{"id":35447,"date":"2025-11-29T21:40:43","date_gmt":"2025-11-29T18:40:43","guid":{"rendered":"https:\/\/fatihsoysal.com\/blog\/?p=35447"},"modified":"2025-11-29T21:40:43","modified_gmt":"2025-11-29T18:40:43","slug":"apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme","status":"publish","type":"post","link":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/","title":{"rendered":"Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme"},"content":{"rendered":"<p><body><\/p>\n<h2>Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme<\/h2>\n<h3>Giri\u015f<\/h3>\n<p>G\u00fcn\u00fcm\u00fcz\u00fcn dijital d\u00fcnyas\u0131nda, web sitelerinin g\u00fcvenli\u011fi hi\u00e7 bu kadar kritik olmam\u0131\u015ft\u0131. Kullan\u0131c\u0131 verilerinin korunmas\u0131, veri b\u00fct\u00fcnl\u00fc\u011f\u00fcn\u00fcn sa\u011flanmas\u0131 ve arama motoru s\u0131ralamalar\u0131nda avantaj elde edilmesi i\u00e7in HTTPS (Hypertext Transfer Protocol Secure) kullan\u0131m\u0131 bir standart haline gelmi\u015ftir. HTTPS, HTTP protokol\u00fcn\u00fcn SSL\/TLS (Secure Sockets Layer\/Transport Layer Security) \u015fifrelemesi ile birle\u015ftirilmi\u015f halidir. Bu sayede, taray\u0131c\u0131 ile web sunucusu aras\u0131ndaki t\u00fcm ileti\u015fim \u015fifrelenir ve yetkisiz eri\u015fime kar\u015f\u0131 korunur.<\/p>\n<p>Apache HTTP Sunucusu, d\u00fcnya genelinde en yayg\u0131n kullan\u0131lan web sunucular\u0131ndan biridir. Esnekli\u011fi, g\u00fc\u00e7l\u00fc \u00f6zellikleri ve geni\u015f topluluk deste\u011fi sayesinde bir\u00e7ok web sitesi ve uygulaman\u0131n temelini olu\u015fturur. Ubuntu ise, sunucu ortamlar\u0131nda s\u0131k\u00e7a tercih edilen, kararl\u0131 ve g\u00fcvenilir bir Linux da\u011f\u0131t\u0131m\u0131d\u0131r. Ubuntu 16.04 LTS (Xenial Xerus), uzun s\u00fcreli destek sunan eski bir s\u00fcr\u00fcm olmas\u0131na ra\u011fmen, hala bir\u00e7ok \u00fcretim ortam\u0131nda kullan\u0131lmaktad\u0131r ve bu makale, bu \u00f6zel s\u00fcr\u00fcm \u00fczerinde Apache&#8217;yi Let&#8217;s Encrypt ile nas\u0131l g\u00fcvenli hale getirece\u011finizi ad\u0131m ad\u0131m a\u00e7\u0131klayacakt\u0131r.<\/p>\n<p>Let&#8217;s Encrypt, \u0130nternet G\u00fcvenlik Ara\u015ft\u0131rma Grubu (ISRG) taraf\u0131ndan i\u015fletilen, kar amac\u0131 g\u00fctmeyen \u00fccretsiz, otomatik ve a\u00e7\u0131k bir sertifika yetkilisidir (CA). Geleneksel SSL\/TLS sertifikalar\u0131n\u0131n y\u00fcksek maliyetleri ve karma\u015f\u0131k kurulum s\u00fcre\u00e7leri, bir\u00e7ok web sitesi sahibini HTTPS kullanmaktan al\u0131koyuyordu. Let&#8217;s Encrypt, bu engelleri ortadan kald\u0131rarak, herkesin web sitelerini \u00fccretsiz ve kolayca g\u00fcvenli hale getirmesini sa\u011flam\u0131\u015ft\u0131r. Certbot arac\u0131 sayesinde, sertifika alma ve yenileme s\u00fcre\u00e7leri tamamen otomatikle\u015ftirilebilir.<\/p>\n<p>Bu makalede, bir Ubuntu 16.04 sunucusu \u00fczerinde \u00e7al\u0131\u015fan Apache web sunucunuzu Let&#8217;s Encrypt&#8217;ten \u00fccretsiz bir SSL\/TLS sertifikas\u0131 kullanarak nas\u0131l g\u00fcvenli hale getirece\u011finizi ayr\u0131nt\u0131l\u0131 olarak ele alaca\u011f\u0131z. S\u00fcre\u00e7, Apache kurulumundan ba\u015flayarak, Certbot&#8217;un kurulumuna, sertifika edinimine ve otomatik yenileme yap\u0131land\u0131rmas\u0131na kadar t\u00fcm ad\u0131mlar\u0131 kapsayacakt\u0131r.<\/p>\n<h3>\u00d6n Ko\u015fullar<\/h3>\n<p>Bu rehbere ba\u015flamadan \u00f6nce a\u015fa\u011f\u0131daki \u00f6n ko\u015fullar\u0131n yerine getirildi\u011finden emin olmal\u0131s\u0131n\u0131z:<\/p>\n<p>*   <strong>Ubuntu 16.04 Sunucusu:<\/strong> Root veya sudo yetkilerine sahip bir Ubuntu 16.04 sunucusu.<br \/>\n*   <strong>Apache Kurulumu:<\/strong> Sunucunuzda Apache web sunucusu kurulu ve \u00e7al\u0131\u015f\u0131r durumda olmal\u0131d\u0131r.<br \/>\n*   <strong>Alan Ad\u0131:<\/strong> Sunucunuzun IP adresine i\u015faret eden kay\u0131tl\u0131 bir alan ad\u0131n\u0131z (\u00f6rn. <code>example.com<\/code>) olmal\u0131d\u0131r. Let&#8217;s Encrypt sertifikalar\u0131 IP adresleri i\u00e7in de\u011fil, alan adlar\u0131 i\u00e7in verilir.<br \/>\n*   <strong>DNS Kay\u0131tlar\u0131:<\/strong> Alan ad\u0131n\u0131z\u0131n A kayd\u0131n\u0131n (veya AAAA kayd\u0131n\u0131n, IPv6 kullan\u0131l\u0131yorsa) sunucunuzun genel IP adresini do\u011fru bir \u015fekilde i\u015faret etti\u011finden emin olun.<br \/>\n*   <strong>G\u00fcvenlik Duvar\u0131 (UFW):<\/strong> Sunucunuzda UFW (Uncomplicated Firewall) gibi bir g\u00fcvenlik duvar\u0131 etkinse, HTTP (80) ve HTTPS (443) portlar\u0131n\u0131n a\u00e7\u0131k oldu\u011fundan emin olun.<\/p>\n<h3>Apache Kurulumu ve Yap\u0131land\u0131rmas\u0131<\/h3>\n<p>E\u011fer Apache sunucunuz hen\u00fcz kurulu de\u011filse, a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izleyerek kurabilirsiniz. Zaten kuruluysa, bu b\u00f6l\u00fcm\u00fc atlayabilirsiniz.<\/p>\n<h4>Sistem G\u00fcncellemesi<\/h4>\n<p>\u00d6ncelikle, paket listenizi g\u00fcncelleyerek ve kurulu paketlerinizi y\u00fckselterek sisteminizin g\u00fcncel oldu\u011fundan emin olun:<\/p>\n<pre><code class=\"language-bash\">sudo apt update\nsudo apt upgrade -y<\/code><\/pre>\n<h4>Apache Kurulumu<\/h4>\n<p>Apache web sunucusunu kurmak i\u00e7in a\u015fa\u011f\u0131daki komutu kullan\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo apt install apache2 -y<\/code><\/pre>\n<h4>G\u00fcvenlik Duvar\u0131 Yap\u0131land\u0131rmas\u0131<\/h4>\n<p>Ubuntu&#8217;da varsay\u0131lan g\u00fcvenlik duvar\u0131 UFW&#8217;dir. Apache&#8217;nin d\u00fczg\u00fcn \u00e7al\u0131\u015fabilmesi i\u00e7in ilgili portlar\u0131n a\u00e7\u0131k olmas\u0131 gerekir. Apache kurulumu, UFW i\u00e7in baz\u0131 uygulama profilleri tan\u0131mlar.<\/p>\n<p>Mevcut uygulama profillerini listelemek i\u00e7in:<\/p>\n<pre><code class=\"language-bash\">sudo ufw app list<\/code><\/pre>\n<p>\u00c7\u0131kt\u0131 a\u015fa\u011f\u0131daki gibi olacakt\u0131r:<\/p>\n<pre><code class=\"language-\">Available applications:\n  Apache\n  Apache Full\n  Apache Secure\n  OpenSSH<\/code><\/pre>\n<p>*   <code>Apache<\/code>: Sadece 80 numaral\u0131 portu (HTTP) a\u00e7ar.<br \/>\n*   <code>Apache Full<\/code>: Hem 80 (HTTP) hem de 443 (HTTPS) numaral\u0131 portlar\u0131 a\u00e7ar.<br \/>\n*   <code>Apache Secure<\/code>: Sadece 443 numaral\u0131 portu (HTTPS) a\u00e7ar.<\/p>\n<p>Bu rehberde hem HTTP hem de HTTPS&#8217;e ihtiyac\u0131m\u0131z olaca\u011f\u0131 i\u00e7in <code>Apache Full<\/code> profilini etkinle\u015ftirece\u011fiz. E\u011fer sadece HTTPS kullanmak isterseniz daha sonra <code>Apache<\/code> profilini devre d\u0131\u015f\u0131 b\u0131rak\u0131p <code>Apache Secure<\/code> profilini etkinle\u015ftirebilirsiniz.<\/p>\n<pre><code class=\"language-bash\">sudo ufw allow 'Apache Full'\nsudo ufw enable # E\u011fer UFW etkin de\u011filse\nsudo ufw status<\/code><\/pre>\n<p><code>sudo ufw status<\/code> komutunun \u00e7\u0131kt\u0131s\u0131nda 80 ve 443 portlar\u0131n\u0131n a\u00e7\u0131k oldu\u011funu g\u00f6rmelisiniz.<\/p>\n<h4>Apache Durumunu Do\u011frulama<\/h4>\n<p>Apache servisinin \u00e7al\u0131\u015f\u0131r durumda oldu\u011funu do\u011frulamak i\u00e7in:<\/p>\n<pre><code class=\"language-bash\">sudo systemctl status apache2<\/code><\/pre>\n<p>\u00c7\u0131kt\u0131da <code>active (running)<\/code> ifadesini g\u00f6rmelisiniz. Ayr\u0131ca, web taray\u0131c\u0131n\u0131zda sunucunuzun IP adresini ziyaret ederek Apache&#8217;nin varsay\u0131lan &#8220;It works!&#8221; sayfas\u0131n\u0131 g\u00f6r\u00fcnt\u00fcleyebilirsiniz.<\/p>\n<h4>Sanal Host (Virtual Host) Yap\u0131land\u0131rmas\u0131<\/h4>\n<p>Let&#8217;s Encrypt, sertifika verme s\u00fcrecinde alan ad\u0131n\u0131z\u0131n sunucuyu i\u015faret etti\u011fini do\u011frulamak i\u00e7in alan ad\u0131n\u0131z \u00fczerinden eri\u015filebilir olmas\u0131 gerekmektedir. Bu nedenle, alan ad\u0131n\u0131z i\u00e7in bir sanal host yap\u0131land\u0131rmas\u0131 olu\u015fturman\u0131z \u00f6nemlidir.<\/p>\n<p>\u00d6rnek olarak <code>example.com<\/code> alan ad\u0131n\u0131 kullanal\u0131m. \u00d6ncelikle alan ad\u0131n\u0131z i\u00e7in bir belge k\u00f6k\u00fc (document root) dizini olu\u015ftural\u0131m:<\/p>\n<pre><code class=\"language-bash\">sudo mkdir -p \/var\/www\/example.com\/html<\/code><\/pre>\n<p>Bu dizine basit bir <code>index.html<\/code> dosyas\u0131 olu\u015ftural\u0131m:<\/p>\n<pre><code class=\"language-bash\">sudo nano \/var\/www\/example.com\/html\/index.html<\/code><\/pre>\n<p>\u0130\u00e7eri\u011fe a\u015fa\u011f\u0131daki gibi bir HTML kodu ekleyebilirsiniz:<\/p>\n<pre><code class=\"language-html\"><!DOCTYPE html>\n<html lang=\"en\">\n<head>\n    <meta charset=\"UTF-8\">\n    <meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n    <title>Example.com<\/title>\n<\/head>\n<body>\n    \n    <p>Bu, Apache sanal hostunuzun \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 g\u00f6steren varsay\u0131lan sayfad\u0131r.<\/p>\n<\/body>\n<\/html><\/code><\/pre>\n<p>Dosyay\u0131 kaydedin ve kapat\u0131n (CTRL+X, Y, Enter).<\/p>\n<p>\u015eimdi belge k\u00f6k\u00fc dizininin sahipli\u011fini Apache kullan\u0131c\u0131s\u0131na (www-data) atayal\u0131m:<\/p>\n<pre><code class=\"language-bash\">sudo chown -R www-data:www-data \/var\/www\/example.com\/html\nsudo chmod -R 755 \/var\/www\/example.com<\/code><\/pre>\n<p>Alan ad\u0131n\u0131z i\u00e7in bir sanal host yap\u0131land\u0131rma dosyas\u0131 olu\u015ftural\u0131m:<\/p>\n<pre><code class=\"language-bash\">sudo nano \/etc\/apache2\/sites-available\/example.com.conf<\/code><\/pre>\n<p>A\u015fa\u011f\u0131daki i\u00e7eri\u011fi dosyaya ekleyin. <code>example.com<\/code> yerine kendi alan ad\u0131n\u0131z\u0131 kullanmay\u0131 unutmay\u0131n.<\/p>\n<pre><code class=\"language-apache\"><VirtualHost *:80>\n    ServerAdmin webmaster@localhost\n    ServerName example.com\n    ServerAlias www.example.com\n    DocumentRoot \/var\/www\/example.com\/html\n    ErrorLog ${APACHE_LOG_DIR}\/error.log\n    CustomLog ${APACHE_LOG_DIR}\/access.log combined\n\n    <Directory \/var\/www\/example.com\/html>\n        Options -Indexes +FollowSymLinks\n        AllowOverride All\n        Require all granted\n    <\/Directory>\n<\/VirtualHost><\/code><\/pre>\n<p>Dosyay\u0131 kaydedin ve kapat\u0131n.<\/p>\n<p>Yeni sanal host dosyas\u0131n\u0131 etkinle\u015ftirin ve varsay\u0131lan yap\u0131land\u0131rmay\u0131 devre d\u0131\u015f\u0131 b\u0131rak\u0131n (e\u011fer kullanm\u0131yorsan\u0131z):<\/p>\n<pre><code class=\"language-bash\">sudo a2ensite example.com.conf\nsudo a2dissite 000-default.conf # \u0130ste\u011fe ba\u011fl\u0131, e\u011fer varsay\u0131lan siteyi kullanm\u0131yorsan\u0131z\nsudo apache2ctl configtest<\/code><\/pre>\n<p><code>Syntax OK<\/code> \u00e7\u0131kt\u0131s\u0131n\u0131 almal\u0131s\u0131n\u0131z. Ard\u0131ndan Apache&#8217;yi yeniden ba\u015flat\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo systemctl restart apache2<\/code><\/pre>\n<p>\u015eimdi taray\u0131c\u0131n\u0131zdan <code>http:\/\/example.com<\/code> adresine giderek sanal hostunuzun \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 do\u011frulayabilirsiniz.<\/p>\n<h3>Certbot Kurulumu<\/h3>\n<p>Certbot, Let&#8217;s Encrypt sertifikalar\u0131n\u0131 kolayca alman\u0131z\u0131 ve y\u00f6netmenizi sa\u011flayan bir istemci yaz\u0131l\u0131m\u0131d\u0131r. Ubuntu 16.04 i\u00e7in Certbot&#8217;u resmi PPA&#8217;dan (Personal Package Archive) kurmak en iyi y\u00f6ntemdir.<\/p>\n<h4>Certbot PPA Ekleme<\/h4>\n<p>Certbot PPA&#8217;y\u0131 sisteminize ekleyin:<\/p>\n<pre><code class=\"language-bash\">sudo add-apt-repository ppa:certbot\/certbot -y<\/code><\/pre>\n<h4>Paket Listesini G\u00fcncelleme<\/h4>\n<p>Yeni PPA eklendikten sonra paket listenizi tekrar g\u00fcncelleyin:<\/p>\n<pre><code class=\"language-bash\">sudo apt update<\/code><\/pre>\n<h4>Certbot Kurulumu<\/h4>\n<p>Certbot&#8217;u Apache entegrasyonu ile birlikte kurun:<\/p>\n<pre><code class=\"language-bash\">sudo apt install python-certbot-apache -y<\/code><\/pre>\n<p>Bu komut, Certbot paketini ve Apache eklentisini kuracakt\u0131r.<\/p>\n<h3>Let&#8217;s Encrypt SSL Sertifikas\u0131 Alma<\/h3>\n<p>Certbot&#8217;u kurduktan sonra, web sunucunuz i\u00e7in bir SSL sertifikas\u0131 almak \u00e7ok kolayd\u0131r. Certbot&#8217;un Apache eklentisi, sertifika alma ve Apache yap\u0131land\u0131rmas\u0131n\u0131 otomatik olarak de\u011fi\u015ftirme yetene\u011fine sahiptir.<\/p>\n<p>Alan ad\u0131n\u0131z i\u00e7in bir SSL sertifikas\u0131 almak i\u00e7in a\u015fa\u011f\u0131daki komutu kullan\u0131n. <code>example.com<\/code> ve <code>www.example.com<\/code> yerine kendi alan adlar\u0131n\u0131z\u0131 eklemeyi unutmay\u0131n:<\/p>\n<pre><code class=\"language-bash\">sudo certbot --apache -d example.com -d www.example.com<\/code><\/pre>\n<p>Bu komutu \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131n\u0131zda Certbot sizden baz\u0131 bilgiler isteyecektir:<\/p>\n<p>1.  <strong>E-posta Adresi:<\/strong> Acil yenileme bildirimleri ve g\u00fcvenlik uyar\u0131lar\u0131 i\u00e7in bir e-posta adresi girin.<\/p>\n<pre><code class=\"language-\">Enter email address (optional) (e.g. name@example.com):<\/code><\/pre>\n<p>2.  <strong>Hizmet \u015eartlar\u0131n\u0131 Kabul Etme:<\/strong> Let&#8217;s Encrypt hizmet \u015fartlar\u0131n\u0131 kabul etmeniz istenecektir. Kabul etmek i\u00e7in <code>A<\/code> (Agree) yaz\u0131p Enter&#8217;a bas\u0131n.<\/p>\n<pre><code class=\"language-\">Please read the terms of service at\n    https:\/\/letsencrypt.org\/documents\/LE-SA-v1.2-November-15-2017.pdf. You must\n    agree in order to register with the ACME server.\n    (A)gree\/(C)ancel: A<\/code><\/pre>\n<p>3.  <strong>EFF&#8217;den E-posta Alma:<\/strong> Electronic Frontier Foundation (EFF) ile e-posta adresinizi payla\u015fmak isteyip istemedi\u011finiz sorulacakt\u0131r. \u0130ste\u011fe ba\u011fl\u0131d\u0131r, <code>Y<\/code> (Yes) veya <code>N<\/code> (No) se\u00e7ene\u011fini belirleyin.<\/p>\n<pre><code class=\"language-\">Would you be willing to share your email address with the Electronic Frontier\n    Foundation, a founding partner of the Let's Encrypt project and the non-profit\n    organization that develops Certbot? We'd like to send you email about our work\n    fighting for encryption and privacy.\n    (Y)es\/(N)o: N<\/code><\/pre>\n<p>4.  <strong>HTTP&#8217;yi HTTPS&#8217;e Y\u00f6nlendirme:<\/strong> Certbot, HTTP trafi\u011fini otomatik olarak HTTPS&#8217;e y\u00f6nlendirip y\u00f6nlendirmeyece\u011finizi soracakt\u0131r. G\u00fcvenlik i\u00e7in t\u00fcm trafi\u011fi HTTPS&#8217;e y\u00f6nlendirmek \u015fiddetle tavsiye edilir. <code>2<\/code> (Redirect) se\u00e7ene\u011fini se\u00e7in ve Enter&#8217;a bas\u0131n.<\/p>\n<pre><code class=\"language-\">Please choose whether or not to redirect HTTP traffic to HTTPS, removing HTTP access.\n    -------------------------------------------------------------------------------\n    1: No redirect - Make no further changes to the webserver configuration.\n    2: Redirect - Make all requests redirect to secure HTTPS access. Choose this for\n    new sites, or if you're confident your site works on HTTPS. You can undo this\n    change by editing your web server's configuration.\n    -------------------------------------------------------------------------------\n    Select the appropriate number [1-2] then [enter] (press 'c' to cancel): 2<\/code><\/pre>\n<p>T\u00fcm bu ad\u0131mlar\u0131 tamamlad\u0131ktan sonra Certbot, alan ad\u0131n\u0131z i\u00e7in sertifikay\u0131 alacak, Apache yap\u0131land\u0131rman\u0131z\u0131 g\u00fcncelleyecek ve SSL\/TLS&#8217;yi etkinle\u015ftirecektir. Ba\u015far\u0131l\u0131 bir kurulumun ard\u0131ndan a\u015fa\u011f\u0131daki gibi bir \u00e7\u0131kt\u0131 g\u00f6rmelisiniz:<\/p>\n<pre><code class=\"language-\">IMPORTANT NOTES:\n - Congratulations! Your certificate and chain have been saved at:\n   \/etc\/letsencrypt\/live\/example.com\/fullchain.pem\n   Your key file has been saved at:\n   \/etc\/letsencrypt\/live\/example.com\/privkey.pem\n   Your cert will expire on 2024-07-25. To obtain a new or tweaked\n   version of this certificate in the future, simply run certbot again\n   with the \"certonly\" option. To non-interactively renew <em>all<\/em> of\n   your certificates, run \"certbot renew\"\n - Your account credentials have been saved in your Certbot\n   configuration directory at \/etc\/letsencrypt. You should make a\n   secure backup of this folder now. This (the .pem files) contains your\n   private key and certificates. If you lose them, you will not be able\n   to recover your site's HTTPS functionality without a new certificate.\n - If you like Certbot, please consider supporting our work by:\n\n   Donating to ISRG \/ Let's Encrypt:   https:\/\/letsencrypt.org\/donate\n   Donating to EFF:                    https:\/\/eff.org\/donate-le<\/code><\/pre>\n<p>Bu \u00e7\u0131kt\u0131, sertifikan\u0131z\u0131n ba\u015far\u0131yla al\u0131nd\u0131\u011f\u0131n\u0131 ve Apache&#8217;nin HTTPS i\u00e7in yap\u0131land\u0131r\u0131ld\u0131\u011f\u0131n\u0131 g\u00f6sterir. Art\u0131k web taray\u0131c\u0131n\u0131zdan <code>https:\/\/example.com<\/code> adresine giderek sitenizin g\u00fcvenli bir ba\u011flant\u0131 \u00fczerinden \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 ve taray\u0131c\u0131n\u0131zda bir asma kilit simgesi g\u00f6rd\u00fc\u011f\u00fcn\u00fcz\u00fc do\u011frulayabilirsiniz.<\/p>\n<h3>Otomatik Yenileme<\/h3>\n<p>Let&#8217;s Encrypt sertifikalar\u0131 90 g\u00fcn boyunca ge\u00e7erlidir. Bu, g\u00fcvenlik nedenleriyle k\u0131sa bir s\u00fcredir. Ancak Certbot, sertifikalar\u0131n\u0131z\u0131 otomatik olarak yenilemek i\u00e7in bir mekanizma sa\u011flar.<\/p>\n<p>Certbot&#8217;u kurdu\u011funuzda, sisteminizde otomatik bir yenileme g\u00f6revi (cron job veya systemd timer) olu\u015fturulur. Bu g\u00f6rev, sertifikalar\u0131n\u0131z\u0131n s\u00fcresi dolmadan \u00f6nce otomatik olarak yenilenmesini sa\u011flar. Genellikle, sertifikalar\u0131n\u0131z\u0131n s\u00fcresi dolmadan 30 g\u00fcn \u00f6nce yenileme i\u015flemi denenir.<\/p>\n<p>Otomatik yenileme i\u015fleminin d\u00fczg\u00fcn \u00e7al\u0131\u015ft\u0131\u011f\u0131ndan emin olmak i\u00e7in bir deneme yapabilirsiniz:<\/p>\n<pre><code class=\"language-bash\">sudo certbot renew --dry-run<\/code><\/pre>\n<p>Bu komut, yenileme i\u015flemini ger\u00e7ekte sertifikalar\u0131 yenilemeden sim\u00fcle eder. E\u011fer herhangi bir hata mesaj\u0131 almazsan\u0131z ve \u00e7\u0131kt\u0131 <code>Congratulations, all renewals succeeded:<\/code> gibi bir ifade i\u00e7eriyorsa, otomatik yenileme mekanizman\u0131z do\u011fru \u015fekilde yap\u0131land\u0131r\u0131lm\u0131\u015f demektir.<\/p>\n<p>Yenileme i\u015flemi genellikle arka planda sessizce \u00e7al\u0131\u015f\u0131r. E\u011fer bir sertifika yenileme s\u0131ras\u0131nda bir sorun olu\u015fursa (\u00f6rne\u011fin, alan ad\u0131n\u0131z\u0131n DNS kayd\u0131 de\u011fi\u015ftiyse veya sunucunuz kapal\u0131ysa), Certbot yap\u0131land\u0131rma s\u0131ras\u0131nda belirtti\u011finiz e-posta adresine bir bildirim g\u00f6nderecektir.<\/p>\n<h3>Apache SSL Yap\u0131land\u0131rmas\u0131n\u0131 \u0130nceleme<\/h3>\n<p>Certbot, sertifikay\u0131 ald\u0131ktan sonra Apache yap\u0131land\u0131rman\u0131zda baz\u0131 de\u011fi\u015fiklikler yapar. Bu de\u011fi\u015fiklikleri incelemek, neler oldu\u011funu anlaman\u0131za yard\u0131mc\u0131 olacakt\u0131r.<\/p>\n<p>Certbot, genellikle mevcut sanal host yap\u0131land\u0131rma dosyan\u0131z\u0131n bir kopyas\u0131n\u0131 olu\u015fturur ve SSL ayarlar\u0131n\u0131 bu kopyaya ekler. \u00d6rne\u011fin, <code>example.com.conf<\/code> dosyan\u0131z varsa, Certbot <code>example.com-le-ssl.conf<\/code> ad\u0131nda yeni bir dosya olu\u015fturur. Bu dosya, <code>\/etc\/apache2\/sites-available\/<\/code> dizininde bulunur.<\/p>\n<p>Bu dosyay\u0131 a\u00e7arak inceleyebilirsiniz:<\/p>\n<pre><code class=\"language-bash\">sudo nano \/etc\/apache2\/sites-available\/example.com-le-ssl.conf<\/code><\/pre>\n<p>Bu dosya i\u00e7inde a\u015fa\u011f\u0131daki gibi direktifler g\u00f6receksiniz:<\/p>\n<pre><code class=\"language-apache\"><IfModule mod_ssl.c>\n<VirtualHost *:443>\n    ServerAdmin webmaster@localhost\n    ServerName example.com\n    ServerAlias www.example.com\n    DocumentRoot \/var\/www\/example.com\/html\n    ErrorLog ${APACHE_LOG_DIR}\/error.log\n    CustomLog ${APACHE_LOG_DIR}\/access.log combined\n\n    Include \/etc\/letsencrypt\/options-ssl-apache.conf\n    SSLCertificateFile \/etc\/letsencrypt\/live\/example.com\/fullchain.pem\n    SSLCertificateKeyFile \/etc\/letsencrypt\/live\/example.com\/privkey.pem\n<\/VirtualHost>\n<\/IfModule><\/code><\/pre>\n<p><em>   <strong><code>VirtualHost <\/em>:443<\/code><\/strong>: Bu blok, 443 numaral\u0131 port \u00fczerinden gelen HTTPS isteklerini dinler.<br \/>\n*   <strong><code>SSLEngine On<\/code><\/strong>: SSL\/TLS motorunu bu sanal host i\u00e7in etkinle\u015ftirir. (Bu genellikle <code>options-ssl-apache.conf<\/code> i\u00e7inde yer al\u0131r.)<br \/>\n*   <strong><code>SSLCertificateFile<\/code><\/strong>: Let&#8217;s Encrypt taraf\u0131ndan verilen birincil sertifika dosyas\u0131n\u0131n yolunu belirtir (<code>fullchain.pem<\/code>). Bu dosya, alan ad\u0131n\u0131z\u0131n sertifikas\u0131n\u0131 ve ara sertifikalar\u0131 i\u00e7erir.<br \/>\n*   <strong><code>SSLCertificateKeyFile<\/code><\/strong>: Sertifikayla e\u015fle\u015fen \u00f6zel anahtar dosyas\u0131n\u0131n yolunu belirtir (<code>privkey.pem<\/code>). Bu dosya gizli tutulmal\u0131d\u0131r.<br \/>\n*   <strong><code>Include \/etc\/letsencrypt\/options-ssl-apache.conf<\/code><\/strong>: Certbot, g\u00fcvenli bir SSL yap\u0131land\u0131rmas\u0131 i\u00e7in \u00f6nerilen ayarlar\u0131 i\u00e7eren bu dosyay\u0131 otomatik olarak dahil eder. Bu dosya, g\u00fc\u00e7l\u00fc \u015fifreleme algoritmalar\u0131, TLS protokol s\u00fcr\u00fcmleri ve di\u011fer g\u00fcvenlik ayarlar\u0131n\u0131 i\u00e7erir. Bu dosya genellikle SSLLabs gibi ara\u00e7larda A+ derecesi alman\u0131z\u0131 sa\u011flayacak ayarlar\u0131 bar\u0131nd\u0131r\u0131r.<\/p>\n<p>Ayr\u0131ca, Certbot HTTP&#8217;den HTTPS&#8217;e y\u00f6nlendirmeyi etkinle\u015ftirdiyseniz, HTTP sanal hostunuzun yap\u0131land\u0131rma dosyas\u0131nda (<code>example.com.conf<\/code>) a\u015fa\u011f\u0131daki gibi bir y\u00f6nlendirme kural\u0131 g\u00f6receksiniz:<\/p>\n<pre><code class=\"language-apache\"><VirtualHost *:80>\n    ServerName example.com\n    ServerAlias www.example.com\n    Redirect permanent \/ https:\/\/example.com\/\n<\/VirtualHost><\/code><\/pre>\n<p>Bu kural, HTTP \u00fczerinden gelen t\u00fcm istekleri otomatik olarak HTTPS versiyonuna y\u00f6nlendirir. Bu, kullan\u0131c\u0131lar\u0131n\u0131z\u0131n her zaman g\u00fcvenli ba\u011flant\u0131 kullanmas\u0131n\u0131 sa\u011flamak i\u00e7in \u00f6nemlidir.<\/p>\n<h4>HTTP Strict Transport Security (HSTS)<\/h4>\n<p>HSTS, bir web sitesinin taray\u0131c\u0131lara sadece HTTPS \u00fczerinden eri\u015filmesi gerekti\u011fini bildiren bir g\u00fcvenlik mekanizmas\u0131d\u0131r. Bu, potansiyel man-in-the-middle sald\u0131r\u0131lar\u0131n\u0131 \u00f6nlemeye yard\u0131mc\u0131 olur ve taray\u0131c\u0131lar\u0131n HTTP ba\u011flant\u0131s\u0131 kurmas\u0131n\u0131 engeller.<\/p>\n<p>Certbot&#8217;un varsay\u0131lan <code>options-ssl-apache.conf<\/code> dosyas\u0131 genellikle HSTS&#8217;yi i\u00e7erir, ancak kontrol etmek veya manuel olarak eklemek isteyebilirsiniz. HSTS&#8217;yi etkinle\u015ftirmek i\u00e7in, SSL sanal host yap\u0131land\u0131rman\u0131za (genellikle <code>example.com-le-ssl.conf<\/code> veya <code>options-ssl-apache.conf<\/code> i\u00e7inde) a\u015fa\u011f\u0131daki sat\u0131r\u0131 ekleyebilirsiniz:<\/p>\n<pre><code class=\"language-apache\">Header always set Strict-Transport-Security \"max-age=63072000; includeSubDomains; preload\"<\/code><\/pre>\n<p>Bu sat\u0131r\u0131 ekledikten sonra Apache&#8217;yi yeniden ba\u015flatman\u0131z gerekir:<\/p>\n<pre><code class=\"language-bash\">sudo systemctl restart apache2<\/code><\/pre>\n<p><code>max-age<\/code> de\u011feri, taray\u0131c\u0131n\u0131n bu kural\u0131 ne kadar s\u00fcreyle hat\u0131rlayaca\u011f\u0131n\u0131 saniye cinsinden belirtir (63072000 saniye = 2 y\u0131l). <code>includeSubDomains<\/code>, t\u00fcm alt alan adlar\u0131 i\u00e7in de HSTS&#8217;yi uygular. <code>preload<\/code> ise, sitenizi HSTS preload listesine eklemek isterseniz kullan\u0131l\u0131r (bu, sitenizin taray\u0131c\u0131lar\u0131n \u00f6nceden y\u00fcklenmi\u015f HSTS listesine eklenmesini sa\u011flar, b\u00f6ylece ilk ziyaret bile g\u00fcvenli olur).<\/p>\n<h3>Ek G\u00fcvenlik \u0130pu\u00e7lar\u0131<\/h3>\n<p>SSL\/TLS sertifikas\u0131 kurmak, web sunucunuzu g\u00fcvence alt\u0131na alman\u0131n \u00f6nemli bir ad\u0131m\u0131d\u0131r, ancak tek ba\u015f\u0131na yeterli de\u011fildir. Ek g\u00fcvenlik \u00f6nlemleri alarak sunucunuzun genel g\u00fcvenli\u011fini art\u0131rabilirsiniz:<\/p>\n<p>*   <strong>Yaz\u0131l\u0131m G\u00fcncellemeleri:<\/strong> \u0130\u015fletim sisteminizi ve t\u00fcm kurulu yaz\u0131l\u0131mlar\u0131 (Apache, PHP, veritaban\u0131 vb.) d\u00fczenli olarak g\u00fcncel tutun. Bu, bilinen g\u00fcvenlik a\u00e7\u0131klar\u0131n\u0131n kapat\u0131lmas\u0131n\u0131 sa\u011flar.<br \/>\n*   <strong>G\u00fc\u00e7l\u00fc Parolalar ve SSH Anahtarlar\u0131:<\/strong> Sunucunuza eri\u015fim i\u00e7in g\u00fc\u00e7l\u00fc, karma\u015f\u0131k parolalar kullan\u0131n ve m\u00fcmk\u00fcnse SSH anahtar tabanl\u0131 kimlik do\u011frulamay\u0131 tercih edin. Parola tabanl\u0131 SSH eri\u015fimini devre d\u0131\u015f\u0131 b\u0131rakmay\u0131 d\u00fc\u015f\u00fcnebilirsiniz.<br \/>\n*   <strong>G\u00fcvenlik Duvar\u0131 Yap\u0131land\u0131rmas\u0131:<\/strong> Sadece ihtiya\u00e7 duyulan portlar\u0131 a\u00e7\u0131n (\u00f6rne\u011fin, 22 SSH, 80 HTTP, 443 HTTPS). Di\u011fer t\u00fcm portlar\u0131 kapat\u0131n.<br \/>\n*   <strong>Fail2ban:<\/strong> Sunucunuza y\u00f6nelik kaba kuvvet sald\u0131r\u0131lar\u0131n\u0131 (brute-force attacks) engellemek i\u00e7in Fail2ban gibi bir ara\u00e7 kullan\u0131n. Bu, tekrarlanan ba\u015far\u0131s\u0131z giri\u015f denemelerinde IP adreslerini otomatik olarak yasaklar.<br \/>\n*   <strong>ModSecurity:<\/strong> Web uygulaman\u0131z\u0131 XSS, SQL enjeksiyonu gibi web tabanl\u0131 sald\u0131r\u0131lardan korumak i\u00e7in ModSecurity gibi bir Web Uygulama G\u00fcvenlik Duvar\u0131 (WAF) kullanmay\u0131 d\u00fc\u015f\u00fcnebilirsiniz.<br \/>\n*   <strong>Apache Mod\u00fcllerini Devre D\u0131\u015f\u0131 B\u0131rakma:<\/strong> Kullanmad\u0131\u011f\u0131n\u0131z Apache mod\u00fcllerini devre d\u0131\u015f\u0131 b\u0131rak\u0131n. Daha az \u00e7al\u0131\u015fan mod\u00fcl, daha az potansiyel sald\u0131r\u0131 y\u00fczeyi demektir.<br \/>\n*   <strong>Sunucu G\u00fcnl\u00fcklerini \u0130zleme:<\/strong> Apache eri\u015fim ve hata g\u00fcnl\u00fcklerini (<code>\/var\/log\/apache2\/<\/code>) d\u00fczenli olarak inceleyin. Anormal aktiviteleri veya sald\u0131r\u0131 giri\u015fimlerini tespit etmek i\u00e7in bu g\u00fcnl\u00fckler \u00f6nemlidir.<br \/>\n*   <strong>Yedeklemeler:<\/strong> Sunucunuzun ve web sitenizin d\u00fczenli yedeklerini al\u0131n. Bir g\u00fcvenlik ihlali veya sistem ar\u0131zas\u0131 durumunda h\u0131zl\u0131 bir \u015fekilde geri d\u00f6nebilmek i\u00e7in bu kritik \u00f6neme sahiptir.<br \/>\n*   <strong>Dizin Listelemeyi Devre D\u0131\u015f\u0131 B\u0131rakma:<\/strong> Apache&#8217;de dizin listelemeyi devre d\u0131\u015f\u0131 b\u0131rak\u0131n (<code>Options -Indexes<\/code>). Bu, ziyaret\u00e7ilerin web sitenizdeki dizinlerin i\u00e7eri\u011fini g\u00f6rmesini engeller.<br \/>\n*   <strong>G\u00fcvenlik Ba\u015fl\u0131klar\u0131:<\/strong> HSTS&#8217;ye ek olarak, X-Frame-Options, X-Content-Type-Options, Content-Security-Policy gibi di\u011fer g\u00fcvenlik ba\u015fl\u0131klar\u0131n\u0131 da uygulayarak taray\u0131c\u0131 tabanl\u0131 sald\u0131r\u0131lar\u0131 azaltabilirsiniz.<\/p>\n<h3>Sorun Giderme<\/h3>\n<p>Kurulum veya yap\u0131land\u0131rma s\u0131ras\u0131nda kar\u015f\u0131la\u015fabilece\u011finiz baz\u0131 yayg\u0131n sorunlar ve \u00e7\u00f6z\u00fcmleri:<\/p>\n<p>*   <strong>Sertifika Al\u0131nam\u0131yor (Certbot Hatalar\u0131):<\/strong><br \/>\n    *   <strong>DNS Sorunlar\u0131:<\/strong> Alan ad\u0131n\u0131z\u0131n sunucunuzun IP adresine do\u011fru i\u015faret etti\u011finden emin olun. DNS de\u011fi\u015fikliklerinin yay\u0131lmas\u0131 biraz zaman alabilir (24-48 saat).<br \/>\n    *   <strong>G\u00fcvenlik Duvar\u0131:<\/strong> 80 ve 443 numaral\u0131 portlar\u0131n a\u00e7\u0131k oldu\u011fundan emin olun. Certbot, alan ad\u0131n\u0131z\u0131 do\u011frulamak i\u00e7in bu portlara eri\u015febilmelidir.<br \/>\n    *   <strong>Sanal Host Yap\u0131land\u0131rmas\u0131:<\/strong> Alan ad\u0131n\u0131z i\u00e7in do\u011fru bir sanal host yap\u0131land\u0131rmas\u0131 oldu\u011fundan ve Apache&#8217;nin bu sanal hostu tan\u0131d\u0131\u011f\u0131ndan emin olun.<br \/>\n    *   <strong>Certbot G\u00fcnl\u00fckleri:<\/strong> <code>\/var\/log\/letsencrypt\/<\/code> dizinindeki g\u00fcnl\u00fck dosyalar\u0131n\u0131 kontrol ederek hatan\u0131n ayr\u0131nt\u0131lar\u0131n\u0131 g\u00f6rebilirsiniz.<br \/>\n*   <strong>Web Sitesi Eri\u015filemez veya Hata Veriyor:<\/strong><br \/>\n    *   <strong>Apache G\u00fcnl\u00fckleri:<\/strong> <code>\/var\/log\/apache2\/error.log<\/code> ve <code>\/var\/log\/apache2\/access.log<\/code> dosyalar\u0131n\u0131 kontrol edin. Apache hatalar\u0131 genellikle burada bulunur.<br \/>\n    *   <strong>Apache Yap\u0131land\u0131rma Testi:<\/strong> <code>sudo apache2ctl configtest<\/code> komutunu \u00e7al\u0131\u015ft\u0131rarak Apache yap\u0131land\u0131rma dosyalar\u0131n\u0131zda s\u00f6zdizimi hatas\u0131 olup olmad\u0131\u011f\u0131n\u0131 kontrol edin.<br \/>\n    *   <strong>Servis Durumu:<\/strong> <code>sudo systemctl status apache2<\/code> komutuyla Apache servisinin \u00e7al\u0131\u015f\u0131r durumda oldu\u011funu do\u011frulay\u0131n.<br \/>\n*   <strong>HTTP&#8217;den HTTPS&#8217;e Y\u00f6nlendirme \u00c7al\u0131\u015fm\u0131yor:<\/strong><br \/>\n    *   HTTP sanal host yap\u0131land\u0131rma dosyan\u0131zda (\u00f6rn. <code>example.com.conf<\/code>) <code>Redirect<\/code> veya <code>RewriteRule<\/code> direktiflerinin do\u011fru \u015fekilde yap\u0131land\u0131r\u0131ld\u0131\u011f\u0131ndan emin olun.<br \/>\n    *   <code>mod_rewrite<\/code> mod\u00fcl\u00fcn\u00fcn etkin oldu\u011fundan emin olun: <code>sudo a2enmod rewrite<\/code> ve ard\u0131ndan Apache&#8217;yi yeniden ba\u015flat\u0131n.<br \/>\n*   <strong>Sertifika S\u00fcresi Doluyor Uyar\u0131s\u0131:<\/strong><br \/>\n    *   Certbot&#8217;un otomatik yenileme i\u015fleminin \u00e7al\u0131\u015ft\u0131\u011f\u0131ndan emin olun. <code>sudo certbot renew --dry-run<\/code> komutunu kullanarak test edin.<br \/>\n    *   Sisteminizde bir cron i\u015fi veya systemd zamanlay\u0131c\u0131s\u0131 olarak <code>certbot renew<\/code> komutunun \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 do\u011frulay\u0131n.<br \/>\n*   <strong>Taray\u0131c\u0131 G\u00fcvenlik Uyar\u0131s\u0131 (Ge\u00e7ersiz Sertifika):<\/strong><br \/>\n    *   Alan ad\u0131n\u0131z\u0131n sertifikada belirtilen alan adlar\u0131yla tam olarak e\u015fle\u015fti\u011finden emin olun (\u00f6rn. <code>www.example.com<\/code> i\u00e7in de sertifika alm\u0131\u015f olmal\u0131s\u0131n\u0131z).<br \/>\n    *   Sertifika zincirinin do\u011fru oldu\u011fundan emin olun. Certbot&#8217;un <code>fullchain.pem<\/code> dosyas\u0131 bunu otomatik olarak halleder.<br \/>\n    *   Sertifikan\u0131n s\u00fcresinin dolup dolmad\u0131\u011f\u0131n\u0131 kontrol edin.<\/p>\n<p>Bu sorun giderme ad\u0131mlar\u0131, \u00e7o\u011fu yayg\u0131n sorunu \u00e7\u00f6zmenize yard\u0131mc\u0131 olacakt\u0131r. Daha spesifik sorunlar i\u00e7in Certbot veya Apache&#8217;nin resmi belgelerine ba\u015fvurmak veya ilgili topluluk forumlar\u0131nda yard\u0131m aramak faydal\u0131 olabilir.<\/p>\n<h3>Sonu\u00e7<\/h3>\n<p>Bu makalede, Ubuntu 16.04 sunucusu \u00fczerinde Apache web sunucunuzu Let&#8217;s Encrypt ile nas\u0131l g\u00fcvenli hale getirece\u011finizi ad\u0131m ad\u0131m \u00f6\u011frendiniz. S\u00fcre\u00e7, Apache kurulumu ve temel sanal host yap\u0131land\u0131rmas\u0131ndan ba\u015flayarak, Certbot&#8217;un kurulmas\u0131na, \u00fccretsiz SSL\/TLS sertifikas\u0131n\u0131n al\u0131nmas\u0131na ve otomatik yenileme mekanizmas\u0131n\u0131n anla\u015f\u0131lmas\u0131na kadar uzand\u0131. Ayr\u0131ca, Apache SSL yap\u0131land\u0131rmas\u0131n\u0131n ayr\u0131nt\u0131lar\u0131n\u0131 inceledik ve HSTS gibi ek g\u00fcvenlik \u00f6nlemlerine de\u011findik.<\/p>\n<p>HTTPS&#8217;in \u00f6nemi g\u00fcn ge\u00e7tik\u00e7e artmaktad\u0131r. Kullan\u0131c\u0131lar\u0131n\u0131z\u0131n verilerini korumak, sitenizin g\u00fcvenilirli\u011fini art\u0131rmak ve arama motoru s\u0131ralamalar\u0131nda avantaj elde etmek i\u00e7in HTTPS kullanmak art\u0131k bir zorunluluktur. Let&#8217;s Encrypt ve Certbot sayesinde, bu s\u00fcre\u00e7 art\u0131k herkes i\u00e7in eri\u015filebilir ve kolayd\u0131r.<\/p>\n<p>Unutmay\u0131n ki web g\u00fcvenli\u011fi s\u00fcrekli bir \u00e7abad\u0131r. Sertifikalar\u0131n\u0131z\u0131 d\u00fczenli olarak yenilemek, sisteminizi g\u00fcncel tutmak ve ek g\u00fcvenlik ipu\u00e7lar\u0131n\u0131 uygulamak, web sitenizin ve kullan\u0131c\u0131lar\u0131n\u0131z\u0131n verilerinin uzun vadede g\u00fcvende kalmas\u0131n\u0131 sa\u011flayacakt\u0131r. Ubuntu 16.04 eski bir s\u00fcr\u00fcm olmas\u0131na ra\u011fmen, bu rehberdeki ad\u0131mlar, benzer Linux tabanl\u0131 sistemlerde de temel Let&#8217;s Encrypt ve Apache yap\u0131land\u0131rmalar\u0131n\u0131 anlamak i\u00e7in sa\u011flam bir temel olu\u015fturmaktad\u0131r. Gelecekte, daha g\u00fcncel Ubuntu s\u00fcr\u00fcmlerine (\u00f6rne\u011fin Ubuntu 20.04 veya 22.04) ge\u00e7i\u015f yapmay\u0131 ve HTTP\/2 gibi daha modern protokolleri kullanmay\u0131 da d\u00fc\u015f\u00fcnebilirsiniz.<\/body><\/p>\n","protected":false},"excerpt":{"rendered":"Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme\nGiri\u015f\nG\u00fcn\u00fcm\u00fcz\u00fcn dijital d\u00fcnyas\u0131nda, web sitelerinin g\u00fcvenli\u011fi hi\u00e7","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"csco_page_header_type":"","csco_page_load_nextpost":"","csco_page_subscribe_form":"","csco_page_contact_form":"","footnotes":""},"categories":[1468],"tags":[],"class_list":{"0":"post-35447","1":"post","2":"type-post","3":"status-publish","4":"format-standard","6":"category-ubuntu","7":"cs-entry","8":"cs-video-wrap"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v20.5 (Yoast SEO v25.3.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Apache&#039;yi Let&#039;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\" \/>\n<meta property=\"og:locale\" content=\"tr_TR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apache&#039;yi Let&#039;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme\" \/>\n<meta property=\"og:description\" content=\"Apache&#039;yi Let&#039;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme Giri\u015f G\u00fcn\u00fcm\u00fcz\u00fcn dijital d\u00fcnyas\u0131nda, web sitelerinin g\u00fcvenli\u011fi hi\u00e7\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\" \/>\n<meta property=\"og:site_name\" content=\"Kodlar\u0131n Gizemli D\u00fcnyas\u0131\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-29T18:40:43+00:00\" \/>\n<meta name=\"author\" content=\"Fatih Soysal\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Yazan:\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fatih Soysal\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tahmini okuma s\u00fcresi\" \/>\n\t<meta name=\"twitter:data2\" content=\"18 dakika\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\"},\"author\":{\"name\":\"Fatih Soysal\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"headline\":\"Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme\",\"datePublished\":\"2025-11-29T18:40:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\"},\"wordCount\":2922,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"articleSection\":[\"Ubuntu\"],\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\",\"name\":\"Apache'yi Let's Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131\",\"isPartOf\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#website\"},\"datePublished\":\"2025-11-29T18:40:43+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#breadcrumb\"},\"inLanguage\":\"tr\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Anasayfa\",\"item\":\"https:\/\/fatihsoysal.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#website\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/\",\"name\":\"Fatihsoysal.com\",\"description\":\"Blog - Yaz\u0131l\u0131m D\u00fcnyas\u0131 Tecr\u00fcbelerim\",\"publisher\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fatihsoysal.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"tr\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1\",\"name\":\"Fatih Soysal\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"tr\",\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png\",\"contentUrl\":\"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png\",\"width\":512,\"height\":512,\"caption\":\"Fatih Soysal\"},\"logo\":{\"@id\":\"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/\"},\"description\":\"Kullan\u0131m ve kodlama m\u00fckemmeliyetini odak alan uygulamalar olu\u015fturma deneyimine sahip, profesyonel olarak 15+ y\u0131l \u00fczeri deneyime sahip bir yaz\u0131l\u0131m m\u00fchendisi.\",\"url\":\"https:\/\/fatihsoysal.com\/blog\/author\/fatihsoysal\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Apache'yi Let's Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/","og_locale":"tr_TR","og_type":"article","og_title":"Apache'yi Let's Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme","og_description":"Apache'yi Let's Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme Giri\u015f G\u00fcn\u00fcm\u00fcz\u00fcn dijital d\u00fcnyas\u0131nda, web sitelerinin g\u00fcvenli\u011fi hi\u00e7","og_url":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/","og_site_name":"Kodlar\u0131n Gizemli D\u00fcnyas\u0131","article_published_time":"2025-11-29T18:40:43+00:00","author":"Fatih Soysal","twitter_card":"summary_large_image","twitter_misc":{"Yazan:":"Fatih Soysal","Tahmini okuma s\u00fcresi":"18 dakika"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#article","isPartOf":{"@id":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/"},"author":{"name":"Fatih Soysal","@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"headline":"Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme","datePublished":"2025-11-29T18:40:43+00:00","mainEntityOfPage":{"@id":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/"},"wordCount":2922,"commentCount":0,"publisher":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"articleSection":["Ubuntu"],"inLanguage":"tr","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/fatihsoysal.com\/blog\/#organization"}},{"@type":"WebPage","@id":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/","url":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/","name":"Apache'yi Let's Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme - Kodlar\u0131n Gizemli D\u00fcnyas\u0131","isPartOf":{"@id":"https:\/\/fatihsoysal.com\/blog\/#website"},"datePublished":"2025-11-29T18:40:43+00:00","breadcrumb":{"@id":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#breadcrumb"},"inLanguage":"tr","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/fatihsoysal.com\/blog\/apacheyi-lets-encrypt-ile-ubuntu-16-04-uzerinde-guvenli-hale-getirme\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Anasayfa","item":"https:\/\/fatihsoysal.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Apache&#8217;yi Let&#8217;s Encrypt ile Ubuntu 16.04 \u00dczerinde G\u00fcvenli Hale Getirme"}]},{"@type":"WebSite","@id":"https:\/\/fatihsoysal.com\/blog\/#website","url":"https:\/\/fatihsoysal.com\/blog\/","name":"Fatihsoysal.com","description":"Blog - Yaz\u0131l\u0131m D\u00fcnyas\u0131 Tecr\u00fcbelerim","publisher":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fatihsoysal.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"tr"},{"@type":["Person","Organization"],"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/002a254750921dcfd568a99e48240dd1","name":"Fatih Soysal","image":{"@type":"ImageObject","inLanguage":"tr","@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png","contentUrl":"https:\/\/fatihsoysal.com\/blog\/wp-content\/uploads\/2024\/04\/cropped-replicate-prediction-3kgg1hgjn5rgp0cf0p5tr0jw7w-1.png","width":512,"height":512,"caption":"Fatih Soysal"},"logo":{"@id":"https:\/\/fatihsoysal.com\/blog\/#\/schema\/person\/image\/"},"description":"Kullan\u0131m ve kodlama m\u00fckemmeliyetini odak alan uygulamalar olu\u015fturma deneyimine sahip, profesyonel olarak 15+ y\u0131l \u00fczeri deneyime sahip bir yaz\u0131l\u0131m m\u00fchendisi.","url":"https:\/\/fatihsoysal.com\/blog\/author\/fatihsoysal\/"}]}},"yoast_meta":{"yoast_wpseo_title":"","yoast_wpseo_metadesc":"","yoast_wpseo_canonical":""},"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/35447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/comments?post=35447"}],"version-history":[{"count":1,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/35447\/revisions"}],"predecessor-version":[{"id":35448,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/posts\/35447\/revisions\/35448"}],"wp:attachment":[{"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/media?parent=35447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/categories?post=35447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fatihsoysal.com\/blog\/wp-json\/wp\/v2\/tags?post=35447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}