業務用エアコン関連の技術情報、エラーコード、環境問題対策に関する別サイト「エアコンの安全な修理・適切なフロン回収」

RockyLinux10.2 : SSL Certificate ( Let's Encrypt ) , Apache/Mail SSL

1.Obtain an SSL certificate ( Let's Encrypt )

Install the latest open ssl

# dnf install openssl-devel

1.1 advance preparation

1.Package management system Snappy installed
Since the SSL certificate issuing tool "certbot" of Let's Encrypt is recommended to be installed using "snap" after 2021, install Snapd first.(Can also be installed the traditional way with dnf or yum)

# dnf install epel-release
# dnf upgrade
# dnf -y install snapd

Enable systemd unit to manage the main snap communication socket

# systemctl enable --now snapd.socket

Enable Classics Snap support

# ln -s /var/lib/snapd/snap /snap

Bring snapd version up to date

# snap install core

If the above fails, run the following command instead (the core package will be installed along with the package called hello-world)

# snap install hello-world

Update core package

# snap refresh core

Version Check

# snap --version
snap          2.72-1.el10_2
snapd         2.72-1.el10_2
series        16
rocky         10.2
kernel        6.12.0-211.16.1.el10_2.0.1.x86_64
architecture  amd64

Log out and log in again or reboot the system to ensure that the snap path is updated correctly

2.certbot package install

# snap install --classic certbot
certbot 5.6.0 from Certbot Project (certbot-eff✓) installed

Create symbolic link to /snap/bin/certbot

# ln -s /snap/bin/certbot /usr/bin/certbot

Confirmation

# ls -la /usr/bin/certbot
lrwxrwxrwx 1 root root 17 Nov 30 17:07 /usr/bin/certbot -> /snap/bin/certbot

# ls -la /snap/bin/certbot
lrwxrwxrwx 1 root root 13 Nov 30 17:06 /snap/bin/certbot -> /usr/bin/snap

1.2 Obtaining Certificates

# certbot certonly --webroot -w /var/www/html/[FQDN] -d [FQDN]

Registration of e-mail address and agreement to terms of use are required for the first time only.
Specify an email address to receive

Saving debug log to /var/log/letsencrypt/letsencrypt.log
Enter email address (used for urgent renewal and security notices)
 (Enter 'c' to cancel): <Administrator e-mail address>

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Please read the Terms of Service at

404 Page not found
Let's Encrypt is a free, automated, and open Certificate Aut...
You must agree in order to register with the ACME server. Do you agree? - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: y - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Would you be willing, once your first certificate is successfully issued, to share your email address with the Electronic Frontier Foundation, a founding partner of the Let's Encrypt project and the non-profit organization that develops Certbot? We'd like to send you email about our work encrypting the web, EFF news, campaigns, and ways to support digital freedom. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - (Y)es/(N)o: y Account registered. Requesting a certificate for [FQDN] Successfully received certificate. Certificate is saved at: /etc/letsencrypt/live/[FQDN]/fullchain.pem Key is saved at: /etc/letsencrypt/live/[FQDN]/privkey.pem This certificate expires on 2026-09-01. These files will be updated when the certificate renews. Certbot has set up a scheduled task to automatically renew this certificate in the background. We were unable to subscribe you the EFF mailing list because your e-mail address appears to be invalid. You can try again later by visiting https://act.eff.org. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - If you like Certbot, please consider supporting our work by: * Donating to ISRG / Let's Encrypt: https://letsencrypt.org/donate * Donating to EFF: https://eff.org/donate-le - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Success if displayed"Successfully received certificate".
The following certificate is obtained under [/etc/letsencrypt/live/<FQDN>/] as described in the message
cert.pem ⇒ SSL server certificate (including public key)
chain.pem ⇒ intermediate certificate
fullchain.pem ⇒ File containing cert.pem and chain.pem combined
privkey.pem ⇒ private key

※ Obtaining a Let's Encrypt certificate when the web server is not running

It is a prerequisite that the server on which the work is to be performed is accessible from the Internet at port 80.
 ・ Use the simple Web server function by specifying [--standalone].
 ・d [FQDN for which you wish to obtain a certificate]# FQDN (Fully Qualified Domain Name) : Hostname.Domain name written without omission
 ・If you have multiple FQDNs for which you want to obtain certificates, specify them multiple times using -d [FQDNs for which you want to obtain certificates].

# certbot certonly --standalone -d <FQDN>

Renewing certificates already obtained
 ・Renew all certificates with an expiration date of less than 30 days
 ・If you want to renew regardless of the number of days remaining on the expiration date, specify [--force-renewal] as well.

# certbot [--force-renewal] renew

1.2 Automatic renewal of certificates(Let's Encrypt)

Pre-registration testing
First, test the automatic update using the following --dry-run option.
With this option, certificates are not renewed, only checked, so there is no need to worry about getting stuck with a limit on the number of times a certificate can be obtained.

# certbot renew --dry-run

Saving debug log to /var/log/letsencrypt/letsencrypt.log

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Processing /etc/letsencrypt/renewal/[FQDN].conf
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Account registered.
Simulating renewal of an existing certificate for [FQDN]

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Congratulations, all simulated renewals succeeded:
  /etc/letsencrypt/live/[FQDN]/fullchain.pem (success)
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

When you install the snap version of certbot, the automatic certificate renewal function is also installed.

# systemctl list-timers | less

NEXT                            LEFT LAST                              PASSED UNIT               
          ACTIVATES
Wed 2026-06-03 12:58:00 JST 4min 41s Wed 2026-06-03 12:28:01 JST    25min ago pmie_check.timer             pmie_check.service
Wed 2026-06-03 12:58:10 JST 4min 51s Wed 2026-06-03 12:28:11 JST    25min ago pmie_farm_check.timer        pmie_farm_check.service
Wed 2026-06-03 13:00:00 JST     6min Wed 2026-06-03 12:50:03 JST 3min 15s ago sysstat-collect.timer        sysstat-collect.service
Wed 2026-06-03 13:20:00 JST    26min Wed 2026-06-03 12:50:03 JST 3min 15s ago pmlogger_check.timer         pmlogger_check.service
Wed 2026-06-03 13:20:10 JST    26min Wed 2026-06-03 12:50:13 JST  3min 5s ago pmlogger_farm_check.timer    pmlogger_farm_check.service
Wed 2026-06-03 13:33:06 JST    39min Wed 2026-06-03 11:47:46 JST  1h 5min ago dnf-makecache.timer          dnf-makecache.service
Wed 2026-06-03 14:54:00 JST  2h 0min -                                      - snap.certbot.renew.timer     snap.certbot.renew.service
Thu 2026-06-04 00:00:00 JST      11h -                                      - sa-update.timer              sa-update.service
Thu 2026-06-04 00:00:00 JST      11h -                                      - sysstat-rotate.timer         sysstat-rotate.service
Thu 2026-06-04 00:00:00 JST      11h Wed 2026-06-03 08:47:10 JST  4h 6min ago unbound-anchor.timer         unbound-anchor.service
Thu 2026-06-04 00:07:00 JST      11h -                                      - sysstat-summary.timer        sysstat-summary.service
Thu 2026-06-04 00:08:00 JST      11h Wed 2026-06-03 08:47:22 JST  4h 5min ago pmie_daily.timer             pmie_daily.service
Thu 2026-06-04 00:10:00 JST      11h Wed 2026-06-03 08:47:22 JST  4h 5min ago pmlogger_daily.timer         pmlogger_daily.service
Thu 2026-06-04 00:16:22 JST      11h Wed 2026-06-03 08:57:38 JST 3h 55min ago plocate-updatedb.timer       plocate-updatedb.service
Thu 2026-06-04 00:45:25 JST      11h Wed 2026-06-03 08:57:38 JST 3h 55min ago logrotate.timer              logrotate.service
Thu 2026-06-04 09:01:54 JST      20h Wed 2026-06-03 09:01:54 JST 3h 51min ago systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service

snap.certbot.renew.timer is registered

Check the unit file snap.certbot.renew.timer

# vi /etc/systemd/system/snap.certbot.renew.timer

[Unit]
# Auto-generated, DO NOT EDIT
Description=Timer renew for snap application certbot.renew
Requires=var-lib-snapd-snap-certbot-5603.mount
After=var-lib-snapd-snap-certbot-5603.mount
X-Snappy=yes

[Timer]
Unit=snap.certbot.renew.service
OnCalendar=*-*-* 02:45
OnCalendar=*-*-* 14:54

[Install]
WantedBy=timers.target

According to the above settings, updates will be attempted at 2:45 and 14:54 daily as specified by the OnCalendar parameter (however, the set time will change randomly for each update).

Check the unit file snap.certbot.renew.service

# vi /etc/systemd/system/snap.certbot.renew.service

[Unit]
# Auto-generated, DO NOT EDIT
Description=Service for snap application certbot.renew
Requires=var-lib-snapd-snap-certbot-5603.mount
Wants=network.target
After=var-lib-snapd-snap-certbot-5603.mount network.target snapd.apparmor.service
X-Snappy=yes

[Service]
EnvironmentFile=-/etc/environment
ExecStart=/usr/bin/snap run --timer="00:00~24:00/2" certbot.renew
SyslogIdentifier=certbot.renew
Restart=no
WorkingDirectory=/var/snap/certbot/5603
TimeoutStopSec=30
Type=oneshot

However, the web server using the certificate will not be restarted, so set up a script to run automatically after the update

# vi /etc/letsencrypt/renewal-hooks/post/web_restart.sh

Please describe the following
#!/bin/bash
systemctl reload httpd
# chmod 755 /etc/letsencrypt/renewal-hooks/post/web_restart.sh

2. Converting Apache to https

Install the following just in case

# dnf -y install mod_ssl

2.1 Edit ssl.conf file

# vi /etc/httpd/conf.d/ssl.conf

Line 43 : Uncomment and change
DocumentRoot "/var/www/html/<FQDN>"

Line 44 : Uncomment and change
ServerName <FQDN>:443

Line 85 : Make it a comment and add it below
# SSLCertificateFile /etc/pki/tls/certs/localhost.crt
SSLCertificateFile /etc/letsencrypt/live/<FQDN>/cert.pem

Line 93 : Make it a comment and add it below
# SSLCertificateKeyFile /etc/pki/tls/private/localhost.key
SSLCertificateKeyFile /etc/letsencrypt/live/<FQDN>/privkey.pem

Line 103 : Add
SSLCertificateChainFile /etc/letsencrypt/live/<FQDN>/chain.pem

Restart Apache.

# systemctl restart httpd

Allow https in Firewall

# firewall-cmd --add-service=https --permanent
# firewall-cmd --reload

2.2 Redirect HTTP communications to HTTPS

Add to the virtual host configuration file

# vi /etc/httpd/conf.d/vhost.conf

<VirtualHost *:80>
Add the following three lines
RewriteEngine On
RewriteCond %{HTTPS} off
RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [R=301,L]
DocumentRoot /var/www/html/[FQDN]
ServerName [FQDN]
ServerAdmin [mail address]
ErrorLog logs/[FQDN].error_log
CustomLog logs/[FQDN].access_log combined
</VirtualHost>

<Directory "/var/www/html/[FQDN]">
Options FollowSymLinks
AllowOverride All
</Directory>

Restart Apache

# systemctl restart httpd

3. SSL/TLS (Let's Encrypt) settings on the mail server

3.1 Obtaining a certificate for the mail server

Obtain a certificate for the mail server
Since it cannot be obtained using the same method as above, adding the "--standalone" option as shown below also fails.

# certbot certonly --standalone -d mail.<domain name>

If I stop the web server once and then do it, it succeeds as follows

# systemctl stop httpd.service
# certbot certonly --standalone -d mail.<domain name>
Saving debug log to /var/log/letsencrypt/letsencrypt.log
Requesting a certificate for mail.&lt;Domain name>

Successfully received certificate.
Certificate is saved at: /etc/letsencrypt/live/mail.&lt;Domain name>/fullchain.pem
Key is saved at:         /etc/letsencrypt/live/mail.&lt;Domain name>/privkey.pem
This certificate expires on 2026-09-01.
These files will be updated when the certificate renews.
Certbot has set up a scheduled task to automatically renew this certificate in the background.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
If you like Certbot, please consider supporting our work by:
 * Donating to ISRG / Let's Encrypt:   https://letsencrypt.org/donate
 * Donating to EFF:                    https://eff.org/donate-le
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

3.2 Postfix Configuration

# vi /etc/postfix/main.cf

Lines 718 and 724: Commented out
#smtpd_tls_cert_file = /etc/pki/tls/certs/postfix.pem
#smtpd_tls_key_file = /etc/pki/tls/private/postfix.key

Add to the last line
smtpd_use_tls = yes
smtp_tls_mandatory_protocols = !SSLv2, !SSLv3
smtpd_tls_mandatory_protocols = !SSLv2, !SSLv3
smtpd_tls_cert_file = /etc/letsencrypt/live/mail.<domain name>/fullchain.pem
smtpd_tls_key_file = /etc/letsencrypt/live/mail.<domain name>/privkey.pem
smtpd_tls_session_cache_database = btree:${data_directory}/smtpd_scache
# vi /etc/postfix/master.cf

Line 19,20,22 : Uncomment
submission inet n       -       n       -       -       smtpd
    -o syslog_name=postfix/submission
#  -o smtpd_tls_security_level=encrypt
    -o smtpd_sasl_auth_enable=yes
#  -o smtpd_tls_auth_only=yes

Lines 38-41: Uncomment
submissions     inet  n       -       n       -       -       smtpd
  -o syslog_name=postfix/submissions
  -o smtpd_tls_wrappermode=yes
  -o smtpd_sasl_auth_enable=yes
#  -o local_header_rewrite_clients=static:all
#  -o smtpd_reject_unlisted_recipient=no

3.3 Dovecot Settings

# vi /etc/dovecot/conf.d/10-ssl.conf

Line 8:confirmation
ssl = yes

Line 14,15:Make it a comment and add certificate/key file designation under it
ssl_cert = </etc/letsencrypt/live/mail.<domain name>/fullchain.pem
ssl_key = </etc/letsencrypt/live/mail.<domain name>/privkey.pem

Allow Port 587 in firewall

# firewall-cmd --add-port=587/tcp --permanent
# firewall-cmd --reload
# systemctl restart postfix dovecot

3.4 Thunderbird Settings

Receiving servers
Port  :  143
Connection security   :  STARTTLS
Authentication method  :  Normal password

Sending server
Port   :  587
Connection security   :  STARTTLS
Authentication method  :  Normal password