Re: OT: Thawte SSL on Mac OS X Server
This WebDNA talk-list message is from 2005
It keeps the original formatting.
numero = 61575
interpreted = N
texte = The cert generation has to be right or you could have problems. I also have to start my ssl sites after my server starts up. thankfully I only have to restart on apples security updates.Here is what I did for my servers:(when you see "domainA" it means your domain name without the quotes)
cddd if=/dev/randon of=rand.dat bs=1m count=1openssl genrsa -rand rand.dat -des 1024 > "domainA".pemcp "domainA".pem /etc/httpd/ssl.key/domainA.keyopenssl req -new -key "domainA".pem -out "domainA"csr.pem(send contents of domainAcsr.pem to ca when I get the crt file back I place it in the ssl.crt folder naming it domainA.csr. I set up an ssl server instance and point the certificate file data to domainA.csr and the key file data to domainB.key as created above and enter the passphrase I enter when creating the server key)(On my second server and IP address I set continue as follows)dd if=/dev/randon of=rand.dat bs=1m count=1openssl genrsa -rand rand.dat -des 1024 > "domainB".pemopenssl req -new -key "domainB".pem -out "domainB"csr.pem(send contents of domainBcsr.pem to ca when I get the crt file back I place it in the ssl.crt folder naming it domainB.csr. I set up an ssl server instance and point the certificate file data to domainB.csr and the key file data to domainB.key as created above in set B and enter the passphrase I enter when creating the second server key)Hard RestartAfter a hard restart I find I have to turn off the instances of the ssl servers, then start the service. Once the service is up I check the ssl services and choose "Don't Restart". They start up fine and I am happy. I would love to get around all this but since its a live server I haven't been able to play much.All done!On Mar 26, 2005, at 3:55 PM, Phil Herring wrote:> Hi Charles,>> I tried everything to make this work, then I finally asked the Thawte> support folks to email the cert to me, spec'd for W* and OSX. It then> worked perfectly with the usual W* setup.-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Associated Messages, from the most recent to the oldest:
The cert generation has to be right or you could have problems. I also have to start my ssl sites after my server starts up. thankfully I only have to restart on apples security updates.Here is what I did for my servers:(when you see "domainA" it means your domain name without the quotes)cddd if=/dev/randon of=rand.dat bs=1m count=1openssl genrsa -rand rand.dat -des 1024 > "domainA".pemcp "domainA".pem /etc/httpd/ssl.key/domainA.keyopenssl req -new -key "domainA".pem -out "domainA"csr.pem(send contents of domainAcsr.pem to ca when I get the crt file back I place it in the ssl.crt folder naming it domainA.csr. I set up an ssl server instance and point the certificate file data to domainA.csr and the key file data to domainB.key as created above and enter the passphrase I enter when creating the server key)(On my second server and IP address I set continue as follows)dd if=/dev/randon of=rand.dat bs=1m count=1openssl genrsa -rand rand.dat -des 1024 > "domainB".pemopenssl req -new -key "domainB".pem -out "domainB"csr.pem(send contents of domainBcsr.pem to ca when I get the crt file back I place it in the ssl.crt folder naming it domainB.csr. I set up an ssl server instance and point the certificate file data to domainB.csr and the key file data to domainB.key as created above in set B and enter the passphrase I enter when creating the second server key)Hard RestartAfter a hard restart I find I have to turn off the instances of the ssl servers, then start the service. Once the service is up I check the ssl services and choose "Don't Restart". They start up fine and I am happy. I would love to get around all this but since its a live server I haven't been able to play much.All done!On Mar 26, 2005, at 3:55 PM, Phil Herring wrote:> Hi Charles,>> I tried everything to make this work, then I finally asked the Thawte> support folks to email the cert to me, spec'd for W* and OSX. It then> worked perfectly with the usual W* setup.-------------------------------------------------------------This message is sent to you because you are subscribed to the mailing list .To unsubscribe, E-mail to: To switch to the DIGEST mode, E-mail to Web Archive of this list is at: http://webdna.smithmicro.com/
Bob Minor
DOWNLOAD WEBDNA NOW!
Top Articles:
Talk List
The WebDNA community talk-list is the best place to get some help: several hundred extremely proficient programmers with an excellent knowledge of WebDNA and an excellent spirit will deliver all the tips and tricks you can imagine...
Related Readings:
WebCat b13 CGI -shownext- (1997)
Shopping cart now good (fixed it) (1997)
WebCat2b13MacPlugIn - [include] doesn't allow creator (1997)
Hyperboard/bulletin board available (1998)
Running 2 two WebCatalog.acgi's (1996)
Fwd: State-of-the-Art Digital Aquarium for Your Computer (2006)
Feature: TCPconnect via SSL (1999)
AOL refuses some e-mails (2000)
UNSUBSCRIBE ME (2004)
TRAINING videos - Prove IT. (1998)
WebCatalog2 Feature Feedback (1996)
Ticket Ordering Question (2003)
WebDNA install on Tiger doesn't work ... (2005)
Webcat run amuk (2002)
Bannerad Demo (1998)
FileMaker and WebCat (1999)
[WebDNA] ONLY the FIRST continuous run of numeric chars? (2008)
Comments in db? (1997)
wild question (1998)
triggers.db (1999)