Slackware: Unterschied zwischen den Versionen
Zur Navigation springen
Zur Suche springen
Reini (Diskussion | Beiträge) Keine Bearbeitungszusammenfassung |
Reini (Diskussion | Beiträge) |
||
| (4 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt) | |||
| Zeile 15: | Zeile 15: | ||
$ make test | $ make test | ||
$ make install | $ make install | ||
für man Pages /etc/profile editieren, Zeile 6: | |||
export MANPATH=/usr/local/man:/usr/man:/usr/X11R6/man:/usr/ssl/man | |||
= Installation Apache = | = Installation Apache = | ||
| Zeile 31: | Zeile 34: | ||
$ make | $ make | ||
$ make install | $ make install | ||
$ ldconfig | |||
$ wget -c http://tweedo.com/mirror/apache//httpd/httpd-2.2.23.tar.gz | $ wget -c http://tweedo.com/mirror/apache//httpd/httpd-2.2.23.tar.gz | ||
$ md5sum httpd-2.2.23.tar.gz | $ md5sum httpd-2.2.23.tar.gz | ||
| Zeile 43: | Zeile 47: | ||
mit Browser testen: http://192.168.0.14 | mit Browser testen: http://192.168.0.14 | ||
= Apache SSL konfigurieren = | |||
in /usr/local/conf/httpd.conf, Zeile 126 Kommentar (#) entfernen: | |||
LoadModule ssl_module modules/mod_ssl.so | |||
$ apachectl configtest | |||
httpd.conf, Zeile 478: | |||
Include conf/extra/httpd-ssl.conf | |||
httpd.conf, Zeile 87: | |||
LoadModule socache_shmcb_module modules/mod_socache_shmcb.so | |||
= openssl = | |||
== Private Key == | |||
openssl genpkey -algorithm RSA -out /etc/ssl/private/cakey.pem | |||
== CA erstellen == | |||
Cert: | |||
$ cd /etc/ssl/certs | |||
$ openssl req -new -x509 -key private/cakey.pem -days 7000 -extensions v3_ca -out certs/cacert.pem | |||
Prüfen: | |||
$ openssl x509 -in cacert.pem -text | |||
(WICHTIG: CA:TRUE) | |||
Files anlegen: | |||
$ touch index | |||
$ touch crlnumber | |||
$ echo "01" > crlnumber | |||
$ openssl ca -gencrl -out crl.pem | |||
'''Default-Werte kommen aus Config-File: /etc/ssl/openssl.cnf''' | |||
Aktuelle Version vom 24. September 2012, 13:23 Uhr
Installation openssl
http://www.openssl.org/source/
=> http://www.openssl.org/source/openssl-1.0.1c.tar.gz
$ cd /usr/local/src $ wget -c http://www.openssl.org/source/openssl-1.0.1c.tar.gz $ md5sum openssl-1.0.1c.tar.gz $ tar xvfz openssl-1.0.1c.tar.gz $ cd /usr/local/src/openssl-1.0.1c $ ./config --prefix=/usr $ make $ make test $ make install
für man Pages /etc/profile editieren, Zeile 6:
export MANPATH=/usr/local/man:/usr/man:/usr/X11R6/man:/usr/ssl/man
Installation Apache
$ cd /usr/local/src $ wget -c http://tweedo.com/mirror/apache//apr/apr-1.4.6.tar.gz $ md5sum apr-1.4.6.tar.gz $ ./configure --prefix=/usr/local $ make $ make install $ wget -c http://tweedo.com/mirror/apache//apr/apr-util-1.4.1.tar.gz $ md5sum apr-util-1.4.1.tar.gz $ tar xvfz apr-util-1.4.1.tar.gz $ cd apr-util-1.4.1 $ ./configure --prefix=/usr/local --with-apr=/usr/local $ make $ make install $ ldconfig $ wget -c http://tweedo.com/mirror/apache//httpd/httpd-2.2.23.tar.gz $ md5sum httpd-2.2.23.tar.gz $ tar xvfz httpd-2.2.23.tar.gz $ cd httpd-2.2.23 $ ./configure --prefix=/usr/local --enable-ssl $ make $ make install
Apache starten:
$ apachectl start
mit Browser testen: http://192.168.0.14
Apache SSL konfigurieren
in /usr/local/conf/httpd.conf, Zeile 126 Kommentar (#) entfernen:
LoadModule ssl_module modules/mod_ssl.so
$ apachectl configtest
httpd.conf, Zeile 478:
Include conf/extra/httpd-ssl.conf
httpd.conf, Zeile 87:
LoadModule socache_shmcb_module modules/mod_socache_shmcb.so
openssl
Private Key
openssl genpkey -algorithm RSA -out /etc/ssl/private/cakey.pem
CA erstellen
Cert:
$ cd /etc/ssl/certs $ openssl req -new -x509 -key private/cakey.pem -days 7000 -extensions v3_ca -out certs/cacert.pem
Prüfen:
$ openssl x509 -in cacert.pem -text (WICHTIG: CA:TRUE)
Files anlegen:
$ touch index $ touch crlnumber $ echo "01" > crlnumber $ openssl ca -gencrl -out crl.pem
Default-Werte kommen aus Config-File: /etc/ssl/openssl.cnf