Re: Wildcards and perdition

Matthias Hunstock <[email protected]> Wed, 13 Feb 2019 14:30:35 +0100
Newsgroups gmane.mail.perdition.user
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============1731894788==
Content-Type: multipart/alternative;
 boundary="------------98A7B6C7F8E01AE5DD7128AD"
Content-Language: de-DE

This is a multi-part message in MIME format.
--------------98A7B6C7F8E01AE5DD7128AD
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Am 12.02.2019 um 18:16 schrieb yugi:
> Does perdition accept wildcards as certificate ?
> I am trying to set a deploy with one and I am getting always the error
> that was no possible to find the DH parameters.

Not finding the DH parameters should be completely independet from the
type of certificate (most server applications do not check the server
certificate anyway, because it is validated and trusted by the client,
which may have completely different rules).

For the DH parameters there are basically 3 options:

1. Generate DH parameters with OpenSSL, GnuTLS or other tools, put them
in a separate file and configure that file with *ssl_dh_params_file *opti=
on*
*

2. Generate DH parameters with OpenSSL, GnuTLS or other tools and put it
into your certificate file

3. Change *ssl_listen_ciphers* option to not include crypto algorithms
that depend on DH parameters.


Regards

Matthias



--------------98A7B6C7F8E01AE5DD7128AD
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html;
      charset=windows-1252">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix">Am 12.02.2019 um 18:16 schrieb yugi:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <div class="">Does perdition accept wildcards as certificate ?</div>
      <div class="">I am trying to set a deploy with one and I am
        getting always the error that was no possible to find the DH
        parameters.</div>
    </blockquote>
    <p>Not finding the DH parameters should be completely independet
      from the type of certificate (most server applications do not
      check the server certificate anyway, because it is validated and
      trusted by the client, which may have completely different rules).</p>
    <p>For the DH parameters there are basically 3 options:</p>
    <p>1. Generate DH parameters with OpenSSL, GnuTLS or other tools,
      put them in a separate file and configure that file with <b>ssl_dh_params_file
      </b>option<b><br>
      </b></p>
    <p>2. Generate DH parameters with OpenSSL, GnuTLS or other tools and
      put it into your certificate file</p>
    <p>3. Change <b>ssl_listen_ciphers</b> option to not include crypto
      algorithms that depend on DH parameters.<br>
    </p>
    <p><br>
    </p>
    <p>Regards</p>
    <p>Matthias</p>
    <br>
  </body>
</html>

--------------98A7B6C7F8E01AE5DD7128AD--

--===============1731894788==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fXwpQZXJkaXRpb24t
dXNlcnMgbWFpbGluZyBsaXN0ClBlcmRpdGlvbi11c2Vyc0B2ZXJnZW5ldC5uZXQKaHR0cHM6Ly9s
aXN0cy52ZXJnZW5ldC5uZXQvbGlzdGluZm8vcGVyZGl0aW9uLXVzZXJzCg==

--===============1731894788==--