>-----Original Message-----
>From: Rich Salz [mailto:[EMAIL PROTECTED]]
>Sent: 29 November 2001 16:06
>To: Mark J Cox
>Cc: [EMAIL PROTECTED]
>Subject: Re: Apache SSL Private Keys
>[snip]
>If the private key is encrypted, they must also break that 
>passphrase to
>get the key. If I, as the owner of the machine, am diligent I will not
>restart my server after my system has "mysteriously" crashed.  Proper
>diligence requires defining mysterious, of course.  (Insert 
>Windows BSOD
>joke here.)
>[snip]
Of course, you forget to mention the most common cause of server reboots
running UNIX based systems. Power failures. 

Unless you've got the money, you probably won't have a backup generator in
place. Also, your working hours mean that you'll only be around your server
for around 20 per cent of the year. The other 80 per cent makes up the
primary motivation for using UNIX based systems in the first place. If you
don't believe me, have a look at how often Microsoft reboots its web
servers. They only keep their site up by running multiple servers.

In the last five years, we've had two major power failures and have only
recently installed a backup generator. Our website had been up for about a
year at the time of the last power failure (which is particularly galling).

Obviously, these are occasions when a server goes down, which is why it is
preferable to have it come up automatically. The original poster was
concerned that he'd have hundreds of keys to input, which has to be a
nightmare scenario. I haven't tried it, but I bet one mistyped key will mean
that the server doesn't start.

Personally, I'd rather do without them.
- 
John Airey
Internet systems support officer, ITCSD, Royal National Institute for the
Blind,
Bakewell Road, Peterborough PE2 6XU,
Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED]

- 

NOTICE: The information contained in this email and any attachments is 
confidential and may be legally privileged. If you are not the 
intended recipient you are hereby notified that you must not use, 
disclose, distribute, copy, print or rely on this email's content. If 
you are not the intended recipient, please notify the sender 
immediately and then delete the email and any attachments from your 
system.

RNIB has made strenuous efforts to ensure that emails and any 
attachments generated by its staff are free from viruses. However, it 
cannot accept any responsibility for any viruses which are 
transmitted. We therefore recommend you scan all attachments.

Please note that the statements and views expressed in this email 
and any attachments are those of the author and do not necessarily 
represent those of RNIB.

RNIB Registered Charity Number: 226227

Website: http://www.rnib.org.uk 

______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [EMAIL PROTECTED]
Automated List Manager                            [EMAIL PROTECTED]

Reply via email to