˜์—ฌ ๋ฌด๋ฃŒ ์ธ์ฆ์„œ๋ฅผ ๋งŒ๋“œ๋Š” ๊ฒƒ ์ž์ฒด๋Š” ๋‹ค์–‘ํ•œ ๋งค๋‰ด์–ผ์ด ์กด์žฌํ•˜๋ฏ€๋กœ ์Šคํ‚ต.

(๋ณธ ํฌ์ŠคํŒ…์—์„œ๋Š” macOS Ventura๋ฅผ ๊ธฐ์ค€์œผ๋กœ ํ•˜์—ฌ ์ž‘์„ฑํ•˜์˜€์Šต๋‹ˆ๋‹ค.)

๊ฐ„๋‹จํ•˜๊ฒŒ ์„ค๋ช…ํ•˜๋ฉด, ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ์น˜๊ณ , ์‹œํ‚ค๋Š” ๋Œ€๋กœ ์‚ฌ์ดํŠธ ์ฃผ์†Œ์™€ ์ด๋ฉ”์ผ ๋“ฑ์„ ์ž…๋ ฅํ•˜๊ณ , DNS ์ œ๊ณต์ž์—์„œ ์ฑŒ๋ฆฐ์ง€ TXT๋ฅผ ์—…๋ฐ์ดํŠธํ•ด ์ฃผ๋ฉด ๋œ๋‹ค. (DNS ์ ‘๊ทผ ๊ถŒํ•œ์ด ํ•„์š”ํ•˜๋‹ค.)

sudo certbot certonly --manual -v --preferred-challenges dns

macOS ๊ธฐ์ค€, manual๋กœ letsencrypt๋กœ ์ธ์ฆ์„œ๋ฅผ ๋งŒ๋“ค๋ฉด /private/etc/letsencrypt/archive/[์‚ฌ์ดํŠธ์ฃผ์†Œ] ์— ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋„ค ๊ฐœ์˜ ํŒŒ์ผ์ด ์ƒ์„ฑ๋œ๋‹ค.

์—ฌ๊ธฐ์„œ cert1.pem ํŒŒ์ผ๊ณผ privkey1.pem ํŒŒ์ผ์„ ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ๋‚˜ ๋ฉ”๋ชจ์žฅ ๋“ฑ ํŽธ์ง‘ ๊ฐ€๋Šฅํ•œ ํ”„๋กœ๊ทธ๋žจ์œผ๋กœ ์—ด๋ฉด, CERTIFICATE ์ •๋ณด์™€ KEY ์ •๋ณด๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. (์•„๋ž˜๋Š” ์ƒ๋žต๋œ ํ˜•ํƒœ๋กœ, ์‹ค์ œ๋กœ๋Š” ์•ฝ 30์ค„์— ๋‹ฌํ•˜๋Š” ๋‚ด์šฉ์ด ์ ํ˜€์žˆ์„ ๊ฒƒ์ด๋‹ค.) ์ด ๋‘๊ฐ€์ง€๋ฅผ ๊ฐ๊ฐ ๋ณต์‚ฌํ•˜๊ฑฐ๋‚˜, ๋ฉ”๋ชจ์žฅ์— ์ €์žฅํ•ด ๋‘”๋‹ค.

-----BEGIN CERTIFICATE-----
MIIFIz************
.....
***********AKY=
-----END CERTIFICATE-----

(cert1.pem)
-----BEGIN PRIVATE KEY-----
MIIEv**************
.....
**********epMpFsA==
-----END PRIVATE KEY-----

(privkey1.pem)

๊ทธ ํ›„, Portainer์˜ container์—์„œ nextcloud ์ปจํ…Œ์ด๋„ˆ๋ฅผ ์„ ํƒํ•˜๊ณ , console์— ์ ‘์†ํ•œ๋‹ค.

console์—์„œ ์•„๋ž˜ ๋‘ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•œ๋‹ค.

touch cert1.crt
touch cert1.key

๊ทธ ํ›„, nano ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ cert1.crt์— cert1.pem์˜ ๋‚ด์šฉ์„, cert1.key์— privkey1.pem์˜ ๋‚ด์šฉ์„ ๋ถ™์—ฌ๋„ฃ๋Š”๋‹ค.

nano ์—๋””ํ„ฐ์—์„œ ctrl + o, ENTER (Return), ctrl + x๋ฅผ ์ฐจ๋ก€๋กœ ๋ˆŒ๋Ÿฌ ์ €์žฅ ํ›„ ๋น ์ ธ๋‚˜์˜ฌ ์ˆ˜ ์žˆ๋‹ค.

์ดํ›„, ์•„๋ž˜ ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•œ๋‹ค.

cd ..
cd nginx
nano ssl.conf

์—ฌ๊ธฐ์„œ ssl_certificate ๊ฐ’๊ณผ ssl_certificate_key ๊ฐ’์„ ๊ฐ๊ฐ ์•„๊นŒ ๋งŒ๋“ค์–ด ์ค€ cert1.crt์™€ cert1.key๋กœ ๋ฐ”๊พธ์–ด ์ค€๋‹ค.

๊ทธ๋Ÿฐ ๋‹ค์Œ, Portainer์˜ ์ปจํ…Œ์ด๋„ˆ ํ™”๋ฉด์œผ๋กœ ๋Œ์•„๊ฐ€ nextcloud๋ฅผ ์žฌ์‹คํ–‰ํ•ด ์ฃผ๋ฉด SSL ์ ์šฉ์ด ์™„๋ฃŒ๋œ๋‹ค.

์งˆ๋ฌธ์ด ์žˆ๋‹ค๋ฉด ๋Œ“๊ธ€๋กœ ๋‚จ๊ฒจ์ฃผ์„ธ์š”.

๋ฐ˜์‘ํ˜•