<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.townx.org" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>townx - Creating a self-signed SSL certificate for Apache on Linux - Comments</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux</link>
 <description>Comments for &quot;Creating a self-signed SSL certificate for Apache on Linux&quot;</description>
 <language>en</language>
<item>
 <title>I followed yours and it</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39332</link>
 <description>&lt;p&gt;I followed yours and it works well, now to bookmark your site so I don&#039;t have to google next time and get a different tut.&lt;/p&gt;</description>
 <pubDate>Sat, 09 May 2009 04:38:47 -0500</pubDate>
 <dc:creator>Assignment</dc:creator>
 <guid isPermaLink="false">comment 39332 at http://www.townx.org</guid>
</item>
<item>
 <title>I know what you mean - it&#039;s</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39246</link>
 <description>&lt;p&gt;I know what you mean - it&#039;s always such a manual process when registering for an &lt;span class=&quot;caps&quot;&gt;SSL &lt;/span&gt;certificate.  &lt;/p&gt;</description>
 <pubDate>Fri, 01 May 2009 05:07:48 -0500</pubDate>
 <dc:creator>Electro Plated Diamond Blades</dc:creator>
 <guid isPermaLink="false">comment 39246 at http://www.townx.org</guid>
</item>
<item>
 <title>Interesting</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39161</link>
 <description>&lt;p&gt;This sounds interesting to me, having in mind that 5 &lt;span class=&quot;caps&quot;&gt;SSL &lt;/span&gt;certificates goes form $80-100 per year.&lt;/p&gt;

&lt;p&gt;And one can be used for a single domain, which is fine. ;) Thanks for sharing this information with us, pleas if you have more, give us more...&lt;/p&gt;

&lt;p&gt;all the best to you. ;)&lt;/p&gt;</description>
 <pubDate>Wed, 22 Apr 2009 16:34:53 -0500</pubDate>
 <dc:creator>Next Day Delivery</dc:creator>
 <guid isPermaLink="false">comment 39161 at http://www.townx.org</guid>
</item>
<item>
 <title>Thanks for this 

I have to</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39137</link>
 <description>&lt;p&gt;Thanks for this &lt;/p&gt;

&lt;p&gt;I have to set up &lt;span class=&quot;caps&quot;&gt;SSL &lt;/span&gt;once every several months and each time it&#039;s like the first time, I just forget what needs doing.&lt;/p&gt;

&lt;p&gt;I&#039;ll bookmark this for future reference.&lt;/p&gt;</description>
 <pubDate>Fri, 17 Apr 2009 09:02:50 -0500</pubDate>
 <dc:creator>team leadership training</dc:creator>
 <guid isPermaLink="false">comment 39137 at http://www.townx.org</guid>
</item>
<item>
 <title>will install on open ssl</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39098</link>
 <description>&lt;p&gt;I&#039;ll try this on my apache box 2, it has open / mod ssl.&lt;/p&gt;</description>
 <pubDate>Wed, 08 Apr 2009 00:42:28 -0500</pubDate>
 <dc:creator>Lyrics</dc:creator>
 <guid isPermaLink="false">comment 39098 at http://www.townx.org</guid>
</item>
<item>
 <title>Nice post thanks!</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39089</link>
 <description>&lt;p&gt;Nice post thanks!&lt;/p&gt;</description>
 <pubDate>Mon, 06 Apr 2009 14:52:00 -0500</pubDate>
 <dc:creator>epc</dc:creator>
 <guid isPermaLink="false">comment 39089 at http://www.townx.org</guid>
</item>
<item>
 <title>Thanks!</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39038</link>
 <description>&lt;p&gt;I&#039;ll be sure to try this. I use Lighttpd instead of Apache, so I&#039;ll see what I can do.&lt;/p&gt;</description>
 <pubDate>Sat, 28 Mar 2009 11:14:01 -0500</pubDate>
 <dc:creator>Gr33n3gg</dc:creator>
 <guid isPermaLink="false">comment 39038 at http://www.townx.org</guid>
</item>
<item>
 <title>Good howto</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-39035</link>
 <description>&lt;p&gt;This is very good article on creating certificate, btw you can also use the CA .sh script to create it .&lt;/p&gt;</description>
 <pubDate>Fri, 27 Mar 2009 06:02:00 -0500</pubDate>
 <dc:creator>Tech Blog</dc:creator>
 <guid isPermaLink="false">comment 39035 at http://www.townx.org</guid>
</item>
<item>
 <title>I&#039;ll turn that one off, I</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-38990</link>
 <description>&lt;p&gt;I&#039;ll turn that one off, I think! Thanks for letting me know.&lt;/p&gt;</description>
 <pubDate>Wed, 18 Mar 2009 16:10:59 -0500</pubDate>
 <dc:creator>elliot</dc:creator>
 <guid isPermaLink="false">comment 38990 at http://www.townx.org</guid>
</item>
<item>
 <title>There&#039;s 1000s of these</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-38984</link>
 <description>&lt;p&gt;There&#039;s 1000s of these tutorials on the net, each one a little different. I followed yours and it works well, now to bookmark your site so I don&#039;t have to google next time and get a different tut.&lt;/p&gt;</description>
 <pubDate>Tue, 17 Mar 2009 16:55:52 -0500</pubDate>
 <dc:creator>nadine anddanes</dc:creator>
 <guid isPermaLink="false">comment 38984 at http://www.townx.org</guid>
</item>
<item>
 <title>Eventually you want a signed</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comment-38979</link>
 <description>&lt;p&gt;Eventually you want a signed one but a cheap signed for $15, not one of those $500 ripoffs.&lt;/p&gt;

&lt;p&gt;PS: Your &lt;span class=&quot;caps&quot;&gt;ASCII &lt;/span&gt;captcha sucks and is broken!  No matter how many times a human tries, the human always gets it wrong.  I had to clear cookies and restart.&lt;/p&gt;</description>
 <pubDate>Mon, 16 Mar 2009 11:05:17 -0500</pubDate>
 <dc:creator>Anonymous</dc:creator>
 <guid isPermaLink="false">comment 38979 at http://www.townx.org</guid>
</item>
<item>
 <title>Creating a self-signed SSL certificate for Apache on Linux</title>
 <link>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux</link>
 <description>&lt;p&gt;(This is extracted from &lt;a href=&quot;http://moochlabs.com/files/apache_and_php_course.pdf&quot;&gt;my Apache course materials&lt;/a&gt;, but it&#039;s a useful howto in its own right.)&lt;/p&gt;

&lt;p&gt;To generate a self-signed &lt;span class=&quot;caps&quot;&gt;SSL &lt;/span&gt;certificate, you will need openssl installed first.&lt;/p&gt;

&lt;p&gt;Then follow these steps:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Generate the server&#039;s private key; we&#039;ll use a 1024-bit key using the &lt;span class=&quot;caps&quot;&gt;RSA &lt;/span&gt;algorithm:&lt;br/&gt;
&lt;code&gt;openssl genrsa -out server.key 1024&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Generate a certificate-signing request:&lt;br/&gt;
&lt;code&gt;openssl req -new -key server.key -out server.csr&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fill in the required information at the prompts:&lt;br/&gt;


&lt;pre&gt;
   Country Name (2 letter code) [GB]:GB
   State or Province Name (full name) []:.
   Locality Name (eg, city) [Newbury]:Birmingham
   Organization Name (eg, company) [My Company Ltd]:Talis
   Organizational Unit Name (eg, section) []:Library Products
   Common Name (eg, your name or your server&#039;s hostname) []:prism.talis.com
   Email Address []:.

   Please enter the following &#039;extra&#039; attributes to be sent with your certificate request

   A challenge password []:.
   An optional company name []:.
&lt;/pre&gt;


The really important one is the Common Name: this must match the domain name which will serve the &lt;span class=&quot;caps&quot;&gt;SSL &lt;/span&gt;site; otherwise connecting clients will get a prompt about a mismatch between the certificate&#039;s host name and the actual host name of the server.&lt;br/&gt;&lt;br /&gt;
Note that we left the password blank. If we don&#039;t do this, Apache will prompt you for the certificate password each time you start the server, which is a pain in the arse.&lt;/li&gt;
&lt;li&gt;Create a self-signed certificate from the certificate-signing request (.csr file):&lt;br/&gt;
&lt;code&gt;openssl x509 -req -days 3650 -in server.csr -signkey server.key -out server.crt&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;rm server.csr&lt;/code&gt; (you don&#039;t need it any more)&lt;/li&gt;
&lt;li&gt;Put the .crt and .key files into Apache&#039;s &lt;span class=&quot;caps&quot;&gt;SSL &lt;/span&gt;directory and configure Apache to use them&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;If I get round to it I&#039;ll do another entry explaining how to make Apache use them.&lt;/p&gt;</description>
 <comments>http://www.townx.org/blog/elliot/creating-self-signed-ssl-certificate-apache-linux#comments</comments>
 <category domain="http://www.townx.org/tech">tech</category>
 <category domain="http://www.townx.org/howtos">howtos</category>
 <pubDate>Thu, 05 Mar 2009 04:36:44 -0600</pubDate>
 <dc:creator>elliot</dc:creator>
 <guid isPermaLink="false">771 at http://www.townx.org</guid>
</item>
</channel>
</rss>
