Craig Newlander wrote:
>    I'm trying to run apache with SSL on NT.  yeah I know this isn't a good
> choice but the choice isn't mine.  If you can't help please don't waste my
> time by chasting me - I'll simply delete your message and move on. :)   You
> are free however, to waste your own time.

Talk about attack being the best form of defence... Chill out a bit,
nobody has said "Boo" to you yet...
>    I've downloaded OpenSSL,and mod_ssl.  I've followed the installation note
> for Win32.  I am #6 in the document.    Can someone point me to a source
> where I can figure out how to setup the config files and certificates?  Or
> better yet tell me how!  thanks.

I hope it doesn't waste your precious time, but here's how I set up my


Owen Boyle.

Making self signed certificates:

NB: These certificates contain no pass-phrase so do not need user input 
when you start apache. Also, can be used by any server...

1) Make a random data file and set it up as $RANDFILE

# cd /usr/local/apache/ssl/certs
# PATH=$PATH:/usr/local/apache/bin
# export PATH
# cp /var/cron/olog temp
# gzip temp
# mv temp.gz random_data
# RANDFILE=/usr/local/apache/ssl/certs/random_data
# export RANDFILE

2) Create a RSA private key and certificate for our Certificate

# openssl genrsa -des3 -out ca.key 1024
        password is "CA_PASSWORD"
        Now make the certificate using the private key.
# openssl req -new -x509 -days 365 -key ca.key -out ca.crt

3) Now make a Certificate Signing Request for

# openssl genrsa -des3 -out kiwi.key 1024
# openssl rsa -in kiwi.key -out banana
# mv banana kiwi.key
# openssl req -new -key kiwi.key -out kiwi.csr

4) And sign it

# ./ kiwi.csr

Now we have 

ca.crt          Certificate Authority certificate
ca.db.certs     ) CA databases, holding
ca.db.index     ) details of certificates
ca.db.serial    ) issued
ca.key          Certificate Authority private key
random_data     for random routines         script for signing certificates
kiwi.crt certificate (sent with SSL requests)
kiwi.csr        KIWI certificate signing request (not really needed
kiwi.key private key (decrypts public-key encoded

- summary of commands

# openssl genrsa -des3 -out 1024
# openssl rsa -in -out banana
# mv banana
# openssl req -new -key -out
# ./
Apache Interface to OpenSSL (mod_ssl)         
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to