Internal Installing Apache SSL Certs

From GrandCare Systems
Revision as of 17:20, 10 July 2017 by Eumhoefer (talk | contribs) (Eumhoefer moved page Installing Apache SSL Certs to Internal Installing Apache SSL Certs: Internal Page)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search
  • Load StartSSL trusted login cert into browser (Located on Password Gorilla)
  • Login and choose the certificate wizard (verify domain if required)
  • Skip automatic cert generation in the wizard
  • SSH into the server and run in /etc/ssl
  • Generate the request
openssl req -new -newkey rsa:2048 -nodes -keyout fqdn.key -out fqdn.csr
  • Set the server domain name for CN
  • Copy server.csr into StartSSL's Cert Wizard
  • Wait for verification (check support mailing list)
  • Follow the instructions in the email and create fqdn.crt
  • Rename the fqdn.key and fqdn.crt to the common name
  • Modify /etc/ssl/apache.conf to read like this
SSLEngine On
SSLProtocol all -SSLv2
SSLCertificateChainFile /etc/ssl/
SSLCACertificateFile /etc/ssl/ca.pem
SSLCertificateFile /etc/ssl/certs/fqdn.crt
SSLCertificateKeyFile /etc/ssl/private/fqdn.key
SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown
  • Restart the apache server daemon
/etc/init.d/apache2 restart


Copy the private key to Password Gorilla