Re: Installation instructions
Hunter Matthews <[email protected]> 02 Feb 2003 17:02:24 -0500
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <[email protected]> |
Using the snake-oil certs utterly violates everything in the apache / mod_ssl documentation. On Sat, 2003-02-01 at 12:54, Jonathan S. Shapiro wrote: > On Sat, 2003-02-01 at 10:47, John Berninger wrote: > > > > 2. The instructions fail to make clear that I am actually configuring > > > SSL for my entire apache server -- not just for current.... > > Erp. Good point - I'll drop that into the issues database. > > More info on this: > > It turns out that (at least on RH7.3) installing mod_ssl automatically > installs server.crt and server.key files. It is *not* necessary to > generate a new cert/key pair at all. All that is needed is to instruct > the person doing the install to copy > > /etc/httpd/conf/ssl.crt/snakeoil-ca-rsa.crt > > to their RHNS-CA-CERT file. I have confirmed that this works (the hard > way). > > While I am thinking about it, it is probably a good idea to localize the > client-side configuration changes as much as possible in case the poor > user wants to revert. Given this, it might be better to tell the user to > stick the new ca cert file in /etc/sysconfig/rhn/, name it something > like MY-RHNS-CA_CERT file, and change the appropriate path in the > up2date configuration file. A minor tweak, but it's easier to understand > what happened umpteen months later when the poor user has long forgotten > that they tweaked any of this. > > > shap > > > > _______________________________________________ > Current-server mailing list > [email protected] > http://lists.dulug.duke.edu/mailman/listinfo/current-server > > -- Hunter Matthews Unix / Network Administrator Office: BioScience 145/244 Duke Univ. Biology Department Key: F0F88438 / FFB5 34C0 B350 99A4 BB02 9779 A5DB 8B09 F0F8 8438 Never take candy from strangers. Especially on the internet.