๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
์„œ๋ฒ„/AWS

EC2 nginx ์„ค์น˜ ๋ฐ ํ†ฐ์บฃ์—ฐ๋™

by yunamom 2022. 1. 26.
728x90
300x250

http -> https ๋กœ ๋ณ€๊ฒฝํ•˜๊ธฐ์œ„ํ•œ ๊ณผ์ •์„ ์Šค์Šค๋กœ ๊ธฐ์–ตํ•˜๊ธฐ์œ„ํ•ด ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค.

*๋ณธ๊ธ€์—๋Š” AWS ๊ฐ€์ž… ๋ฐ ec2 ์„ค์ • ํ†ฐ์บฃ ์„ค์น˜ ํ†ฐ์บฃ ํ™˜๊ฒฝ๋ณ€์ˆ˜ ๋Š” ์ƒ๋žตํ•ฉ๋‹ˆ๋‹ค.


$sudo apt-get --purge remove nginx-*

๊ธฐ์กด์— ์„ค์น˜ํ–ˆ๋˜ nginx ๋ฅผ ์‚ญ์ œํ•ด์ฃผ์—ˆ๋‹ค.

 
$sudo apt install nginxโ€‹

 

nginx ๋‹ค์‹œ์„ค์น˜

Do you want to countinue? [Y/n]    y
 

์„ค์น˜ ์™„๋ฃŒํ›„

$cd /etc/nginx/sites-available

sites-available ํด๋”๋กœ ์ด๋™

 
$sudo touch tomcat.conf

tomcat.conf ํŒŒ์ผ์„ ์ƒ์„ฑํ•ด์ค€๋‹ค.

 

$sudo vi tomcat.conf

tomcat.conf ํŒŒ์ผ์„ ์—ด์–ด ์ž‘์„ฑํ•ด์ฃผ์ž

์„œ๋ฒ„์— ์ ‘์†ํ• ๋•Œ ์‚ฌ์šฉํ•œ public ip ๊ฐ€ ์•„๋‹Œ! *๊ผญ private ip ๋ฅผ ์ ์–ด์ฃผ์ž

๋ณธ์ธ์€ ์ด๊ฑธ ๋ชฐ๋ผ์„œ ์• ๊ฟŽ์€ nginx ์ง€์› ๋‹ค ์„ค์น˜ํ–ˆ๋‹ค ์‚ฝ์งˆํ•จ..ใ… ใ… ํ—ˆํ—ˆ

๋„๋ฉ”์ธ์ฃผ์†Œ๊ฐ€ ์žˆ๋Š”๊ฒฝ์šฐ ์„œ๋ฒ„๋„ค์ž„์— ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•ด์ฃผ๋ฉด๋œ๋‹ค.

* AWS ec2 ์ธ์Šคํ„ด์Šค ํด๋ฆญํ•˜๋ฉด private ip ๋ฅผ ํ™•์ธํ• ์ˆ˜์žˆ๋‹ค.

์ž‘์„ฑํ•œ๋’ค :wq ์ €์žฅํ›„ ๋‚˜์˜จ๋‹ค.

 

$sudo ln -s /etc/nginx/sites-available/tomcat.conf  /etc/nginx/sites-enabled/

๊ทธ๋’ค ํŒŒ์ผ์„ ์ ์šฉํ•ด์ฃผ์ž 

 
$sudo service nginx restart
 
๋‹ค์‹œ์‹œ์ž‘
 
 
$sudo apt install certbot python3-certbot-nginx

certbot ์„ ๊น”์•„์ฃผ์ž 

* certbot ์ด๋ž€?

SSL ์ธ์ฆ์„œ๋ฅผ ๋ฐœ๊ธ‰ ๋ฐ ๊ฐฑ์‹ ํ•ด์ฃผ๋Š” ์•„์ฃผ ๋˜‘๋˜‘์ด ํ”„๋กœ๊ทธ๋žจ์ž…๋‹ˆ๋‹ค.

 

* SSL ์ด๋ž€???

SSL์€ Secure Sockets Layer์˜ ์•ฝ์ž์ž…๋‹ˆ๋‹ค. ํ’€์ดํ•˜์ž๋ฉด ์ธํ„ฐ๋„ท์˜ ๋‚ด์šฉ์„ ์•”ํ˜ธํ™” ํ•ด์ฃผ๋Š” ํ”„๋กœํ† ์ฝœ(๊ทœ์น™)์ž…๋‹ˆ๋‹ค.

SSL์ธ์ฆ์„œ๋Š” ์ด๋Ÿฐ ๋ณด์•ˆํ†ต์‹ ์„ ํ•˜๊ธฐ ์œ„ํ•œ ์ „์ž ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.

SSL์ธ์ฆ์„œ๋ฅผ ์„œ๋ฒ„์— ์„ค์น˜ํ•จ์œผ๋กœ์จ SSL ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ณด์•ˆ ํ†ต์‹ ์„ ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๋Š”๊ฒƒ! ์ด๋ผ๊ณ  ์•Œ์•„๋‘ก์‹œ๋‹ค.

์ž์„ธํ•œ ์„ค๋ช…์€ ์•„๋ž˜ ๋งํฌ์—์„œ ํ™•์ธํ•˜์‹ค์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค :D

https://yunamom.tistory.com/66

 

 

SSL ์ธ์ฆ์„œ๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”?

๊ฐœ์š” SSL์€ Secure Sockets Layer ์˜ ์•ฝ์ž์ž…๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท์„ ํ•  ๋•Œ ์™”๋‹ค๊ฐ”๋‹ค ํ•˜๋Š” ๋‚ด์šฉ์„ ์•”ํ˜ธํ™” ํ•ด์ฃผ๋Š” ํ”„๋กœํ† ์ฝœ(๊ทœ์น™) ์ž…๋‹ˆ๋‹ค. SSL ์ธ์ฆ์„œ๋ž€ ์ด๋Ÿฐ ๋ณด์•ˆํ†ต์‹ ์„ ํ•˜๊ธฐ ์œ„ํ•œ ์ „์ž ํŒŒ์ผ์ž…๋‹ˆ๋‹ค. SSL ์ธ์ฆ์„œ๋ฅผ

yunamom.tistory.com

 

 
$sudo certbot --nginx -d ๋„๋ฉ”์ธ์ฃผ์†Œ

certbot ์„ ์„ค์น˜ํ•˜๊ณ  ๋ณธ์ธ์˜ ๋„๋ฉ”์ธ ์ฃผ์†Œ๋ฅผ ์ž…๋ ฅํ•˜์ž

์™„๋ฃŒ :D

https ๋กœ ์ž˜์ ์šฉ๋œ๊ฒƒ์„ ํ™•์ธํ• ์ˆ˜์žˆ๋‹ค. ใ…Žใ…Ž

๋งˆ๋ฌด๋ฆฌ๋กœ ํ˜น์‹œ๋ผ๋„.. ์ด๊ฑธ๋ณด๊ณ  ๋”ฐ๋ผํ• ๋ถ„์ด ๊ณ„์‹œ๋‹ค๋ฉด

AWS EC@ security(๋ณด์•ˆ) -> security group ์—์„œ 8080ํฌํŠธ 80ํฌํŠธ ์ถ”๊ฐ€ํ•ด์ฃผ์…”์•ผํ•ฉ๋‹ˆ๋‹ค.์ค‘์š”

 

 

 

 

 

728x90
300x250

์ฝ”๋“œ