Hey All,

I'm thoroughly confused by this whole SSL thing. All of the guides I've found are of the "type this and this and works right?" And yeah... it works but I don't understand why... or how to maintain it... or if I need to...

All I want to be able to have both my domains on my box use encryption when checking email, either via squirrelmail or via pop/imap. So I don't feel completely "naked". I know qmail (well, courier-imap...) has certificates created for pop3 and imap, and mod_ssl created a self-signed certificate for apache. Do I need to combine those somehow? Would that make maintenance any easier?

And what do I need to do so that every virtual host in apache just quietly listens on the https port as well as the standard http port? Can I just move all the commands in the ssl default virtual host into the main commonapache.conf file? With the possible exception of the SSLCertificateFile and SSLCertificateKeyFile settings which I would keep on a host by host basis? (To allow for future use of a real certificate on a host by host basis)

Am I missing something? Any advice would be greatly appreciated.

Thanks!

Matt



--
[EMAIL PROTECTED] mailing list

Reply via email to