Slackware: Unterschied zwischen den Versionen

Aus Callooh Wiki
Zur Navigation springen Zur Suche springen
Die Seite wurde neu angelegt: „= Installation openssl = http://www.openssl.org http://www.openssl.org/source/ => http://www.openssl.org/source/openssl-1.0.1c.tar.gz $ cd /usr/local/src …“
 
 
(5 dazwischenliegende Versionen desselben Benutzers werden nicht angezeigt)
Zeile 15: Zeile 15:
  $ make test
  $ make test
  $ make install
  $ make install
für man Pages /etc/profile editieren, Zeile 6:
export MANPATH=/usr/local/man:/usr/man:/usr/X11R6/man:/usr/ssl/man


= Installation Apache =
= Installation Apache =
Zeile 31: Zeile 34:
  $ make
  $ make
  $ make install
  $ make install
$ ldconfig
  $ wget -c http://tweedo.com/mirror/apache//httpd/httpd-2.2.23.tar.gz
  $ wget -c http://tweedo.com/mirror/apache//httpd/httpd-2.2.23.tar.gz
  $ md5sum httpd-2.2.23.tar.gz
  $ md5sum httpd-2.2.23.tar.gz
Zeile 38: Zeile 42:
  $ make
  $ make
  $ make install
  $ make install
Apache starten:
$ apachectl start
mit Browser testen: http://192.168.0.14
= Apache SSL konfigurieren =
in /usr/local/conf/httpd.conf, Zeile 126 Kommentar (#) entfernen:
LoadModule ssl_module modules/mod_ssl.so
$ apachectl configtest
httpd.conf, Zeile 478:
Include conf/extra/httpd-ssl.conf
httpd.conf, Zeile 87:
LoadModule socache_shmcb_module modules/mod_socache_shmcb.so
= openssl =
== Private Key ==
openssl genpkey -algorithm RSA -out /etc/ssl/private/cakey.pem
== CA erstellen ==
Cert:
$ cd /etc/ssl/certs
$ openssl req -new -x509 -key private/cakey.pem -days 7000 -extensions v3_ca -out certs/cacert.pem
Prüfen:
$  openssl x509 -in cacert.pem -text
(WICHTIG:  CA:TRUE)
Files anlegen:
$ touch index
$ touch crlnumber
$ echo "01" > crlnumber
$ openssl ca -gencrl -out crl.pem
'''Default-Werte kommen aus Config-File: /etc/ssl/openssl.cnf'''

Aktuelle Version vom 24. September 2012, 13:23 Uhr

Installation openssl

http://www.openssl.org

http://www.openssl.org/source/

=> http://www.openssl.org/source/openssl-1.0.1c.tar.gz

$ cd /usr/local/src
$ wget -c http://www.openssl.org/source/openssl-1.0.1c.tar.gz
$ md5sum openssl-1.0.1c.tar.gz
$ tar xvfz openssl-1.0.1c.tar.gz
$ cd /usr/local/src/openssl-1.0.1c
$ ./config --prefix=/usr
$ make
$ make test
$ make install

für man Pages /etc/profile editieren, Zeile 6:

export MANPATH=/usr/local/man:/usr/man:/usr/X11R6/man:/usr/ssl/man

Installation Apache

http://httpd.apache.org

$ cd /usr/local/src
$ wget -c http://tweedo.com/mirror/apache//apr/apr-1.4.6.tar.gz
$ md5sum apr-1.4.6.tar.gz
$ ./configure --prefix=/usr/local
$ make
$ make install
$ wget -c http://tweedo.com/mirror/apache//apr/apr-util-1.4.1.tar.gz
$ md5sum apr-util-1.4.1.tar.gz
$ tar xvfz apr-util-1.4.1.tar.gz
$ cd apr-util-1.4.1
$ ./configure --prefix=/usr/local --with-apr=/usr/local
$ make
$ make install
$ ldconfig
$ wget -c http://tweedo.com/mirror/apache//httpd/httpd-2.2.23.tar.gz
$ md5sum httpd-2.2.23.tar.gz
$ tar xvfz httpd-2.2.23.tar.gz
$ cd httpd-2.2.23
$ ./configure --prefix=/usr/local --enable-ssl
$ make
$ make install

Apache starten:

$ apachectl start

mit Browser testen: http://192.168.0.14

Apache SSL konfigurieren

in /usr/local/conf/httpd.conf, Zeile 126 Kommentar (#) entfernen:

LoadModule ssl_module modules/mod_ssl.so
$ apachectl configtest

httpd.conf, Zeile 478:

Include conf/extra/httpd-ssl.conf

httpd.conf, Zeile 87:

LoadModule socache_shmcb_module modules/mod_socache_shmcb.so

openssl

Private Key

openssl genpkey -algorithm RSA -out /etc/ssl/private/cakey.pem

CA erstellen

Cert:

$ cd /etc/ssl/certs
$ openssl req -new -x509 -key private/cakey.pem -days 7000 -extensions v3_ca -out certs/cacert.pem

Prüfen:

$  openssl x509 -in cacert.pem -text
(WICHTIG:  CA:TRUE)

Files anlegen:

$ touch index
$ touch crlnumber
$ echo "01" > crlnumber
$ openssl ca -gencrl -out crl.pem


Default-Werte kommen aus Config-File: /etc/ssl/openssl.cnf