# Nginx+Let's Encrypt(Certbot) on Docker

**URL:** https://forum.ficusonline.com/t/topic/375
**Category:** Server
**Created:** [2020 年 6 月 27 日午前 9:20 UTC](https://forum.ficusonline.com/t/topic/375 "2020-06-27T09:20:07Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2020 年 6 月 27 日午前 9:20 UTC](https://forum.ficusonline.com/t/topic/375/1 "2020-06-27T09:20:07Z")

</div>

**Alpine版NginxコンテナのSSL対応**

Let’s EncryptによるSSL認証用ファイルを **Certbot** (Automatic Certificate Management Environment : ACME Client)により獲得し、NginxによるウェブサーバをSSL対応させます。

> **[ACME Client Implementations](https://letsencrypt.org/docs/client-options/)**
>
> Last updated: Sep 5, 2025 | See all Documentation Let’s Encrypt uses the ACME protocol to verify that you control a given domain name and to issue you a certificate. To get a Let’s Encrypt certificate, you’ll need to choose a piece of ACME client...

> **[Certbot](https://certbot.eff.org/)**
>
> Get your site on https://

NginxのDockerイメージ作成時にDockerfileにより **Certbot** のインストールを指定します。

**Alpine版Certbot(Nginx)**

> **[certbot-nginx - Alpine Linux packages](https://pkgs.alpinelinux.org/package/edge/community/x86/certbot-nginx)**

```auto
RUN apk add --no-cache bash nano awstats apache2-utils certbot-nginx

```

または、Nginxコンテナ稼働後、インストールして下さい。

```auto
# apk add certbot-nginx

```

Nginx設定ファイルの異なる **server\_name** を持つ **serverセクション毎** に、SSL認証ファイルを獲得するため、Nginxコンテナ内で以下コマンドを実行します。

```auto
# certbot --nginx -d www.testsite1.com -d www.testsite2.com

```

各サーバセクションにSSLアクセス(443)時に必要な認証ファイルディレクトリなどが追加されます。

```auto
server {
    listen 80;
    server_name www.testsite1.com;

    location / {
        proxy_pass http://your_server_ip:8080;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
    listen 443 ssl;
    ssl_certificate /etc/letsencrypt/live/www.testsite1.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/www.testsite1.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
}
server {
    listen 80;
    server_name www.testsite2.com;

    location / {
        proxy_pass http://your_server_ip:8080;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }
    listen 443 ssl;
    ssl_certificate /etc/letsencrypt/live/www.testsite2.com/fullchain.pem;
    ssl_certificate_key /etc/letsencrypt/live/www.testsite2.com/privkey.pem;
    include /etc/letsencrypt/options-ssl-nginx.conf;
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem;
}

```

Nginx設定ファイルをリロードして動作を確認します。

```auto
# nginx -s reload

```

**\<参考サイト\>**

> **[How To Configure Nginx as a Web Server and Reverse Proxy for Apache on One...](https://www.digitalocean.com/community/tutorials/how-to-configure-nginx-as-a-web-server-and-reverse-proxy-for-apache-on-one-ubuntu-18-04-server)**
>
> In this tutorial you’ll configure Nginx as both a web server and as a reverse proxy for Apache to host four domains on a single server.

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2020 年 7 月 20 日午前 12:32 UTC](https://forum.ficusonline.com/t/topic/375/2 "2020-07-20T00:32:53Z")

</div>

### certbot renewコマンドによる証明書更新

> **[User Guide — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/using.html)**

### crontabによる更新

> **[User Guide — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/using.html)**

**注）** 以下コマンドで更新の際は **nginx** で有効になっているドメインを再確認すること。無効なドメインが残っていると更新プロセスに影響があります。無効なドメインは **deleteコマンド** で削除します。

```auto
# certbot certificates

```

**nginx** コンテナにインストールした **certbot** で更新する場合は、ホストマシンから **crontab** で実行スケジュールを指定します。

毎週月曜日1:00,1:05に実行

```auto
$ sudo crontab -e

#certbot in nginx docker
0 1 * * 1 docker exec nginx bash -c "certbot renew >> /var/log/letsencrypt/renew.log"
5 1 * * 1 docker exec nginx bash -c "nginx -s reload"

```

または、

```auto
$ sudo crontab -e

#certbot in nginx docker: for the certification renewal, execute "certbot renew" or "certbot --nginx -d www.example1.com -d www.example2.com"
@monthly docker exec nginx bash -c "certbot --nginx -d www.example1.com -d www.example2.com"

```

**更新頻度の目安**

以下のFAQによると証明書は90日で期限切れとなるため60日毎の更新を推奨しています。

**What is the lifetime for Let’s Encrypt certificates? For how long are they valid?**

> **[What is the lifetime for Let’s Encrypt certificates? For how long are they... -...](https://letsencrypt.org/docs/faq/#what-is-the-lifetime-for-let-s-encrypt-certificates-for-how-long-are-they-valid)**
>
> This FAQ is divided into the following sections:
> General Questions Technical Questions General Questions What services does Let’s Encrypt offer? Let’s Encrypt is a global Certificate Authority (CA). We let people and organizations around the world...

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2020 年 7 月 28 日午前 2:54 UTC](https://forum.ficusonline.com/t/topic/375/3 "2020-07-28T02:54:16Z")

</div>

### 証明書の削除 “certbot delete”

```auto
# certbot delete
Saving debug log to /var/log/letsencrypt/letsencrypt.log

Which certificate(s) would you like to delete?
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
1: www.test001.com
2: www.test002.com
3: www.test001.org
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Select the appropriate numbers separated by commas and/or spaces, or leave input
blank to select all options shown (Enter 'c' to cancel): c

```

または、

```auto
# certbot revoke --cert-name www.test001.com

```

```auto
# certbot --help
manage certificates:
    certificates Display information about certificates you have from Certbot
    revoke Revoke a certificate (supply --cert-path or --cert-name)
    delete Delete a certificate

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2020 年 9 月 25 日午後 1:07 UTC](https://forum.ficusonline.com/t/topic/375/4 "2020-09-25T13:07:28Z")

</div>

### Certbot-Dockerhub

> **[certbot/certbot - Docker Image](https://hub.docker.com/r/certbot/certbot/)**

**Dockerコンテナによる運用**

> **[Get Certbot — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/install.html)**

**スタンドアローンモード（オプション）**  
ウェブサーバ以外の用途で認証を取得する場合のオプションです。  
認証取得には、ポート:80をオープンにする必要があるため、ウェブサーバ等は停止してから実行すること。

> **[User Guide — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/using.html)**

**certonly** ：単に指定ドメインの認証を取得したいだけの場合

```auto
$ sudo docker run -it --rm --name certbot \
            -v "$PWD/letsencrypt:/etc/letsencrypt" \
            -v "/var/lib/letsencrypt:/var/lib/letsencrypt" \
            -p 80:80 \
            certbot/certbot certonly --standalone -d stun.example.com

```

コンテナ内の **/etc/letsencrypt/live** ディレクトリに証明書が作成されるため、 **-vオプション** によりホスト側のアプリ指定のディレクトリと共有させます。

**certbotコマンドオプション**

> **[User Guide — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/using.html)**

* * *

**マニュアルモード(standalone + preferred-challenges)**

> **[User Guide — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/using.html)**

サーバ以外での用途にSSL認証を取得したい時に利用します。

> **[How To Use Certbot Standalone Mode to Retrieve Let's Encrypt SSL Certificates...](https://www.digitalocean.com/community/tutorials/how-to-use-certbot-standalone-mode-to-retrieve-let-s-encrypt-ssl-certificates-on-ubuntu-16-04)**
>
> Certbot offers a variety of ways to validate your domain, fetch certificates, and automatically configure Apache and Nginx. In this tutorial, we’ll discuss C…

ポート80を開放して以下コマンドを実行します。

```auto
$ sudo certbot certonly --standalone --preferred-challenges http -d test.example.com

```

```
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Plugins selected: Authenticator standalone, Installer None
Obtaining a new certificate
Performing the following challenges:
http-01 challenge for test.example.com
Waiting for verification...
Cleaning up challenges

IMPORTANT NOTES:
 - Congratulations! Your certificate and chain have been saved at:
   /etc/letsencrypt/live/test.example.com/fullchain.pem
   Your key file has been saved at:
   /etc/letsencrypt/live/test.example.com/privkey.pem
   Your cert will expire on 2021-07-27. To obtain a new or tweaked
   version of this certificate in the future, simply run certbot
   again. To non-interactively renew *all* of your certificates, run
   "certbot renew"
 - If you like Certbot, please consider supporting our work by:

   Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate
   Donating to EFF: https://eff.org/donate-le

```

`/etc/letsencrypt/live/test.example.com`に認証ファイルが作成されます。

```auto
$ sudo ls /etc/letsencrypt/live/test.example.com
README	cert.pem chain.pem fullchain.pem privkey.pem

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2021 年 4 月 16 日午後 2:59 UTC](https://forum.ficusonline.com/t/topic/375/5 "2021-04-16T14:59:16Z")

</div>

## Nginx+Certbot Docker

**Github**

> **[GitHub - JonasAlfredsson/docker-nginx-certbot: Automatically create and renew website...](https://github.com/JonasAlfredsson/docker-nginx-certbot/)**
>
> Automatically create and renew website certificates for free using the Let's Encrypt certificate authority.

**Docker hub**

> **[jonasal/nginx-certbot - Docker Image](https://hub.docker.com/r/jonasal/nginx-certbot)**

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2021 年 4 月 21 日午後 2:05 UTC](https://forum.ficusonline.com/t/topic/375/6 "2021-04-21T14:05:12Z")

</div>

### リバースプロキシサーバ経由のサーバでLet’s Encryptによる証明書を取得

以下、同一LAN内に配置した②でLet’s Encryptによる証明書を取得する場合

| WAN | LAN | Local IP |
| --- | --- | --- |
| Internet \>\>\> | NAT(Router) \>\>\> | ① Nginx Reverse Proxy:192.168.0.10 \>\>\> ② Nginx Server:192.168.0.20 |
| **注)** ②はリバースプロキシサーバ①経由で配置したサーバ | | |

①のマシン上でcertbotにより複数ドメインの証明書は取得できますが、②で証明書を他の用途(SIPサーバ等)でも使用したい場合、①からコピーするのではなく②でもcertbotにより取得します。

## **`$ cetbot --nginx` コマンド実行前の設定**

① Nginx Reverse Proxyの設定 `/etc/nginx/conf.d/your-domain.conf`  
**注)** プロキシ箇所のみの設定のため、別途default.confの設定も必要です。

```auto
server {
    server_name www.your-domain.com;

    server_tokens off;

    location / {
        proxy_pass http://192.168.0.20;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    listen 80;
}

```

② Nginx Severの設定 `/etc/nginx/conf.d/default.conf`

```auto
server {
    root /var/www/html;
    server_name www.your-domain.com;
    index ndex.html;

    location / {
          location ~ \.php$ {
             #fastcgi_pass fastcgi_backend;
             include fastcgi_params;
             fastcgi_param SCRIPT_FILENAME $request_filename;
             fastcgi_index index.php;
             fastcgi_pass 127.0.0.1:9000;
          }
    }

    listen 80;
}

```

### **Note) HTTP-01 challenge**

②でcertbotコマンドを実行する前に①の`proxy_pass`が`http`であることを確認すること。

> proxy\_pass **http** ://192.168.0.20;

②でcertbot実行後はhttpsにすること。

> proxy\_pass **https** ://192.168.0.20;

### HTTP-01 challenge

> **[HTTP-01 challenge - Challenge Types](https://letsencrypt.org/docs/challenge-types/#http-01-challenge)**
>
> When you get a certificate from Let’s Encrypt, our servers validate that you control the domain names in that certificate using “challenges,” as defined by the ACME standard. Most of the time, this validation is handled automatically by your ACME...

## **`$ cetbot --nginx` コマンド実行後の設定**

① Nginx Reverse Proxyの設定 `/etc/nginx/conf.d/your-domain.conf`  
**注)** プロキシ箇所のみの設定のため、別途default.confの設定も必要です。

```auto
server {
    server_name www.your-domain.com;

    server_tokens off;

    location / {
        proxy_pass https://192.168.0.20;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
    }

    listen 443 ssl; # managed by Certbot
    ssl_certificate /etc/letsencrypt/live/www.your-domain.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/www.your-domain.com/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}
server {
    if ($host = www.your-domain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    server_name www.your-domain.com;
    listen 80;
    return 404; # managed by Certbot
}

```

② Nginx Severの設定 `/etc/nginx/conf.d/default.conf`

```auto
server {
    root /var/www/html;
    server_name www.your-domain.com;
    index ndex.html;

    location / {
          location ~ \.php$ {
             #fastcgi_pass fastcgi_backend;
             include fastcgi_params;
             fastcgi_param SCRIPT_FILENAME $request_filename;
             fastcgi_index index.php;
             fastcgi_pass 127.0.0.1:9000;
          }
    }

    listen 443 ssl; # managed by Certbot
    ssl_certificate /etc/letsencrypt/live/www.your-domain.com/fullchain.pem; # managed by Certbot
    ssl_certificate_key /etc/letsencrypt/live/www.your-domain.com/privkey.pem; # managed by Certbot
    include /etc/letsencrypt/options-ssl-nginx.conf; # managed by Certbot
    ssl_dhparam /etc/letsencrypt/ssl-dhparams.pem; # managed by Certbot

}

server {
    if ($host = www.your-domain.com) {
        return 301 https://$host$request_uri;
    } # managed by Certbot

    listen 80;
    server_name www.your-domain.com;
    return 404; # managed by Certbot
}

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2021 年 10 月 12 日午後 12:47 UTC](https://forum.ficusonline.com/t/topic/375/7 "2021-10-12T12:47:14Z")

</div>

### Certbotコマンドオプション

> **[User Guide — Certbot 5.5.0.dev0 documentation](https://eff-certbot.readthedocs.io/en/latest/using.html)**

**一部抜粋**

```auto
usage: 
  certbot [SUBCOMMAND] [options] [-d DOMAIN] [-d DOMAIN] ...

Certbot can obtain and install HTTPS/TLS/SSL certificates. By default,
it will attempt to use a webserver both for obtaining and installing the
certificate. The most common SUBCOMMANDS and flags are:

obtain, install, and renew certificates:
    (default) run Obtain & install a certificate in your current webserver
    certonly Obtain or renew a certificate, but do not install it
    renew Renew all previously obtained certificates that are near expiry
    enhance Add security enhancements to your existing configuration
   -d DOMAINS Comma-separated list of domains to obtain a certificate for

  --apache Use the Apache plugin for authentication & installation
  --standalone Run a standalone webserver for authentication
  --nginx Use the Nginx plugin for authentication & installation
  --webroot Place files in a server's webroot folder for authentication
  --manual Obtain certificates interactively, or using shell script hooks

   -n Run non-interactively
  --test-cert Obtain a test certificate from a staging server
  --dry-run Test "renew" or "certonly" without saving any certificates to disk

manage certificates:
    certificates Display information about certificates you have from Certbot
    revoke Revoke a certificate (supply --cert-name or --cert-path)
    delete Delete a certificate (supply --cert-name)

manage your account:
    register Create an ACME account
    unregister Deactivate an ACME account
    update_account Update an ACME account
  --agree-tos Agree to the ACME server's Subscriber Agreement
   -m EMAIL Email address for important account notifications

```

**Dockerfileでは `--agree-tos` オプションを使用**

```auto
Please read the Terms of Service at https://letsencrypt.org/documents/LE-SA-v1.2-November-15-2017.pdf. You must agree in order to register with the ACME server. Do you agree?

(You can set this with the --agree-tos flag)

```

オプション **`'-n', '--agree-tos'`** を付与するとコマンド実行後の **certbot** が要求する入力事項を省略できます。

```auto
$ certbot --nginx --agree-tos -n -d www.EXAMPLE.com -m EXAMPLE@gmail.com

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2022 年 2 月 1 日午前 7:31 UTC](https://forum.ficusonline.com/t/topic/375/8 "2022-02-01T07:31:41Z")

</div>

## Official Nginx DockerHubイメージ

**NginxオフィシャルのDockerイメージ** では、 **`.template` 拡張子** を付けたテンプレート設定ファイル **`default001.conf.template`** の中で変数を定義することが出来ます。このテンプレートファイルはコンテナ起動時に、変数が **docker-composeファイル** で指定した値や文字に変換されて **`/etc/nginx/conf.d`** フォルダに **`default001.conf`** ファイルとして保存され読み込まれます。

> **[nginx - Official Image | Docker Hub](https://hub.docker.com/_/nginx)**
>
> Official build of Nginx.

**ex) `default001.conf.template`** という設定ファイルのテンプレートを **`docker-compose.yml`** ファイルが格納されているフォルダ内に作成し、そのファイル内で変数 **`${NGINX_HOST}, ${NGINX_PORT}`** を定義します。

**`./templates/default001.conf.template`**

```auto
server {
    root /var/www/html;
    server_name ${NGINX_HOST};
    listen ${NGINX_PORT};
    .....
    }
.....
.....

```

作成したテンプレートは、以下 **docker-composeファイル** で **Dockerコンテナ** の **`/etc/nginx/templates`** フォルダにコピーされます。 **nginx** コンテナ起動時、変数が指定した値や文字に変換された設定ファイルが **`/etc/nginx/conf.d/default001.conf`** として読み込まれます。

```auto
web:
  image: nginx
  volumes:
   - ./templates:/etc/nginx/templates
  ports:
   - "8080:80"
  environment:
   - NGINX_HOST=foobar.com
   - NGINX_PORT=80

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2022 年 2 月 2 日午後 12:08 UTC](https://forum.ficusonline.com/t/topic/375/9 "2022-02-02T12:08:16Z")

</div>

## NginxコンテナへのCertbotの導入について

‼  
**Nginx** 公式イメージに **Certbot** を追加した新規イメージを作成し、コンテナ起動後に **Certbot** による認証手続きを行うのではなく、事前に **Certbot** による **SSL認証手続き** を専用の **Docker** イメージを利用して **スタンドアローンモード** で行い、取得した認証ファイルを **docker-compose** ファイル内で指定して **Nginx** コンテナを起動することを推奨します。

**Running on Docker**

> **[Get Certbot — Certbot 5.4.0 documentation](https://eff-certbot.readthedocs.io/en/stable/install.html#running-with-docker)**

```auto
$ sudo docker run -it --rm --name certbot -v "$PWD/letsencrypt:/etc/letsencrypt" -p 80:80 certbot/certbot certonly --standalone -d www.example.com

```

事前に **SSL認証ファイル** が取得できるため、 **Nginx** の **443** ポートを指定した設定ファイルを事前に用意出来ます。

更新については上の投稿記事 **”Certbotコマンドオプション”** を参照してホストマシンのクローンジョブに更新コマンドを記述すること。

### [Certbot - ArchWiki](https://wiki.archlinux.org/title/certbot)

> The factual accuracy of this article or section is disputed.  
> Reason: In the webroot way, the **`/var/lib/letsencrypt`** path is dictated by certbot.  
> Manual creation is not necessary, that applies to [#Manual](https://wiki.archlinux.org/title/certbot#Manual).

* * *

### トラブルシュート

> <https://github.com/certbot/certbot/issues/2916>
>
> Hi,
> 
> It's never the right time to have issues...
> I got a certificate expiring to…morrow, and I can't renew it.
> 
> \`\`\`
> letsencrypt certonly --apache --renew-by-default --domains 
> Requested domain is not a FQDN
> \`\`\`
> 
> This is what I got for the domain https://canada.with.susie.and.louwii.fr/
> 
> What file should I modify in order to make that work ? I'd like to renew my cert quite quickly.
> 
> Thanks !

I was writing:

```auto
./certbot-auto certonly --expand -d first.domain.com, second.domain.com

```

It should be:

```auto
./certbot-auto certonly --expand -d first.domain.com,second.domain.com

```

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2022 年 2 月 20 日午前 12:55 UTC](https://forum.ficusonline.com/t/topic/375/10 "2022-02-20T00:55:19Z")

</div>

## Nginx SSLオプションの適用

**TLS** バージョンの指定などのセキュリティ対策。 **TLS** は **SSL** の後継呼称として捉えて構いません。SIPなどのウェブアプリなどでTLS認証を使用する場合にはバージョンの整合性に注意。

**`nginx`** プラグイン **`--nginx`** を指定して取得した場合は下記ファイルが作成されるため、このファイル内で調整します。

**`/etc/letsencrypt/options-ssl-nginx.conf`**

**TLSバージョンv1.2とv1.3を指定**

```auto
# This file contains important security parameters. If you modify this file
# manually, Certbot will be unable to automatically provide future security
# updates. Instead, Certbot will print and log an error message with a path to
# the up-to-date file that you will need to refer to when manually updating
# this file.

ssl_session_cache shared:le_nginx_SSL:10m;
ssl_session_timeout 1440m;
ssl_session_tickets off;

ssl_protocols TLSv1.2 TLSv1.3;
ssl_prefer_server_ciphers off;

ssl_ciphers "ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384";

```

> <https://github.com/certbot/certbot/blob/master/certbot-nginx/certbot_nginx/_internal/tls_configs/options-ssl-nginx.conf>

**`ssl_prefer_server_ciphers on` の場合**  
**Standalone** モードでTLS認証を取得した場合は、 **`openssl`** コマンドで以下の **`dhp-4096.pem`** ファイルを作成、格納ディレクトリを指定して下さい。（ **`nginx`** プラグイン **`--nginx`** を指定して取得した場合、既に `/etc/letsencrypt` ディレクトリに格納されています。）

```auto
ssl_prefer_server_ciphers on;
  # on this container, "mkdir -p /etc/nginx/ssl"
  # on host machine, "sudo openssl dhparam -out dhp-4096.pem 4096"
  ssl_dhparam /etc/nginx/ssl/dhp-4096.pem;

```

**OpenSSL Wiki バイナリ**  
[Binaries · openssl/openssl Wiki · GitHub](https://wiki.openssl.org/index.php/Binaries)

Certonlyモードでは上記暗号化に必要なファイルは自分で用意します。

> **[Generating options-ssl-nginx.conf and ssl-dhparams in certonly mode](https://community.letsencrypt.org/t/generating-options-ssl-nginx-conf-and-ssl-dhparams-in-certonly-mode/136272)**
>
> Hello, I'm using nginx within docker, so I've installed certbot on the host machine and used certbot certonly along with the dns-digitalocean plugin to generate my certs. It's working well, except I get a B rating on ssl labs. I believe this is...

以下のMozillaによるSSL Configuration Generatorも参考にして下さい。

> **[Mozilla SSL Configuration Generator](https://ssl-config.mozilla.org/)**
>
> An easy-to-use secure configuration generator for web, database, and mail software. Simply select the software you are using and receive a configuration file that is both safe and compatible.

---

<div class="post-metadata">

### Author: ![tk-fuse](https://forum.ficusonline.com/user_avatar/forum.ficusonline.com/tk-fuse/32/255_2.png) [@tk-fuse](https://forum.ficusonline.com/u/tk-fuse)
#### Post date: [2022 年 11 月 28 日午前 2:41 UTC](https://forum.ficusonline.com/t/topic/375/11 "2022-11-28T02:41:47Z")

</div>

## IPv6アドレスによるSSL認証

ドメインのIPアドレスがIPv4とIPv6で設定されている場合、CertbotによるSSL認証ではIPv6アドレスが優先されて認証アクセスされます。

> **[IPv6 Support](https://letsencrypt.org/docs/ipv6-support/)**
>
> Let’s Encrypt supports IPv6 both for accessing the ACME API using an ACME client, and for the DNS lookups and HTTP requests we make when validating your control of domain names.
> Domain Validation When making outbound domain validation requests for a...

## Domain Validation

When making outbound domain validation requests for a domain that has **both IPv4 and IPv6 addresses (e.g. both `A` and `AAAA` records)** Let’s Encrypt will **always prefer the IPv6 addresses** for the initial connection. If the IPv6 connection fails at the network level (e.g. there is a timeout) and there are IPv4 addresses available then we will retry the request with one of the IPv4 addresses.
