Skip to main content

Automate certificate management for Apache servers on Linux

Use DigiCert​​®​​ Trust Lifecycle Manager to automate certificate management for Apache web servers running on Linux. This guide describes how to set up agent-based automation and manage certificates on your Apache server.

After you install the DigiCert agent, Trust Lifecycle Manager discovers the Apache endpoints on the server. Depending on how Apache is configured, you may need to configure some endpoints manually. You then create a certificate profile for enrollment and configure automation to install a certificate on an unsecured endpoint or replace an existing certificate. From the inventory, you can continue to track and manage these certificates throughout their lifecycle.

Before you begin

DigiCert prerequisites

  • Make sure Trust Lifecycle Manager can access the certificate authority (CA) that issues your TLS server certificates.

    • DigiCert-hosted Private CA is available by default.

    • Other CAs require a CA connector.

  • Ensure that the Linux server meets the system and network requirements for installing and running the DigiCert agent. For more information, see DigiCert agent system requirements.

  • (Optional) To automate domain control validation (DCV) for certificates issued from CertCentral or Let's Encrypt, configure a DNS integration to use for DNS-based challenges. For more information, see DNS 統合.

Apache prerequisites

  • Verify that your Apache version and operating system are supported. See サポートされるシステム.

  • Verify that your Apache configuration meets these requirements:

    • Websites use VirtualHost configuration blocks.

    • Apache is configured to work with TLS certificates.

Set up agent-based automation

Install and activate the DigiCert agent, and then create a certificate profile to prepare your Apache endpoints for certificate automation.

Linux 版エージェントソフトウェアをダウンロードして Trust Lifecycle Manager でアクティベーションキーを生成するには、以下の手順に従います。

  1. Trust Lifecycle Manager メインメニューから、[Discovery & automation tools > Client tools]を選択します。

  2. [エージェント - Linux インストーラ]を選択します。

  3. 右側にあるダウンロードボタンを使用して LInux 版 DigiCert エージェントインストーラの最新バージョンをダウンロードします。インストーラは tlm_agent_N.N.N_linux64.tar.gz といった名前になっているはずです。ここで、「N.N.N」はエージェントのバージョン番号です。

  4. アクティベーションコードを取得するには、[Requirements]の下にある[アクティベーションコードの生成]ボタンを選択します。開かれたポップアップダイアログで、次の操作を実行します。

    1. (任意)エージェントを割り当てる事業部門を選択します。ここで選択した場合、その事業部門に管理者として割り当てられたユーザーだけがエージェントを管理できるようになります。

    2. (任意)[コードの共有]で、アクティベーションコードを電子メールで受け取るユーザーを選択します。たとえば、エージェントソフトウェアをインストールする管理者を選択します。

    3. [コードの生成]ボタンを選択します。コードをコピーします。このコードを使用してエージェントをインストールすることも、インストールを実行するユーザーにコードを提供することもできます。

    注記

    アクティベーションコードは 30 分間有効で、1 回だけ使用できます。有効期限が切れた場合は、プロセスを繰り返して新しいコードを生成します。

重要

問題を回避するため、デジサートは、エージェントソフトウェアを Linux の /opt ディレクトリにインストールすることを推奨します。エージェントを /tmp ディレクトリまたはユーザーのホームディレクトリにインストールしないでください。

Linux サーバーにエージェントソフトウェアをインストールしてアクティブ化するには、以下の手順に従います。

  1. ダウンロードしたインストーラアーカイブを /opt ディレクトリ、または DigiCert エージェントのインストール先とするディレクトリにコピーします。

  2. インストーラアーカイブを解凍します(例: tar -xzvf <agent-file>.tar.gz)。これにより、tlm_agent_N.N.N_linux64 といった名前のエージェントインストールディレクトリが作成されます。ここで、「N.N.N」はエージェントのバージョン番号です。

  3. エージェントインストールディレクトリに移動し、start-tlm-agent.sh をルートとして実行します(例: sudo ./start-tlm-agent.sh)。指示に従ってエージェントをインストールしてアクティブ化します。

  4. 入力を求められたら、生成したアクティベーションコードを入力します。

  5. 選択を求められたら、エージェントが Trust Lifecycle Manager に接続する方法を選択します。

    • [Direct, no proxy]: エージェントが直接接続する場合に選択します。

    • [My own proxy server]: サードパーティのプロキシサーバー経由で接続する場合に選択します。プロキシサーバーの詳細の入力を求められます。

    • [DigiCert sensor as proxy]: DigiCert センサーをプロキシサーバーとして使用する場合に選択します。センサーの詳細の入力を求められます。

      注記

      DigiCert センサーには、組み込みのフェイルオーバーサポートが含まれています。エージェントでは、プロキシとして使用するプライマリセンサーを構成するだけで十分です。ネットワークに DigiCert センサーが複数存在する場合、プロキシのプライマリセンサーに障害が発生すると、エージェントは自動的に別のセンサーに切り替わります。

  6. (任意)Trust Lifecycle Manager で識別しやすくなるように、エージェントにカスタム名を割り当てます。

Verify that the agent is connected to Trust Lifecycle Manager and has correctly identified the Apache endpoints you want to automate.

  1. From the Trust Lifecycle Manager menu, select Discovery & automation tools > Agents.

  2. Verify that the agent you installed is listed in the table.

  3. Select the agent and verify the following:

    • On the General information tab, the Apache endpoint shows the correct application and application version.

    • On the IP/port targets tab, verify that the application and application version for each Apache port you want to automate is accurate. If the Apache version is incorrect, edit the agent and select the application and application version for each port.

    • The Automation options tab lists additional automation-related settings. If your web server uses Server Name Indication (SNI) to host certificates for different domains on a single IP/port, edit the agent and enable SNI here so the agent can discover and automate the SNI certificates. To learn more, see Server Name Indication.

The agent is now ready to manage certificates on the Apache endpoints.

Create a certificate profile for requesting and managing certificates on Apache endpoints by using an agent.

  1. From the Trust Lifecycle Manager main menu, go to Policies > Certificate profiles.

  2. Select Create profile from template.

  3. Select a base template that supports managed automation.

    To find base templates that support managed automation, look for End-to-end certificate automation in the Use cases column on the Policies > Base templates page. Available templates include those in the following table.

  4. Configure the following options in the Create certificate profile wizard.

    注記

    The screens and options available in the wizard depend on the certificate template you started with.

    • Enter a name for the profile.

    • Select DigiCert agent as the enrollment method for requesting certificates from this profile.

    • Configure the following optional settings as needed:

      • Select Auto-renew certificate to automatically renew certificates issued from the profile before they expire.

      • Assign tags and select certificate owners who should receive notifications for all certificates issued from the profile.

    For more details on creating a certificate profile, see プロファイル構成ウィザードの使用.

  5. Select Next to continue through the wizard, or select Back to return to previous screens and make changes.

  6. Select Create to create the certificate profile.

The certificate profile is now available for certificate automation requests from your Apache endpoints.

Install a certificate on an unsecured Apache endpoint

To request and install a certificate on an unsecured Apache endpoint:

  1. From the Trust Lifecycle Manager main menu, select Discovery & automation tools > Agents.

  2. Select the agent that you installed from the table.

  3. Select Unsecured IP/ports. This opens the Unsecured system view in the inventory, pre-filtered to show endpoints managed by this agent.

  4. Find the endpoint where you want to install the certificate.

  5. In the rightmost column of the table, select the certificate icon (Request certificate).

  6. Complete the Automation request form:

    • Choose profile: Select the certificate profile that you created.

    • Certificate information: Add the common name, Subject Alternative Name (SAN) attributes, and any additional order options for the certificate.

    • Make any additional selections based on the certificate profile you selected and common name you entered. For example:

      • Specify whether to include both the base domain (example.com) and its www domain (www.example.com) in the certificate.

      • For wildcard certificates, specify whether to install the certificate on virtual hosts that match the base domain or only hosts that exactly match the wildcard pattern.

    • Configure scheduling, auto-renewal, agent scripts, certificate owners, and tags as needed.

    • Select the checkbox at the end of the form to acknowledge acceptance of the Certificate Services Agreement.

  7. Select Submit.

The certificate is issued and installed on the Apache endpoint.

Replace the existing certificate on an Apache endpoint

To replace an existing certificate on an Apache endpoint:

  1. From the Trust Lifecycle Manager main menu, select Discovery & automation tools > Agents.

  2. Select the DigiCert agent that's running on the target web server.

  3. Select Managed certificates. This opens the Automated system view in the inventory, pre-filtered to show endpoints managed by this agent.

  4. Find the endpoint where you want to replace the existing certificate.

  5. In the rightmost column of the table, select the certificate icon (Request certificate).

  6. Complete the Automation request form:

    • Choose profile: Select the certificate profile that you created.

    • Certificate information: Add the common name, Subject Alternative Name (SAN) attributes, and any additional order options for the certificate.

    • Make any additional selections based on the certificate profile you selected and common name you entered. For example:

      • Specify whether to include both the base domain (example.com) and its www domain (www.example.com) in the certificate.

      • For wildcard certificates, specify whether to install the certificate on virtual hosts that match the base domain or only hosts that exactly match the wildcard pattern.

    • Configure scheduling, auto-renewal, agent scripts, certificate owners, and tags as needed.

    • Select the checkbox at the end of the form to acknowledge acceptance of the Certificate Services Agreement.

  7. Select Submit.

The new certificate is issued and installed on the Apache endpoint, replacing the existing certificate.

注記

You can follow the same workflow to perform other certificate management actions, such as renewing or reissuing a certificate. For details, see Manage endpoints.

View and manage automated certificates