Re: Installation instructions

Hunter Matthews <[email protected]> 02 Feb 2003 17:02:24 -0500
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
Using the snake-oil certs utterly violates everything in the apache /
mod_ssl documentation. 




On Sat, 2003-02-01 at 12:54, Jonathan S. Shapiro wrote:
> On Sat, 2003-02-01 at 10:47, John Berninger wrote:
> 
> > > 2. The instructions fail to make clear that I am actually configuring
> > > SSL for my entire apache server -- not just for current....
> >         Erp.  Good point - I'll drop that into the issues database.
> 
> More info on this:
> 
> It turns out that (at least on RH7.3) installing mod_ssl automatically
> installs server.crt and server.key files. It is *not* necessary to
> generate a new cert/key pair at all.  All that is needed is to instruct
> the person doing the install to copy
> 
> 	/etc/httpd/conf/ssl.crt/snakeoil-ca-rsa.crt
> 
> to their RHNS-CA-CERT file. I have confirmed that this works (the hard
> way).
> 
> While I am thinking about it, it is probably a good idea to localize the
> client-side configuration changes as much as possible in case the poor
> user wants to revert. Given this, it might be better to tell the user to
> stick the new ca cert file in /etc/sysconfig/rhn/, name it something
> like MY-RHNS-CA_CERT file, and change the appropriate path in the
> up2date configuration file. A minor tweak, but it's easier to understand
> what happened umpteen months later when the poor user has long forgotten
> that they tweaked any of this.
> 
> 
> shap
> 
> 
> 
> _______________________________________________
> Current-server mailing list
> [email protected]
> http://lists.dulug.duke.edu/mailman/listinfo/current-server
> 
> 
-- 
Hunter Matthews                          Unix / Network Administrator
Office: BioScience 145/244               Duke Univ. Biology Department
Key: F0F88438 / FFB5 34C0 B350 99A4 BB02  9779 A5DB 8B09 F0F8 8438
Never take candy from strangers. Especially on the internet.