ssk’s posterous

ssk’s posterous

Jun 25 / 3:27am

Webdav - openSUSE

by ssk

Import the cacert.org root certificates

Copy ca.crt and root.crt from cacert.org into your /etc/apache2/ssl.crt/ directory.

Copy /etc/apache2/vhosts.d/vhost-ssl.template to /etc/apache2/vhosts.d/vhost-ssl.conf and uncomment the SSLCertificateChainFile and SSLCACertificatePath lines.

<IfDefine SSL>
<IfDefine !NOSSL>
<VirtualHost _default_:443>
       DocumentRoot "/srv/www/htdocs"
       ErrorLog /var/log/apache2/error_log
       TransferLog /var/log/apache2/access_log
       SSLEngine on
       SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
       SSLCertificateFile /etc/apache2/ssl.crt/server.crt
       SSLCertificateKeyFile /etc/apache2/ssl.key/server.key
       SSLCertificateChainFile /etc/apache2/ssl.crt/ca.crt
       SSLCACertificatePath /etc/apache2/ssl.crt
       <Files ~ "\.(cgi|shtml|phtml|php3?)$">
           SSLOptions +StdEnvVars
       </Files>
       <Directory "/srv/www/cgi-bin">
           SSLOptions +StdEnvVars
       </Directory>
       SetEnvIf User-Agent ".*MSIE.*" \
                nokeepalive ssl-unclean-shutdown \
                downgrade-1.0 force-response-1.0
       CustomLog /var/log/apache2/ssl_request_log   ssl_combined
</VirtualHost>
</IfDefine>
</IfDefine>

root.crt は落としても使わないのかな?
SSLCACerticatePath に root.crt というファイル名なら自動認識?

Filed under  //  apache   ssl  

Comments (0)