I tried typing the passphrase twice and !voila!  Thanks a lot for the hint.
This also explains why the "apache -k shutdown" also didn't work (which I
failed to mention as well).

Yes I'm running on NT.  I think that it should be fairly simple to fix the
code so that the use is prompted for the second entry.  However, when I
tried a startup and entered a bad passphrase, it was detected at once.
Thus, I can't imagine why the second entry is wanted/needed.  Seems to me
this is a bug that ought to be fixed.

regards
Kirk

> -----Original Message-----
>
> Kirk Benson wrote:
> >
> > After several hours of experimentation, I discover the
> following problem-
> > when I use the encrypted server key file and enter the passphrase in the
> > Apache startup console window, Apache does not respond to ANY
> requests at
> > all (HTTP or HTTPS).  However, when I create an unencrypted
> server key file,
> > all works perfectly!  The ONLY change between the two runs is
> to change the
> > filename in my SSLCertificateKeyFile directive.
> >
> This has been reported before. I assume you work on a Win32 (NT perhaps)
> platform. The odd thing is, you're supposed to type the pass phrase
> twice. Yes, it doesn't tell you to do so. Yes, you don't see it's
> waiting for you to do this. But that's really what's going on. If you
> look at the last line in the log that you sent, it says:
> "Init: Requesting pass phrase via builtin terminal dialog"
> It's waiting for you to type it a second time. That's why it appears to
> hang. Type it twice, and all will work fine. Or use a key with the
> passphrase removed. Or use a password program that will, when invoked by
> mod_ssl, tell it the password. See the faq for that. But do note that
> that too has some dark corners on Win32. I've managed to make it work
> only when running apache with the -X option (single instance debug
> mode).
>
> Regards,
> Jan Dries

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to