Re: [apache-ssl] Apache-SSl setup
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [apache-ssl] Apache-SSl setup



Jeffrey Koch wrote:
> 
> I'm a bit confused on how to setup Apache-SSl. We already have a
> functioning Apache web server and want to add SSL to it. Now here are the
> questions:
> 
> 1. Is the normal installation to have Apache-SSL replace the
> non-SSL httpd service and provide both SSL and non-SSL service or do we
> run two servers at the same time Apache and Apache-SSL?

Use Apache-SSL for both.

> 
> 2.  The installation left me with a directory /usr/local/etc/httpd/conf
> which contains srm.conf, access.conf, httpd.conf and mime.types. These
> appeared to be normal Apache conf files. It also left me with
> /usr/local/etc/httpd/SSLconf/conf which contains access.conf, fdd948c7.0@,
> httpd.conf, mime.types and srm.conf. Access.conf and srm.conf are supposed
> to be empty (which they are) and httpd.conf has the SSL configuration
> lines. I have no idea what fdd948c7.0 and why it is linked to
> /usr/local/etc/ssl/conf/httpsd.pem.
> 
> - So what is fdd948c7.0?

Its a hash of the cert, used to find CA certs. In the simple case it is
completely redundant.

> - And are the conf files in SSLconf/conf supposed to be copied into
> /usr/local/etc/httpd/conf to replace the original Apache stuff? And, if
> so, is the httpd.conf file suppoed to be expanded to include all the
> directives from our srm, access and httpd.conf files.

Put them where you like, but obviously if you want it to do the same as
your existing server, you need to copy the directives across.

Cheers,

Ben.

-- 
Ben Laurie            |Phone: +44 (181) 735 0686|  Apache Group member
Freelance Consultant  |Fax:   +44 (181) 735 0689|http://www.apache.org
and Technical Director|Email: ben@algroup.co.uk |
A.L. Digital Ltd,     |Apache-SSL author    http://www.apache-ssl.org/
London, England.      |"Apache: TDG" http://www.ora.com/catalog/apache