ã€ã³ã¿ãŒãããã§ã¯ããã®ãããªããéæšæºã®ãµãŒããŒãã€ã³ã¹ããŒã«ããŠæ§æããããã®ã¬ã·ãã¯1ã€ãèŠã€ãããŸããã§ããã ã¬ã·ããæžãããšã«ããŸããã
åäœåçã¯æ¬¡ã®ãšããã§ãã
Nginxã¯éçããŒã¿ïŒãã¡ã€ã«ïŒãæäŸããApacheã¯ãã€ããã¯ã¹ã«åŸäºããŠããŸãã
å§ããŸãããã
å¿
èŠãªãã®ïŒ
VirtualboxUbuntu Server 16.04.3 LTS ïŒ
LTS-é·æéãµããŒãïŒ
PuTTYVirtualBoxãã€ã³ã¹ããŒã«ãã
- VirtualBoxã€ã³ã¹ããŒã©ãŒãå®è¡ããŸãã
- ããã©ã«ãèšå®ã®ãŸãŸã«ããŸãã
- ã€ã³ã¹ããŒã©ãŒã¯äžæçã«ãããã¯ãŒã¯ããåæããŸãã [ã¯ã]ãã¯ãªãã¯ããŸãã
- ã€ã³ã¹ããŒã«ãéå§ããŸãã
- ãã£ããã·ã¥ã©ã€ã³ã
Ubuntu Server 16.04.3 LTSã€ã³ã¹ããŒã«çšã«VirtualBoxãæºåãã
- ubuntu-16.04.3-server-amd64.isoã€ã¡ãŒãžãããŠã³ããŒãããŸã
- ä»®æ³ãã·ã³ãäœæããŸãã
- ååïŒdefault_server
ã¿ã€ãïŒLinux
ããŒãžã§ã³ïŒUbuntuïŒ64ãããïŒ
RAM容éïŒ2048 MB
éèŠïŒ8 GBã®RAMããããç§ã®å Žåã¯2ã®ã¬ãã€ãã§ååã§ãã ããªãã®ãã®ã¯ç°ãªããããããŸãã...
ããŒããã©ã€ããµã€ãºïŒ15 GB
ä»ã®ãã©ã¡ãŒã¿ã¯ããã©ã«ãã§æ®ãããŸãã
ãäœæããã¯ãªãã¯ããŸãã
- ãããã¯ãŒã¯ãããã«æ§æããŸãã
æ¥ç¶ã¿ã€ããNATãããããã¯ãŒã¯ããªããžã«å€æŽããŸãã
å°æ¥çã«ã¯ãããŒã転éãåŠçããŸããã - è»ãå§åããŸãã
Ubuntu Server 16.04.3 LTSãã€ã³ã¹ããŒã«ããŸã
- Ubuntu Server 16.04.3 LTSã€ã¡ãŒãžã®ããããŒããã£ã¹ã¯ãéžæããŸãã
- 䟿å©ãªèšèªãéžæããŸãããã·ã¢èªããããŸãã
ãEnterããã¯ãªãã¯ããŸãã - ãUbuntuãµãŒããŒã®ã€ã³ã¹ããŒã«ããéžæããŸãã
- åœãéžæããŠãã ããã
éèŠïŒç»é¢äžéšã®ããã³ãããèªãã§ãã ããã
- ããŒããŒãã¬ã€ã¢ãŠãã決å®ããŸãããããã¯å¿
èŠãããŸããã
- ããŒããŒãã䜿çšããåœãéžæããŸãã
- ã¬ã€ã¢ãŠãã®é åãéžæããŸãã
- ããŒã®çµã¿åãããéžæããŠãèšèªãåãæ¿ããŸãã CTRL +
ã·ããã
- ãããã¯ãŒã¯äžã§èªèãããã³ã³ãã¥ãŒã¿ãŒã®ååãå
¥åããŸãã
- 管çè
ã®ååãå
¥åããŸãã
- 管çè
ã¢ã«ãŠã³ãã®ååãå
¥åããŸãïŒã·ã¹ãã ã«å
¥ãããã®ãã°ã€ã³ãšããŠäœ¿çšãããŸãïŒã
- 管çè
ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããå
¥åããŸãã
- ãã¹ã¯ãŒããç¹°ãè¿ããŸãã
- ã©ãããŠ..ïŒ
- ã¿ã€ã ãŸãŒã³ãéžæããŸãã
- ã·ã¹ãã ããã£ã¹ã¯å
šäœãèªåçã«äœ¿çšããããã«ããŸãã
- ããŒãã£ã·ã§ã³ãã£ã¹ã¯ãããã©ã«ãã§éžæããŸãã
- å€æŽããã£ã¹ã¯ã«æžã蟌ã¿ãŸãã
- ãããã·ã¯ãããŸããããã£ãŒã«ãã空ã®ãŸãŸã«ããŠç¶è¡ããŸãã
- ã·ã¹ãã èªäœã«ã»ãã¥ãªãã£æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ãããŸãã
- ã·ã¹ãã ãšå
±ã«ã€ã³ã¹ããŒã«ãããããã°ã©ã ã®ã»ãããéžæããŸãã
æšæºã»ãããšOpenSSHãµãŒããŒã§ååã§ãã
- GRUBãã¡ã€ã³ãšããŠèšå®ããŸãã
- ã»ãŒå®äºã§ãã
ãã©ã€ããããã£ã¹ã¯ãåé€ããå¿
èŠããããŸãã
ããã€ã¹->å
åŠãã£ã¹ã¯->ãã©ã€ããããã£ã¹ã¯ãåé€
ç¶è¡ãã¯ãªãã¯ããŸãã - Ubuntu Serverãã€ã³ã¹ããŒã«ãããŸããã
ãã°ã€ã³ãå
¥åãããã®åŸã«ãã¹ã¯ãŒããå
¥åããŠãã·ã¹ãã ã«å
¥ããŸãããã¹ãŠãOKã§ãã
è»ã®é»æºãåããŸãã
poweroff
- å
·äœçã«ã¯ããã®ãã·ã³ã¯ãã®ãŸãŸã«ããŠãã¯ããŒã³äœæã«ã®ã¿äœ¿çšããŸãã
è»ã®ã¯ããŒã³ãäœæããŸãã
ååãå
¥åããŠãã ããã
ç¶ããŸãã
å®å
šãªã¯ããŒã³ãéžæããŸãã
ã¯ãªãã¯ããŠè€è£œããŸãã ã¯ããŒã³äœæã¯2åéç¶ããŸããã
PuTTYãã€ã³ã¹ããŒã«ããŠSSHçµç±ã§ã¢ã¯ã»ã¹ãã
- ã€ã³ã¹ããŒã«ãã¡ã€ã«ãå®è¡ããŸãã
- ããã©ã«ãèšå®ã®ãŸãŸã«ããŸãã
ãã€ã³ã¹ããŒã«ããã¯ãªãã¯ããŸãã - ãã£ããã·ã¥ã©ã€ã³ã
SSHãä»ãããµãŒããŒãžã®æ¥ç¶
- ãã·ã³ã®ã¯ããŒã³ãå®è¡ããŠãIPã¢ãã¬ã¹ã確èªããŸãã
ã³ãã³ããæžããŸãããïŒ
ifconfig
ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ãIPã¢ãã¬ã¹ãæžã蟌ãŸããå ŽæãããŒã¯ããŸããã ç§ã¯ãããæã£ãŠããŸãïŒ192.168.0.103ïŒèšäºã®å·çäžã«å€æŽã§ããŸãããç§ã«ãšã£ãŠã¯192.168.0.101ã«å€æŽãããŸããïŒã
ããã§ã次ã®ããã«èšè¿°ããŠã¢ã«ãŠã³ããããã°ã¢ãŠãã§ããŸãã
exit
- PuTTYã«ç§»åããŠãä¿åãããã»ãã·ã§ã³ã®IPã¢ãã¬ã¹ãšååãå
¥åããŸãã
[ä¿å]ãã¯ãªãã¯ããŸãã
- 次ã«ãä¿åããã»ãã·ã§ã³ã®ååãããã«ã¯ãªãã¯ããŸãã
以äžãéµå®ããå¿
èŠããããŸãã
ãã¹ã¯ãŒãã®åŸã«ââãã°ã€ã³ãå
¥åããŸãã
SSHæ¥ç¶ãæ£åžžã«æ§æãããŸãããããã§ïŒNginx + ApacheïŒ+ PostgreSQL + PHPã®æ§æãéå§ã§ããŸãã
ã€ã³ã¹ããŒã«ãšæ§æïŒNginx + ApacheïŒ+ PostgreSQL + PHP
ã¹ãŒããŒãŠãŒã¶ãŒã¢ãŒãã«åãæ¿ããŸããã
sudo su
ã«ãŒããã£ã¬ã¯ããªã«è¡ããŸããã
cd /
PostgreSQLãªããžããªãè¿œå ãã
wget -q https://www.postgresql.org/media/keys/ACCC4CF8.asc -O - | sudo apt-key add -
sh -c 'echo "deb http://apt.postgresql.org/pub/repos/apt/ `lsb_release -cs`-pgdg main" >> /etc/apt/sources.list.d/pgdg.list'
PHPãªããžããªãè¿œå ãã
add-apt-repository ppa:ondrej/php
æŽæ°ãã
apt-get update
ã¢ããã°ã¬ãŒãããŸããã
apt-get upgrade
ã¢ããã°ã¬ãŒãã¯5åéç¶ããŸããã
pythonãååŸããŸããåŸã§å¿
èŠã«ãªããŸã
apt-get install python
ApacheãPHPãPostgreSQLã®ã€ã³ã¹ããŒã«ãå§ããŸããã
apt-get install apache2 php7.2 php7.2-cli php7.2-curl php7.2-fpm php7.2-pgsql postgresql postgresql-contrib postgresql-server-dev-10 libapache2-mod-rpaf build-essential apache2-dev
ããã©ã«ãã§ã¯ãPostgreSQLã«ã¯ã·ã³ã°ã«ãã€ãããã³ç¬Šå·ãªãã®æ°åããªããããã€ã³ã¹ããŒã«ããŸãã
PostgreSQLã®æ¡åŒµæ©èœã§ãã
pguint-github.com/petere/pguintgit clone https://github.com/petere/pguint.git /pguint
äœæãããã£ã¬ã¯ããªã«è¡ããŸããã
cd /pguint
次ã«ããã®æ¡åŒµæ©èœãã³ã³ãã€ã«ããå¿
èŠããããŸãïŒããã§ãå
ã»ã©ã€ã³ã¹ããŒã«ããpythonãå¿
èŠã§ãïŒã
make
make install
ããã§ãç®çã®ããŒã¿ããŒã¹ã®PostgreSQLãµãŒããŒã«ã笊å·ãªãã®1ãã€ãã®æ°åã䜿çšãããå Žåã次ãéä¿¡ããŸãã
CREATE EXTENSION uint;
ã«ãŒããã£ã¬ã¯ããªã«æ»ããŸããã
cd /
Nginxãã€ã³ã¹ããŒã«ããŸããããã®åã«ããŒã80ãå æããªãããã«Apacheãåæ¢ããŸããããããªããšãNginxã¯ã€ã³ã¹ããŒã«ãããŸããã
service apache2 stop
Nginxã®ã€ã³ã¹ããŒã«
apt-get install nginx
OKãnginxãåæ¢ããŸã
service nginx stop
Apacheãæ§æãã
a2dismod mpm_event
a2enmod mpm_worker
a2enmod proxy_fcgi
a2enconf php7.2-fpm
ApacheããŒããå€æŽãã
nano /etc/apache2/ports.conf
亀æ
Listen 80
ã«
Listen 127.0.0.1:8080
127.0.0.1-ããŒã«ã«ã¢ãã¬ã¹ã§ã®ã¿Apacheã«ã¢ã¯ã»ã¹ã§ããããšãæå³ããŸãã
8080-ä»»æã®ç©ºãããŒããé
眮ã§ããŸãã
å©çšå¯èœãªãµã€ãããããã©ã«ããŒã«è¡ããŸããã
cd /etc/apache2/sites-available
ç§ãã¡ã®åŽã®èšå®ãã¡ã€ã«ãäœæããŸã
nano domain-name.local.conf
ãããŠããã®ãã©ãŒã ã«æã£ãŠããŠãã ããïŒ
<VirtualHost 127.0.0.1:8080> ServerName domain-name.local ServerAlias www.domain-name.local ServerAdmin admin@domain-name.local DocumentRoot /var/www/domain-name.local ErrorLog ${APACHE_LOG_DIR}/domain-name.local_error.log CustomLog ${APACHE_LOG_DIR}/domain-name.local_access.log vhost_combined </VirtualHost>
/ var / wwwã«ãããã®ãèŠãŠã¿ãŸããã
cd /var/www/
ls -F
htmlãã©ã«ããŒãå¿
èŠãªããªããŸãããã³ã³ãã³ããšäžç·ã«åé€ããŸã
rm -R html
ãµã€ãã«ç¬èªã®ãã©ã«ããŒãäœæããŸã
mkdir domain-name.local/
ç§ãã¡ã®ãµã€ãã®ãããã©ã«ããŒã«è¡ããŸããã
cd domain-name.local/
index.pnpããã¥ã¡ã³ããäœæãã
nano index.php
æžã蟌ã¿ãŸãïŒ
<?php phpinfo(); ?>
ããã¯ãŸã çµäºããŠããŸãã
ã«ãŒããã£ã¬ã¯ããªã«æ»ããŸããã
cd /
Apacheã§ã¯ãrpaf 0.6ãã€ã³ã¹ããŒã«ãããŠãããnginxããããŒããéåä¿¡ããªããããæ£åžžã«åäœããŸããã ãããã£ãŠãæŽæ°ããå¿
èŠããããŸãã
wget -O rpaf_v0.8.4.tar.gz https://github.com/gnif/mod_rpaf/archive/v0.8.4.tar.gz
gunzip rpaf_v0.8.4.tar.gz
tar xvf rpaf_v0.8.4.tar
cd mod_rpaf-0.8.4/
ã³ã³ãã€ã«ãã
make
make install
ã«ãŒããã£ã¬ã¯ããªã«ç§»åããŸã
cd /
ã§ã¯ãApacheã®ã»ããã¢ãããç¶ããŸãããã
nano /etc/apache2/apache2.conf
亀æ
LogFormat "%v:%p %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
ã«
LogFormat "%v:%p %{X-Forwarded-For}i %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined
ãã¡ããšããrpaf.conf
nano /etc/apache2/mods-available/rpaf.conf
ãã®ãã©ãŒã ã«æã£ãŠããŸãïŒ
<IfModule rpaf_module> RPAF_Enable On RPAF_ProxyIPs 127.0.0.1 ::1 RPAF_SetHostName On RPAF_SetHTTPS On RPAF_SetPort On RPAF_ForbidIfNotProxy Off RPAF_Header X-Forwarded-For </IfModule>
Apacheã§ãµã€ããæå¹ã«ããŸãã
a2ensite domain-name.local.conf
ãããŠãApacheãå®è¡ããŸãã
service apache2 start
C ApacheãçµäºããŸããã
Nginxãæ§æãã
nano /etc/nginx/sites-available/domain-name.local
ãã®ãã¥ãŒã衚瀺ããŸãïŒ
server { listen 80; listen [::]:80; root /var/www/domain-name.local; index index.php index.html index.htm; server_name domain-name.local www.domain-name.local; location / { proxy_pass http://127.0.0.1:8080; proxy_redirect off; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_pass_header Set-Cookie; } location ~ /\.ht { deny all; } location ~* \.(ico|docx|doc|xls|xlsx|rar|zip|jpg|jpeg|txt|xml|pdf|gif|png|css|js|html)$ { root /var/www/domain-name.local; } add_header Strict-Transport-Security "max-age=63072000; includeSubDomains; preload"; add_header Content-Security-Policy "block-all-mixed-content"; add_header X-Frame-Options "SAMEORIGIN"; add_header X-XSS-Protection "1; mode=block"; add_header X-Content-Type-Options "nosniff"; resolver 8.8.8.8; }
次ã«ããã®ãã¡ã€ã«ãžã®ã·ã³ããªãã¯ãªã³ã¯ãäœæããŸã
ln -s /etc/nginx/sites-available/domain-name.local /etc/nginx/sites-enabled/domain-name.local
ç·šé/ etc / nginx / sites-available / default
nano /etc/nginx/sites-available/default
default_serverãåé€ããŸãããã
ãããŠãwwwãããªãã€ã¬ã¯ããæ¿å
¥ããŸãã ãããŠIP
server { listen 80; listen [::]:80; server_name www.domain-name.local; return 301 http://domain-name.local$request_uri; } server { listen 80; listen [::]:80; server_name 192.168.0.101; return 301 http://domain-name.local$request_uri; }
Nginxãèµ·åããŸãã
service nginx start
ãã°ããããã©ã®ããã«æ©èœãããã確èªã§ããŸãã
ãã ãããã®åã«ããã¹ããã¡ã€ã«Cãç·šéããŸãã\ Windows \ System32 \ drivers \ etc
ããã¹ããšãã£ã¿ãŒã§hostsãã¡ã€ã«ãéããäžçªäžã«æ¿å
¥ããŸãã
192.168.0.101 domain-name.local
192.168.0.101 www.domain-name.local
IPãšãã¡ã€ã³ãç¬èªã®ãã®ã«çœ®ãæããŸãã
ãã©ãŠã¶ãŒã§
domain-name.localã«ç§»åã ããã®ã¬ã·ãã«åŸã£ãŠãã¹ãŠãè¡ã£ãå Žåãphpinfoã®ããŒãžã衚瀺ãããŸãã
ãŸããåé¡ã¯å°ããªãã®ã«ä»»ãããŠããŸãã
PostgreSQLãã»ããã¢ããããŸãã
æ°ããPostgreSQLãŠãŒã¶ãŒãäœæãã
sudo -u postgres createuser --superuser test-user
DBMSã«å
¥ããŸããã
sudo -u postgres psql
ãããŠãæ°ãããŠãŒã¶ãŒã®ãã¹ã¯ãŒããå€æŽããŸã
\password test-user
ããã§ãæ°ãããŠãŒã¶ãŒã¯æ¥ç¶ã®ã¿ââã€ããå€æŽããå¿
èŠããããŸãããã®ããã«ã¯ãpg_hba.confãã¡ã€ã«ãèŠã€ããå¿
èŠããããŸãã
æžã
SHOW hba_file;
DBMSãæ®ã
\q
/etc/postgresql/10/main/pg_hba.confã®ç·šéãéå§ããŸã
nano /etc/postgresql/10/main/pg_hba.conf
æ¢ããŠãã
# Database administrative login by Unix domain socket
以äžãèŠã€ãããŸãã
# Database administrative login by Unix domain socket
local all postgres peer
ç§ãã¡ã¯ãã®ãã©ãŒã ã«æã£ãŠããŸãïŒ
# Database administrative login by Unix domain socket
local all postgres peer
local all test-user md5
PostgreSQLãåèµ·åããŸã
service postgresql restart
次ã«ãæ°ãããŠãŒã¶ãŒãä»ããŠDBMSã«ã¢ã¯ã»ã¹ããŸã
psql test-user -h 127.0.0.1 -d postgres
ãã¹ã¯ãŒããå
¥åãããšãDBMSã«ã¢ã¯ã»ã¹ããŸãã
ãã¹ãããŒã¿ããŒã¹ãäœæãã
CREATE DATABASE test_db;
ãããŠããã«ããã«å
¥ã
\c test_db
pguintæ¡åŒµæ©èœãæ¥ç¶ããŸã
CREATE EXTENSION uint;
ãã¹ããã¿ãŒã³ãäœæããŸã
CREATE TABLE test_tb( id uint4 PRIMARY KEY, title TEXT );
ããŒãã«ã«ãã¹ãããŒã¿ãå
¥åããŸã
INSERT INTO test_tb(id, title) VALUES (1, ' 1'), (2, ' 2'), (3, ' 3'), (4, ' 4'), (5, ' 5'), (6, ' 6'), (7, ' 7'), (8, ' 8'), (9, ' 9'), (10, ' 10'), (2147483642, ' 2147483642'), (2147483643, ' 2147483643'), (2147483644, ' 2147483644'), (2147483645, ' 2147483645'), (2147483646, ' 2147483646'), (2147483647, ' 2147483647'), (2147483648, ' 2147483648'), (2147483649, ' 2147483649'), (2147483650, ' 2147483650'), (2147483651, ' 2147483651'), (2147483652, ' 2147483652'), (4294967286, ' 4294967286'), (4294967287, ' 4294967287'), (4294967288, ' 4294967288'), (4294967289, ' 4294967289'), (4294967290, ' 4294967290'), (4294967291, ' 4294967291'), (4294967292, ' 4294967292'), (4294967293, ' 4294967293'), (4294967294, ' 4294967294'), (4294967295, ' 4294967295') RETURNING id, title;
test_tbããŒãã«ã®å
容ãèŠãŠã¿ãŸããã
SELECT * FROM test_tb;
ããã§ã¯ããã®ããŒã¿ãphpããååŸããŠã¿ãŸãããã
DBMSãžã®æ¥ç¶ãéããŸã
\q
/var/www/domain-name.local/index.phpãéããŸã
nano /var/www/domain-name.local/index.php
ããã次ã®ãã©ãŒã ã«æã£ãŠãããŸãããïŒ
<?php $dbh = new PDO('pgsql:host=localhost port=5432 user=test-user dbname=test_db password=password'); $test = $dbh->prepare('SELECT * FROM test_tb;'); $test->execute(); echo "<pre>"; print_r($test->fetchAll(PDO::FETCH_ASSOC)); echo "</pre>"; ?>
ä»ããããæ©èœããããšã確èªããŠãã ãã
çŽ æŽããããïŒNginx + ApacheïŒ+ PostgreSQL + PHPãèšå®ããŸããããæ£åžžã«åäœããŸãã
ãµã€ããžã®FTPã¢ã¯ã»ã¹ãæ§æãã
FTPãµãŒããŒãã€ã³ã¹ããŒã«ãã
apt-get install vsftpd
èšå®ããåã«vsftpdãåæ¢ããŸã
service vsftpd stop
etc / vsftpd.confãéã
nano etc/vsftpd.conf
以äžã®ãã©ã¡ãŒã¿ãŒãèšå®/眮æ/åãæ¿ãïŒ
- èã=ã¯ã
- listen_ipv6 = NO
- local_enable = YES
- write_enable = YES
- chroot_local_user = YES
- pam_service_name = ftp
FTPçµç±ã§ã¢ã¯ã»ã¹ããæ°ãããŠãŒã¶ãŒãäœæããŸã
useradd -d /home/domain-name -s /sbin/nologin domain-name
ãã¹ã¯ãŒããèšå®ããŸã
passwd domain-name
ãŠãŒã¶ãŒã®ããŒã ãã£ã¬ã¯ããªãäœæãã
mkdir -p /home/domain-name
圌女ã«æš©å©ãèšå®ãã
chmod aw /home/domain-name
ãŠãŒã¶ãŒã®ã°ã«ãŒããäœæããŸã
groupadd ftps
ã°ã«ãŒãã«ãŠãŒã¶ãŒãè¿œå
usermod -G ftps domain-name
ãã£ã¬ã¯ããªã®ææè
ãå€æŽãã
chown -R domain-name:ftps /home/domain-name
ãµã€ãçšã®ãã©ã«ããŒãäœæããŸã
mkdir /home/domain-name/domain-name.local
圌女ã®ææè
ãå€æŽãã
chown -R domain-name:ftps /home/domain-name/domain-name.local
ãã£ã¬ã¯ããªãããŠã³ããããã¡ã€ã«/ etc / fstabãéããŸã
nano /etc/fstab
äžçªäžã«æ¿å
¥
/var/www/domain-name.local /home/domain-name/domain-name.local none bind 0 0
ææè
/var/www/domain-name.localãè¿œå ããŸã
chown www-data:domain-name /var/www/domain-name.local/ -R
æš©å©ãå²ãåœãŠã
find /var/www/domain-name.local -type d -exec chmod 775 {} \;
find /var/www/domain-name.local -type f -exec chmod 664 {} \;
vsftpdãå®è¡ããŸã
service vsftpd start
ãã§ãã¯ãFileZillaã䜿çšããŸãã
ãã¹ãŠé 調ã§ãããã£ã¬ã¯ããªãäœæããŠã¿ãŠãã ããã
åäœããŸãã
å®å
šãªFTPæ¥ç¶ãèšå®ããŸãã
vsftpdãåæ¢ããŸã
service vsftpd stop
蚌ææžãçæããŸã
openssl req -x509 -nodes -days 720 -newkey rsa:2048 -keyout /etc/ssl/private/vsftpd.key -out /etc/ssl/private/vsftpd.pem
ããã§ã¯ãããªãã®éãæããã¹ãŠã玹ä»ããŸã
åœåïŒ2æåã®ã³ãŒãïŒ[AU]ïŒ
å·ãŸãã¯çã®ååïŒãã«ããŒã ïŒ[äžéšã®å·]ïŒ
å°ååïŒäŸïŒéœåžïŒ[]ïŒ
çµç¹åïŒäŒç€Ÿãªã©ïŒ[Internet Widgits Pty Ltd]ïŒ
çµç¹åäœåïŒäŸãã»ã¯ã·ã§ã³ïŒ[]ïŒ
å
±éåïŒãµãŒããŒFQDNãŸãã¯ããªãã®ååãªã©ïŒ[]ïŒ
ã¡ãŒã«ã¢ãã¬ã¹[]ïŒ
etc / vsftpd.confãéã
nano etc/vsftpd.conf
以äžã®ãã©ã¡ãŒã¿ãŒãèšå®/è¿œå ããŸãã
- ssl_enable = YES
- ssl_tlsv1 =ã¯ã
- ssl_sslv2 = NO
- ssl_sslv3 = NO
- rsa_cert_file = / etc / ssl / private / vsftpd.pem
- rsa_private_key_file = / etc / ssl / private / vsftpd.key
- allow_anon_ssl = NO
- force_local_data_ssl = YES
- force_local_logins_ssl = YES
- ssl_ciphers = HIGH
vsftpdãä¿åããŠå®è¡ãã
service vsftpd start
ãã£ãŠã¿ãŸããã
ããããããã¹ãŠãæ©èœããWebã¢ããªã±ãŒã·ã§ã³ã®éçºãå§ããããšãã§ããŸãã
PSãã®ã¬ã·ãã¯ãå¯äžã®æ£ç¢ºãã€çæ³çãªãã®ã§ã¯ãããŸããã ããªããäœããèŠéãããããã®ã¬ã·ããè£ãããã®ææ¡ãããã°ãã³ã¡ã³ããæè¿ããŸããç§ã¯ã©ããªæ¹å€ãåãå
¥ããŸãã ç§ã®ã¹ãã«ãæé·ããã«ã€ããŠããã®ã¬ã·ãã¯è£è¶³ããä¿®æ£ãããŸãã