Re: More fun with SSL certificates

2023-05-14 Thread Patrick O'Callaghan
On Sun, 2023-05-14 at 08:37 +0200, Peter Boy wrote: > > > > Am 08.05.2023 um 12:52 schrieb Patrick O'Callaghan > > : > > > > On Fri, 2023-05-05 at 23:38 +0200, Peter Boy wrote: > > > I just updated the Web service guide and its troubleshooting > > > section. > > > The URL is still the same. 

Re: More fun with SSL certificates

2023-05-14 Thread Peter Boy
> Am 08.05.2023 um 12:52 schrieb Patrick O'Callaghan : > > On Fri, 2023-05-05 at 23:38 +0200, Peter Boy wrote: >> I just updated the Web service guide and its troubleshooting section. >> The URL is still the same. Sorry for the delay, the issue has proven >> in systematic testing to be even

Re: More fun with SSL certificates

2023-05-08 Thread Patrick O'Callaghan
On Fri, 2023-05-05 at 23:38 +0200, Peter Boy wrote: > I just updated the Web service guide and its troubleshooting section. > The URL is still the same.  Sorry for the delay, the issue has proven > in systematic testing to be even more complicated than we previously > knew.  > > The guide is not

Re: More fun with SSL certificates

2023-05-05 Thread Peter Boy
I just updated the Web service guide and its troubleshooting section. The URL is still the same. Sorry for the delay, the issue has proven in systematic testing to be even more complicated than we previously knew. The guide is not yet completed, I’ll work on it over the next days as my time

Re: More fun with SSL certificates

2023-05-03 Thread Peter Boy
> Am 03.05.2023 um 23:56 schrieb Patrick O'Callaghan : > > On Wed, 2023-05-03 at 18:49 +0200, Peter Boy wrote: >> The description is now at >> https://docs.stg.fedoraproject.org/en-US/fedora-server/services/httpd-basic-setup/ >> >> at the bottom, Troubleshooting >> >> Unfortunately, I had

Re: More fun with SSL certificates

2023-05-03 Thread Mike Wright
On 5/2/23 05:31, Peter Boy wrote: Am 02.05.2023 um 12:23 schrieb Patrick O'Callaghan : # httpd -S VirtualHost configuration: *:80 bree.org.uk (/etc/httpd/conf.d/bree.conf:1) *:443 is a NameVirtualHost default server bree.org.uk

Re: More fun with SSL certificates

2023-05-03 Thread Patrick O'Callaghan
On Wed, 2023-05-03 at 18:49 +0200, Peter Boy wrote: > The description is now at > https://docs.stg.fedoraproject.org/en-US/fedora-server/services/httpd-basic-setup/ >   > at the bottom, Troubleshooting > > Unfortunately, I had various issues with my test equipment and > couldn’t test the steps so

Re: More fun with SSL certificates

2023-05-03 Thread Patrick O'Callaghan
On Wed, 2023-05-03 at 13:57 -0400, Jeffrey Walton wrote: > On Wed, May 3, 2023 at 12:50 PM Peter Boy wrote: > > [...] > > The description is now at > > https://docs.stg.fedoraproject.org/en-US/fedora-server/services/httpd-basic-setup/ > > at the bottom, Troubleshooting > > > > Unfortunately, I

Re: More fun with SSL certificates

2023-05-03 Thread Tim via users
On Wed, 2023-05-03 at 14:50 -0400, Jeffrey Walton wrote: > Would Apache accept example.local or example.localdomain with the > appropriate hosts change? I've never had Apache fail with any hostname as long as it resolves locally. And, yes, my tests make use of names that won't conflict with real

Re: More fun with SSL certificates

2023-05-03 Thread Jeffrey Walton
On Wed, May 3, 2023 at 2:25 PM Chris Adams wrote: > > Once upon a time, Jeffrey Walton said: > > Re, the info about a fake server: > > > > As a workaround, configure a fake server that is never used but is > > just a decoy for httpd to associate with the default server > > configured

Re: More fun with SSL certificates

2023-05-03 Thread Chris Adams
Once upon a time, Jeffrey Walton said: > Re, the info about a fake server: > > As a workaround, configure a fake server that is never used but is > just a decoy for httpd to associate with the default server > configured in /etc/httpd/conf.d/ssl.conf... > > ServerName

Re: More fun with SSL certificates

2023-05-03 Thread Todd Zullinger
Jeffrey Walton wrote: > If OCSP stapling is going to be used, then you should also enable > mod_socache_shmcb: > > a2enmod ssl > a2enmod socache_shmcb > a2enmod rewrite a2enmod is a Debian thing, FWIW. -- Todd signature.asc Description: PGP signature

Re: More fun with SSL certificates

2023-05-03 Thread Jeffrey Walton
On Wed, May 3, 2023 at 12:50 PM Peter Boy wrote: > [...] > The description is now at > https://docs.stg.fedoraproject.org/en-US/fedora-server/services/httpd-basic-setup/ > at the bottom, Troubleshooting > > Unfortunately, I had various issues with my test equipment and couldn’t test > the steps

Re: More fun with SSL certificates

2023-05-03 Thread Jeffrey Walton
On Wed, May 3, 2023 at 12:50 PM Peter Boy wrote: > [...] > The description is now at > https://docs.stg.fedoraproject.org/en-US/fedora-server/services/httpd-basic-setup/ > at the bottom, Troubleshooting > > Unfortunately, I had various issues with my test equipment and couldn’t test > the steps

Re: More fun with SSL certificates

2023-05-03 Thread Peter Boy
> Am 03.05.2023 um 13:37 schrieb Patrick O'Callaghan : > > On Wed, 2023-05-03 at 13:31 +0200, Peter Boy wrote: >> >> >>> Am 03.05.2023 um 12:05 schrieb Patrick O'Callaghan >>> : >>> >>> On Tue, 2023-05-02 at 14:31 +0200, Peter Boy wrote: > Am 02.05.2023 um 12:23 schrieb

Re: More fun with SSL certificates

2023-05-03 Thread Patrick O'Callaghan
On Wed, 2023-05-03 at 13:31 +0200, Peter Boy wrote: > > > > Am 03.05.2023 um 12:05 schrieb Patrick O'Callaghan > > : > > > > On Tue, 2023-05-02 at 14:31 +0200, Peter Boy wrote: > > > > > > > > > > Am 02.05.2023 um 12:23 schrieb Patrick O'Callaghan > > > > : > > > > > > > > # httpd  -S > > >

Re: More fun with SSL certificates

2023-05-03 Thread Peter Boy
> Am 03.05.2023 um 12:05 schrieb Patrick O'Callaghan : > > On Tue, 2023-05-02 at 14:31 +0200, Peter Boy wrote: >> >> >>> Am 02.05.2023 um 12:23 schrieb Patrick O'Callaghan >>> : >>> >>> # httpd -S >>> VirtualHost configuration: >>> *:80 bree.org.uk

Re: More fun with SSL certificates

2023-05-03 Thread Patrick O'Callaghan
On Tue, 2023-05-02 at 14:31 +0200, Peter Boy wrote: > > > > Am 02.05.2023 um 12:23 schrieb Patrick O'Callaghan > > : > > > > # httpd  -S > > VirtualHost configuration: > > *:80   bree.org.uk (/etc/httpd/conf.d/bree.conf:1) > > *:443  is a NameVirtualHost > >  

Re: More fun with SSL certificates

2023-05-02 Thread Jeffrey Walton
On Tue, May 2, 2023 at 9:44 AM Chris Adams wrote: > > Once upon a time, Jeffrey Walton said: > > On Tue, May 2, 2023 at 6:22 AM Patrick O'Callaghan > > wrote: > > > # openssl x509 -in cert.pem -noout -text > > > Certificate: > > > Data: > > > Version: 3 (0x2) > > > Serial

Re: More fun with SSL certificates

2023-05-02 Thread Chris Adams
Once upon a time, Jeffrey Walton said: > On Tue, May 2, 2023 at 6:22 AM Patrick O'Callaghan > wrote: > > # openssl x509 -in cert.pem -noout -text > > Certificate: > > Data: > > Version: 3 (0x2) > > Serial Number: > >

Re: More fun with SSL certificates

2023-05-02 Thread Peter Boy
> Am 02.05.2023 um 15:25 schrieb Jeffrey Walton : > > On Tue, May 2, 2023 at 6:22 AM Patrick O'Callaghan > wrote: >> >> On Mon, 2023-05-01 at 23:41 +0100, Barry wrote: >>> >>> On 1 May 2023, at 23:22, Patrick O'Callaghan wrote: My small web server appears to be

Re: More fun with SSL certificates

2023-05-02 Thread Jeffrey Walton
On Tue, May 2, 2023 at 6:22 AM Patrick O'Callaghan wrote: > > On Mon, 2023-05-01 at 23:41 +0100, Barry wrote: > > > > > > > On 1 May 2023, at 23:22, Patrick O'Callaghan > > > wrote: > > > > > > My small web server appears to be working and even has https, > > > however > > > I've noticed this

Re: More fun with SSL certificates

2023-05-02 Thread Peter Boy
> Am 02.05.2023 um 12:23 schrieb Patrick O'Callaghan : > > # httpd -S > VirtualHost configuration: > *:80 bree.org.uk (/etc/httpd/conf.d/bree.conf:1) > *:443 is a NameVirtualHost >default server bree.org.uk (/etc/httpd/conf.d/bree-le-ssl.conf:2) >

Re: More fun with SSL certificates

2023-05-02 Thread Patrick O'Callaghan
On Tue, 2023-05-02 at 16:51 +0930, Tim via users wrote: > On Mon, 2023-05-01 at 23:21 +0100, Patrick O'Callaghan wrote: > > My small web server appears to be working and even has https, > > however > > I've noticed this in /var/log/httpd/ssl_error_log: > > > > [...] AH01909: bree.org.uk:443:0

Re: More fun with SSL certificates

2023-05-02 Thread Patrick O'Callaghan
On Tue, 2023-05-02 at 10:39 +0200, Peter Boy wrote: > > > > Am 02.05.2023 um 00:21 schrieb Patrick O'Callaghan > > : > > > > My small web server appears to be working and even has https, > > however > > I've noticed this in /var/log/httpd/ssl_error_log: > > > > [...] AH01909: bree.org.uk:443:0

Re: More fun with SSL certificates

2023-05-02 Thread Patrick O'Callaghan
On Mon, 2023-05-01 at 23:41 +0100, Barry wrote: > > > > On 1 May 2023, at 23:22, Patrick O'Callaghan > > wrote: > > > > My small web server appears to be working and even has https, > > however > > I've noticed this in /var/log/httpd/ssl_error_log: > > > > [...] AH01909: bree.org.uk:443:0

Re: More fun with SSL certificates

2023-05-02 Thread Patrick O'Callaghan
On Mon, 2023-05-01 at 21:17 -0400, Jeffrey Walton wrote: > On Mon, May 1, 2023 at 6:22 PM Patrick O'Callaghan > wrote: > > > > My small web server appears to be working and even has https, > > however > > I've noticed this in /var/log/httpd/ssl_error_log: > > > > [...] AH01909:

Re: More fun with SSL certificates

2023-05-02 Thread Peter Boy
> Am 02.05.2023 um 00:21 schrieb Patrick O'Callaghan : > > My small web server appears to be working and even has https, however > I've noticed this in /var/log/httpd/ssl_error_log: > > [...] AH01909: bree.org.uk:443:0 server certificate does NOT include an ID > which matches the server name

Re: More fun with SSL certificates

2023-05-02 Thread Tim via users
On Mon, 2023-05-01 at 23:21 +0100, Patrick O'Callaghan wrote: > My small web server appears to be working and even has https, however > I've noticed this in /var/log/httpd/ssl_error_log: > > [...] AH01909: bree.org.uk:443:0 server certificate does NOT include an ID > which matches the server

Re: More fun with SSL certificates

2023-05-01 Thread Jeffrey Walton
On Mon, May 1, 2023 at 6:22 PM Patrick O'Callaghan wrote: > > My small web server appears to be working and even has https, however > I've noticed this in /var/log/httpd/ssl_error_log: > > [...] AH01909: bree.org.uk:443:0 server certificate does NOT include an ID > which matches the server name

Re: More fun with SSL certificates

2023-05-01 Thread Jeffrey Walton
On Mon, May 1, 2023 at 6:22 PM Patrick O'Callaghan wrote: > > My small web server appears to be working and even has https, however > I've noticed this in /var/log/httpd/ssl_error_log: > > [...] AH01909: bree.org.uk:443:0 server certificate does NOT include an ID > which matches the server name

Re: More fun with SSL certificates

2023-05-01 Thread Barry
> On 1 May 2023, at 23:22, Patrick O'Callaghan wrote: > > My small web server appears to be working and even has https, however > I've noticed this in /var/log/httpd/ssl_error_log: > > [...] AH01909: bree.org.uk:443:0 server certificate does NOT include an ID > which matches the server name

More fun with SSL certificates

2023-05-01 Thread Patrick O'Callaghan
My small web server appears to be working and even has https, however I've noticed this in /var/log/httpd/ssl_error_log: [...] AH01909: bree.org.uk:443:0 server certificate does NOT include an ID which matches the server name The ServerName is set to bree.org.uk, and that's the name under which