Vinícius Ferrão wrote:
> 
> 
>> On 5 Dec 2019, at 15:22, Rob Crittenden <[email protected]> wrote:
>>
>> Vinícius Ferrão via FreeIPA-users wrote:
>>> Hello,
>>>
>>> Is it supported to install mod_ssl on the same machine of FreeIPA? I’m 
>>> asking this because FreeIPA ships by default mod_nss and this may lead to 
>>> conflicting issues inside /etc/httpd/conf.d. For example:
>>>
>>> [root@headnode conf.d]# grep -iR virtualhost
>>> nss.conf:<VirtualHost _default_:443>
>>> nss.conf:</VirtualHost>                                  
>>> ssl.conf:<VirtualHost _default_:443>
>>> ssl.conf:</VirtualHost>       
>>>
>>> Both add a default virtual host to 443.
>>>
>>> What’s the correct procedure? Don’t use mod_ssl at all?
>>
>> They can co-exist but they can't share ports.
>>
>> We do not recommend running other services on an IPA server.
> 
> Thanks for rescuing out again Rob.
> 
> So I need to custom tailor the ssl.conf and keep the nss.conf as default 
> right?
> 
> I can learn the right way and use nss.conf instead, I think it will keep the 
> sanity of the configuration files.

For many configuration options it is SSL<thing> -> NSS<thing> with the
exception of the certs, but those are already configured so it may be
pretty straightforward.

> 
> Just for curiosity, it’s the web interface of a monitoring system. Just that.

Ok.

rob

> 
>>
>> rob
>>
> 
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to