
本プロキシサーバソフトウェアにてSMTP/POP3 Over SSLを利用するための可能にするには、以下の手順にて設定を行います。

  1. 「公開鍵証明書」と「秘密鍵」を作成する。
  2. 「公開鍵証明書」と「秘密鍵」を本プロキシサーバソフトウェアに設定する。
    利用可能な証明書としてジオトラスト クイックSSL プレミアムグローバルサイン クイック認証SSLなどが、2009.07現在存在します。



     openssl req -config openssl.cnf -new -nodes -keyout cakey.pem -x509 -out cacert.pem

     Using configuration from openssl.cnf
     Loading 'screen' into random state - done
     Generating a 512 bit RSA private key
     writing new private key to 'key.pem'
     You are about to be asked to enter information that will be incorporated
     into your certificate request.
     What you are about to enter is what is called a Distinguished Name or a DN.
     There are quite a few fields but you can leave some blank
     For some fields there will be a default value,
     If you enter '.', the field will be left blank.
     Country Name (2 letter code) [AU]:JP
     State or Province Name (full name) [Some-State]:Saitama
     Locality Name (eg, city) []:Kasukabe-shi
     Organization Name (eg, company) [Internet Widgits Pty Ltd]:K-TEC
     Organizational Unit Name (eg, section) []:Postmaster
     Common Name (eg, YOUR name) []:mail.ktinc.jp
     Email Address []:

     openssl req -config openssl.cnf -new -nodes -newkey rsa:512 -keyout mykey.pem -out myreq.pem

     Using configuration from openssl.cnf
     Loading 'screen' into random state - done
     Generating a 512 bit RSA private key
     writing new private key to 'mykey.pem'
     You are about to be asked to enter information that will be incorporated
     into your certificate request.
     What you are about to enter is what is called a Distinguished Name or a DN.
     There are quite a few fields but you can leave some blank
     For some fields there will be a default value,
     If you enter '.', the field will be left blank.
     Country Name (2 letter code) [AU]:JP
     State or Province Name (full name) [Some-State]:Saitama
     Locality Name (eg, city) []:Kasukabe-shi
     Organization Name (eg, company) [Internet Widgits Pty Ltd]:K-TEC
     Organizational Unit Name (eg, section) []:Postmaster
     Common Name (eg, YOUR name) []:mail.ktinc.jp
     Email Address []:

     Please enter the following 'extra' attributes
     to be sent with your certificate request
     A challenge password []:
     An optional company name []:

     openssl ca -config openssl.cnf -in myreq.pem -keyfile cakey.pem -cert cacert.pem -out mycert.pem

     Using configuration from openssl.cnf
     Loading 'screen' into random state - done
     Check that the request matches the signature
     Signature ok
     The Subjects Distinguished Name is as follows
     countryName :PRINTABLE:'JP'
     stateOrProvinceName :PRINTABLE:'Saitama'
     localityName :PRINTABLE:'Kasukabe-shi'
     organizationName :PRINTABLE:'K-TEC'
     commonName :PRINTABLE:'mail.ktinc.jp'
     Certificate is to be certified until May 6 00:29:27 2003 GMT (365 days)
     Sign the certificate? [y/n]:y

     1 out of 1 certificate requests certified, commit? [y/n]y
     Write out database with 1 new entries
     Data Base Updated


     mycert.pem ---- 公開鍵証明書ファイル
     mykey.pem ---- 秘密鍵ファイル

<Prev                                             Next>