Results 1 to 4 of 4

Thread: Enabling apache-SSL

  1. #1
    Member registered user
    Join Date
    Jan 2003
    Location
    NY
    Posts
    86

    Enabling apache-SSL

    What files need to be edited to enable apache to work in SSL mode (https), port 443?

    thanks in advance,
    Jim

  2. #2
    Junior Member registered user
    Join Date
    Jan 2003
    Location
    Rotterdam, Netherlands
    Posts
    10
    hi,

    the mod_ssl module is loaded in /etc/apache/httpd.conf so it should be enabled.
    other modules, like PHP, server-info & server-status also work fine ...
    only problem is that the httpd.conf is write-proteced (linked), so i copied it to alt.conf, edited that file and enabled the modules i wanted and used "apache -f /etc/apache/alt.conf"

    i searched around a bit and found this :
    http://ist.uwaterloo.ca/security/lib.../howto/ssleay/
    it seems you need to install a certificate to enable SSL ??

    Goner

  3. #3
    Guest
    Quote Originally Posted by Goner
    hi,

    the mod_ssl module is loaded in /etc/apache/httpd.conf so it should be enabled.
    other modules, like PHP, server-info & server-status also work fine ...
    only problem is that the httpd.conf is write-proteced (linked), so i copied it to alt.conf, edited that file and enabled the modules i wanted and used "apache -f /etc/apache/alt.conf"

    i searched around a bit and found this :
    http://ist.uwaterloo.ca/security/lib.../howto/ssleay/
    it seems you need to install a certificate to enable SSL ??

    Goner
    I tried various other things, including creating a certificate, was not able to get it to work on port 443 using SSL yet.

    Jim

  4. #4
    Junior Member
    Join Date
    Jan 2004
    Posts
    1
    Ok,

    I got it working after this:

    I used the (installed) libapache-mod-ssl package to create certificates.
    Go to /usr/share/doc/libapache-mod-ssl/examples
    Unzip gid-mkcert.sh.gz and run it.
    Fill out all the fields, and a bunch of server.* and ca.* files will be created in the current directory.
    (remember the pass phrases you use).

    Copy the .key files (ca.key and server.key) to /etc/apache/ssl.key
    Copy the .crt files (ca.crt and server.crt) to /etc/apache/ssl.crt
    Copy the .crs files (ca.crs and server.crs) to /etc/apache/ssl.crs

    Add the following to /etc/apache/httpd.conf:

    Code:
    Listen 80
    Listen 443
    And:

    Code:
    <VirtualHost _default_:443>
         DocumentRoot /var/www
         ServerName My.server.com
         ServerAdmin webmaster@my.server.com
         ErrorLog /var/log/apache/ssl_error_log
         TransferLog /var/log/apache/ssl_access_log
         SSLEngine On
         SSLCertificateFile /etc/apache/conf/ssl.crt/server.crt
         SSLCertificateKeyFile /etc/apache/conf/ssl.key/server.key
        <Files ~ "\.(cgi|shtml|php)$">
          SSLOptions +StdEnvVars
        </Files>
        <Directory "/cgi-bin">
          SSLOptions +StdEnvVars
        </Directory>
        SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown
        CustomLog /var/log/apache/ssl_request_log \
          "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
    </VirtualHost>
    Restart the httpd server:

    Code:
    /etc/init.d/apache restart
    You will be asked for the RSA pass phrase.

    Regards,

    IKK

Similar Threads

  1. enabling 3d in knoppix 3.6 hd install
    By helios17 in forum General Support
    Replies: 1
    Last Post: 11-21-2004, 01:11 AM
  2. patch for enabling k3b for user mode ?
    By cul971 in forum General Support
    Replies: 2
    Last Post: 11-05-2003, 02:05 PM
  3. Enabling X-Servers connection
    By blackshadow in forum General Support
    Replies: 1
    Last Post: 06-10-2003, 04:11 PM
  4. Enabling static IP configuration
    By dafne in forum Customising & Remastering
    Replies: 1
    Last Post: 05-23-2003, 12:05 PM
  5. Enabling 3D Support
    By Cyber in forum Customising & Remastering
    Replies: 0
    Last Post: 12-18-2002, 03:07 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  


Fortinet FortiGate 60F | 10 Gbps Firewall Network Security EXPIRED (FG-60F)- New picture

Fortinet FortiGate 60F | 10 Gbps Firewall Network Security EXPIRED (FG-60F)- New

$251.99



SonicWALL TZ300 Network Security Appl FirewallRouter5pt 01-SSC-0215TransferReady picture

SonicWALL TZ300 Network Security Appl FirewallRouter5pt 01-SSC-0215TransferReady

$45.00



Cisco FPR1010-NGFW-K9 FirePOWER Security Appliance **CISCO EXCESS** picture

Cisco FPR1010-NGFW-K9 FirePOWER Security Appliance **CISCO EXCESS**

$339.00



Palo Alto PA-220 Next-Gen Firewall 750-000128-00A w/ Power adapter  picture

Palo Alto PA-220 Next-Gen Firewall 750-000128-00A w/ Power adapter

$68.00



Netgate SG-3100 pfSense Security Gateway Firewall Appliance w/Power Adapter 32GB picture

Netgate SG-3100 pfSense Security Gateway Firewall Appliance w/Power Adapter 32GB

$150.00



Protectli The Vault 4-Port Firewall Network Appliance FW108120 51524F17 picture

Protectli The Vault 4-Port Firewall Network Appliance FW108120 51524F17

$149.95



Sophos XGS 116 Firewall Appliance - White picture

Sophos XGS 116 Firewall Appliance - White

$320.00



Dell SonicWALL TZ300 Firewall Appliance Transfer Ready - NO AC picture

Dell SonicWALL TZ300 Firewall Appliance Transfer Ready - NO AC

$24.98



Fortinet Fortiwifi 60D FG-60D Security Appliance Firewall / VPN w/ AC Adapter picture

Fortinet Fortiwifi 60D FG-60D Security Appliance Firewall / VPN w/ AC Adapter

$34.97



Fortinet FortiGate 60F FG-60F Network Security Firewall Appliance picture

Fortinet FortiGate 60F FG-60F Network Security Firewall Appliance

$199.99